feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(web): add audit log entries for org membership changes - #1165

Merged
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes
May 2, 2026
Merged

feat(web): add audit log entries for org membership changes#1165
brendan-kellam merged 4 commits into
mainfrom
brendan/audit-org-membership-changes

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds three new audit actions so the membership lifecycle is fully captured in the audit log:

  • org.member_added — fires from all five UserToOrg-creation paths:
    • Initial owner on first signup (onCreateUser, alongside the existing user.owner_created)
    • Auto-add on signup when memberApprovalRequired = false (previously silent)
    • Magic invite-link join via joinOrganization (previously silent)
    • Email invite redemption (alongside the existing user.invite_accepted)
    • Join-request approval (alongside the existing user.join_request_approved)
  • org.member_removed — fires when an admin removes a member via Settings → Members.
  • org.member_left — fires when a user leaves the org themselves.

All three use a consistent (actor=user, target=user) shape so the full membership history can be reconstructed with one filter per state transition (org.member_added / org.member_removed / org.member_left). The existing per-path audits (user.invite_accepted, user.join_request_approved, user.owner_created) are preserved as semantic detail — they describe how a user joined, while org.member_added records that they joined.

The metadata.message on each event records the specific path (initial owner, no-approval signup, invite link, invite ID, approving admin) so detail isn't lost.

createGuestUser is intentionally not audited — it upserts the singleton system Guest user, not a real membership grant.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added three audit action types for organization member lifecycle: org.member_added, org.member_removed, org.member_left. These events are now recorded across member approval, invite acceptance, removals, voluntary departures, and single-tenant provisioning flows.
  • Documentation

    • Updated audit logs docs to include the new membership action types with actor/target details.
  • Chores

    • Added entry to CHANGELOG for the new audit actions.

Adds three new audit actions covering the full membership lifecycle:
- org.member_added — fires from all five UserToOrg-creation paths
(initial owner, auto-add on signup, magic invite-link join, email
invite redemption, join-request approval). Two of those paths were
previously silent.
- org.member_removed — fires when an admin removes a member via the
Settings UI.
- org.member_left — fires when a user leaves the org themselves.
Each event uses a consistent (actor=user, target=user) shape so the
membership history can be reconstructed with a single query per state
transition. Existing audits (user.invite_accepted,
user.join_request_approved, user.owner_created) are preserved as
semantic detail.
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Adds three organization membership audit events (org.member_added, org.member_removed, org.member_left) and instruments membership-related flows to emit those audits across account-approval, invite/join, member removal/leave, and single-tenant provisioning paths.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md, docs/docs/configuration/audit-logs.mdx
Added Unreleased changelog entry and documented three new audit action types: org.member_added, org.member_removed, org.member_left.
Account Request Approval
packages/web/src/actions.ts
Emits org.member_added after approveAccountRequest completes; reorders email send to occur after audit and wraps send in try/catch.
Invite & Join Flows
packages/web/src/app/invite/actions.ts
Emits org.member_added in joinOrganization and redeemInvite after successful membership changes, with contextual metadata (invite link or inviteId).
Member Management
packages/web/src/features/userManagement/actions.ts
Calls audit service in removeMemberFromOrg and leaveOrg to create org.member_removed and org.member_left records after transaction/guard checks.
Single-Tenant Provisioning
packages/web/src/lib/authUtils.ts
Creates org.member_added audit events during onCreateUser for initial owner and for subsequent member additions when approval is not required (uses single-tenant org ID).

Sequence Diagram(s)

sequenceDiagram
participant Client
participant ServerAction as Server Action Handler
participant AuditSvc as AuditService
participant DB as Database
participant Email as Email/SMTP
Client->>ServerAction: trigger approveAccountRequest / join / redeem / leave / remove
ServerAction->>DB: perform membership change transaction
DB-->>ServerAction: transaction result
ServerAction->>AuditSvc: createAudit(action: org.member_*)
AuditSvc-->>DB: persist audit record
AuditSvc-->>ServerAction: confirmation
ServerAction->>Email: send notification (if applicable)
Email-->>ServerAction: send result / errors
ServerAction-->>Client: response
Loading

Possibly related PRs

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'feat(web): add audit log entries for org membership changes' accurately and concisely describes the main change across all files—adding audit logging for organization member lifecycle events (added, removed, left).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/audit-org-membership-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/configuration/audit-logs.mdx (1)

148-150: ⚡ Quick win

Clarify actor/target semantics for these new membership events.

The user / user rows are accurate on types, but org.member_added and org.member_removed do not always use the same user ID on both sides. In the approval/removal flows the actor is the admin and the target is the affected member, so a short note here would prevent readers from inferring actorId === targetId for every one of these events.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/configuration/audit-logs.mdx` around lines 148 - 150, Update the
docs for the membership events (`org.member_added`, `org.member_removed`,
`org.member_left`) to clarify actor vs target semantics: explicitly state that
for `org.member_added` and `org.member_removed` the actor is typically the admin
performing the approval/removal and the target is the affected member (so
actorId != targetId), whereas for `org.member_left` the actor and target are the
same user (self-initiated, actorId === targetId); add a short footnote or
parenthetical note next to those table rows so readers don’t assume actorId ===
targetId for all three events.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/web/src/actions.ts`:
- Around line 1051-1059: The approval audit writes (calls to
auditService.createAudit for "user.join_request_approved" and
"org.member_added") must be performed before the email side-effect (the call(s)
to render() and sendMail()), so move the auditService.createAudit calls to occur
immediately after addUserToOrganization() (and before render/sendMail), or
alternatively wrap render/sendMail in a try/catch that logs/suppresses email
errors without reverting the endpoint error response; update the code paths
using requestId, request.requestedById, user.id, org.id and ensure the
user.join_request_approved and org.member_added audits are created prior to any
potential throw from render()/sendMail().
---
Nitpick comments:
In `@docs/docs/configuration/audit-logs.mdx`:
- Around line 148-150: Update the docs for the membership events
(`org.member_added`, `org.member_removed`, `org.member_left`) to clarify actor
vs target semantics: explicitly state that for `org.member_added` and
`org.member_removed` the actor is typically the admin performing the
approval/removal and the target is the affected member (so actorId != targetId),
whereas for `org.member_left` the actor and target are the same user
(self-initiated, actorId === targetId); add a short footnote or parenthetical
note next to those table rows so readers don’t assume actorId === targetId for
all three events.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b4ac4407-4234-4546-aac8-a8e03407825d

📥 Commits

Reviewing files that changed from the base of the PR and between ff41d83 and 073421a.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/docs/configuration/audit-logs.mdx
  • packages/web/src/actions.ts
  • packages/web/src/app/invite/actions.ts
  • packages/web/src/features/userManagement/actions.ts
  • packages/web/src/lib/authUtils.ts

Comment threadpackages/web/src/actions.ts
Move user.join_request_approved and org.member_added audit writes to occur
immediately after addUserToOrganization() and before the email send. This
ensures the audit trail is complete even if render() or sendMail() throws.
Wrapped the email block in try/catch so email failures are logged without
propagating as errors.
Co-authored-by: Brendan Kellam <brendan-kellam@users.noreply.github.com>
@brendan-kellam
brendan-kellam merged commit 84f6454 into mainMay 2, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/audit-org-membership-changes branch May 2, 2026 00:05
@github-actionsgithub-actionsBot mentioned this pull request May 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam