Skip to content

Add enhanced session and authentication audit bindings - #156

Draft
arkmish wants to merge 2 commits into
armishra/zk-write-auditfrom
armishra/zk-session-auth-audit
Draft

arkmish wants to merge 2 commits into
armishra/zk-write-auditfrom
armishra/zk-session-auth-audit

Conversation

@arkmish

@arkmish arkmish commented Sep 28, 2026 •

Copy link
Copy Markdown

Description

Add session and authentication context to enhanced audit logging so consumers can follow valid connection attachments, reconnects, and authentication changes without rewriting the identity recorded on earlier writes.

Two operations are emitted:

Operation Meaning
sessionEstablished A valid session attachment, including reconnect or movement to another server
authentication An actual explicit-auth or completed SASL authentication outcome

Each record pairs one sanitized scalar user with its auth_scheme. Distinct bindings are emitted separately; duplicate sanitized pairs within one hook are collapsed.

  • Emit only after valid session assignment or an actual authentication outcome, never for an intermediate SASL challenge.
  • Leave unassigned session IDs and unknown principals absent. Failed authentication is not attributed to an identity from an earlier successful authentication.
  • Reuse conservative identity sanitization, a consistent enhanced-mode decision, and best-effort error reporting.
  • Preserve request-time write identities and all existing authentication, connection-close, and SASL-policy behavior.

These records are binding observations, not unique authentication-attempt or new-session counters. X509 or super identity is not evidence of TLS.

Tests

Validated SessionAuthAuditTest together with existing audit, auth, X509, SASL, TTL, DataTree, and metrics regression tests on JDK 11 targeting Java 8 APIs:

Tests run: 129, Failures: 0, Errors: 0, Skipped: 0
BUILD SUCCESS

Coverage includes real standalone/quorum session movement, real DIGEST-MD5 exchanges, synthetic X509/provider cases, scalar escaping, feature gates, mode changes, identity changes after attachment, and failing audit/reporting backends.

Live TLS transport, a Kerberos KDC, and production log delivery were not qualified by these tests.

  • Local code review completed

Changes that Break Backward Compatibility (Optional)

Bindings require both zookeeper.audit.enable=true and zookeeper.audit.enhanced.enable=true; default and legacy-mode behavior are unchanged.

No authentication/TLS policy, ACL decision, or client protocol change. Consumers must handle per-identity event cardinality and unknown attribution. Strict schema consumers need updating before additive producer fields are enabled.

Documentation (Optional)

Updated zookeeper-docs/src/main/resources/markdown/zookeeperAuditLogs.md with binding fields, examples, identity/cardinality semantics, privacy, and consumer compatibility requirements.

🤖 Generated with GitHub Copilot CLI

arkmish and others added 2 commits September 28, 2026 12:20
Emit sanitized scalar auth_scheme/user bindings for valid attachments and actual authentication outcomes. Preserve C1 feature gates, mode snapshots and best-effort reporting; account explicitly for setup bindings in write-focused tests.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Document that the pinned local JOBS parser rejects unknown fields and staging quarantines those records. Require updating and validating the consumer before enabling additive v2 producer fields; leave runtime behavior unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

audit log enhancement Audit log metadata, privacy, outcomes, and session or authentication correlation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant