access: persist the access audit to state.db #90
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
ADR-003 decision 7 says every grant/deny is audited to state.db (hashed credential, timestamp, role, outcome), with optional later publication as a Nostr event. What shipped in #86 is
recordAccessAudit()in stores/atm.ts, which only console.info()s a truncated hash.Needed:
state:record-access-eventIPC handler in electron/main.ts next tostate:record-transaction, plus preload exposureaccess_eventstable in state.db (credential_id_hash, role, result, reason, at); never a raw external_id or lnurlwrecordAccessAudit()writes through it; dev unlocks recorded with role operator and credentialdev-unlockSee the 2026-09-20 amendment in docs/adr/003-nfc-access-control-layer.md.