feat: add hash-chained, append-only audit log

Introduce src/audit.rs: a SHA-256 hash-chained audit log for
security-sensitive operations (key export, NIP-46 connect/revoke,
signing approvals, vault lock/unlock, permission denials).

- AuditEntry carries timestamp, profile npub, action, reason,
  success flag, error, and prev/this hash forming a tamper-evident
  chain from a genesis hash.
- record() holds a single mutex across the entire read-compute-write-
  update cycle so concurrent writers cannot interleave and silently
  overwrite entries; appends are atomic (write-all + fsync + rename).
- verify_chain() re-hashes every entry end to end.
- Log lives in the app data dir with 0600 permissions.

Also adds the sha2 dependency. Verified in isolation on top of HEAD:
cargo test --release -> 124 passed (119 prior + 5 audit).
This commit is contained in:
Avi 2026-09-03 09:21:53 -05:00
commit caed722b06
4 changed files with 491 additions and 1 deletions

View file

@ -17,5 +17,6 @@ base64 = "0.22"
getrandom = "0.2"
zeroize = "1"
rpassword = "7"
sha2 = "0.10"
async-trait = "0.1"
keyring = "4.2"