diff --git a/app.py b/app.py index f84d5e8..85eeb1c 100644 --- a/app.py +++ b/app.py @@ -883,7 +883,13 @@ def _connect_with_jump_chain(host_id: int) -> tuple[paramiko.SSHClient, paramiko raise RuntimeError("failed to build jump chain") +def is_audit_log_enabled() -> bool: + return os.getenv("ENABLE_AUDIT_LOG", "true").lower() in ("1", "true", "yes") + + def _insert_connection_audit(host_row: dict[str, Any]) -> int | None: + if not is_audit_log_enabled(): + return None try: with db_cursor() as (_, cur): cur.execute( @@ -964,9 +970,10 @@ def api_logout(): @app.route("/api/me", methods=["GET"]) def api_me(): version = app.config.get("VERSION", "unknown") + audit_enabled = is_audit_log_enabled() if session.get("logged_in"): - return jsonify({"logged_in": True, "app_version": version}) - return jsonify({"logged_in": False, "app_version": version}) + return jsonify({"logged_in": True, "app_version": version, "audit_log_enabled": audit_enabled}) + return jsonify({"logged_in": False, "app_version": version, "audit_log_enabled": audit_enabled}) @app.route("/api/identities", methods=["GET"]) diff --git a/frontend/src/App.vue b/frontend/src/App.vue index 1e4f5e5..a77b002 100644 --- a/frontend/src/App.vue +++ b/frontend/src/App.vue @@ -25,6 +25,7 @@ interface TabItem { const loggedIn = ref(false); const checking = ref(true); const appVersion = ref("unknown"); +const auditLogEnabled = ref(true); const identities = ref([]); const allHosts = ref([]); const allFolders = ref([]); @@ -347,6 +348,9 @@ onMounted(async () => { if (m.app_version) { appVersion.value = m.app_version; } + if (m.audit_log_enabled !== undefined) { + auditLogEnabled.value = m.audit_log_enabled; + } if (loggedIn.value) await refreshData(); } catch { loggedIn.value = false; @@ -918,6 +922,7 @@ async function deleteIdentityRow(id: number) { API keys