flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/apps/web/app/routes/workspace/audit.tsx

193 lines7,479 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1import { Download, Filter } from "lucide-react";
2import { Form, Link, data } from "react-router";
3
4import type { Route } from "./+types/audit";
5import { page } from "../../lib/meta";
6import { AuditTable } from "../../components/audit";
7import { Button, ButtonLink, EmptyState, Field, Input } from "../../components/ui";
8import { type AuditFilters, filterHref, parseFilters, toQuery } from "../../lib/audit";
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put9import { auditPage, auditRetention } from "../../lib/audit.server";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API10import { repos } from "../../lib/services.server";
11import { requireUser, roleIn } from "../../lib/session.server";
12
13const PAGE_SIZE = 100;
14
15/** Actions worth offering in the filter; any other can be typed. */
16const COMMON_ACTIONS = [
17 "git.push",
18 "git.fetch",
19 "create_issue",
20 "add_comment",
21 "record_session",
22 "mark_pull_request_ready",
23 "review_pull_request",
24 "merge_pull_request",
25 "remember",
26 "message_agent",
27];
28
29export function meta({ params, ...args }: Route.MetaArgs) {
30 return page(args, { title: `Audit log · ${params.owner} · g1t` });
31}
32
33export async function loader({ params, context, request }: Route.LoaderArgs) {
34 const viewer = requireUser(context, request);
35 const workspace = params.owner.toLowerCase();
36 const role = roleIn(viewer, workspace);
37 if (!role) throw data("Only members of this workspace can read its audit log.", { status: 404 });
38 const filters = parseFilters(new URL(request.url).searchParams);
39 const { visibility: _, ...query } = toQuery(workspace, { kind: "all" }, filters, PAGE_SIZE);
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put40 const [found, projects, retention] = await Promise.all([
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API41 auditPage(viewer, query),
42 repos.list(viewer, { namespace: workspace }).catch(() => []),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put43 auditRetention(workspace),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API44 ]);
45 return {
46 workspace,
47 role,
48 filters,
49 entries: found?.entries ?? [],
50 next: found?.next ?? null,
51 projects: projects.map((repo) => repo.name),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put52 retention,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API53 };
54}
55
56function FilterField({
57 label,
58 name,
59 value,
60 placeholder,
61 list,
62}: {
63 label: string;
64 name: keyof AuditFilters;
65 value: string;
66 placeholder?: string;
67 list?: string;
68}) {
69 return (
70 <Field label={label}>
71 <Input name={name} defaultValue={value} placeholder={placeholder} list={list} />
72 </Field>
73 );
74}
75
76const SELECT =
77 "w-full rounded-md border border-line bg-bg px-3 py-2 text-sm outline-none transition-colors hover:border-line-strong focus:border-accent-dim";
78
79export default function WorkspaceAudit({ loaderData }: Route.ComponentProps) {
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put80 const { workspace, role, filters, entries, next, projects, retention } = loaderData;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API81 const base = `/${workspace}/-/audit`;
82 const filtered = Object.entries(filters).some(([key, value]) => key !== "before" && value);
83 const exportHref = (format: "csv" | "json") => filterHref(`${base}/export`, { ...filters, before: "" }) + `${filtered ? "&" : "?"}format=${format}`;
84 return (
85 <div>
86 <p className="max-w-3xl text-sm text-muted">
87 Every action taken with an agent run's credentials, reads included, and every change people and
88 workspace tokens make through the API, MCP and git: who did it, on whose behalf, with which
89 credential, to what, and whether it was allowed. Refusals name the rule that refused them.
90 {role === "owner"
91 ? " As an owner you see the whole workspace."
92 : " As a member you see what was done to the workspace's projects, and what was done by you or on your behalf."}
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put93 {retention != null &&
94 (retention >= 365
95 ? ` The log goes back ${retention === 365 ? "a year" : `${retention} days`}, on the Team plan.`
96 : ` The log goes back ${retention} days; the Team plan keeps a year.`)}
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API97 </p>
98
99 <Form method="get" className="mt-6 rounded-xl border border-line bg-surface p-4">
100 <div className="grid gap-4 sm:grid-cols-2 lg:grid-cols-4">
101 <FilterField label="Actor" name="actor" value={filters.actor} placeholder="A person, or whom an agent worked for" />
102 <FilterField label="Agent" name="agent" value={filters.agent} placeholder="g1t-agent" />
103 <FilterField label="Action" name="action" value={filters.action} placeholder="git.push" list="audit-actions" />
104 <FilterField label="Project" name="project" value={filters.project} placeholder="Any" list="audit-projects" />
105 <Field label="Outcome">
106 <select name="outcome" defaultValue={filters.outcome} className={SELECT}>
107 <option value="">Any</option>
108 <option value="allowed">Allowed</option>
109 <option value="denied">Denied</option>
110 </select>
111 </Field>
112 <Field label="Who">
113 <select name="kind" defaultValue={filters.kind} className={SELECT}>
114 <option value="">Anyone</option>
115 <option value="agent">Agents</option>
116 <option value="person">People</option>
117 <option value="workspace">Workspace tokens</option>
118 </select>
119 </Field>
120 <Field label="From">
121 <Input type="date" name="from" defaultValue={filters.from} />
122 </Field>
123 <Field label="To">
124 <Input type="date" name="to" defaultValue={filters.to} />
125 </Field>
126 </div>
127 {filters.run && <input type="hidden" name="run" value={filters.run} />}
128 <datalist id="audit-actions">
129 {COMMON_ACTIONS.map((action) => (
130 <option key={action} value={action} />
131 ))}
132 </datalist>
133 <datalist id="audit-projects">
134 {projects.map((name) => (
135 <option key={name} value={name} />
136 ))}
137 </datalist>
138 <div className="mt-4 flex flex-wrap items-center gap-3">
139 <Button type="submit">
140 <Filter size={14} />
141 Filter
142 </Button>
143 {filtered && (
144 <Link to={base} className="text-sm text-muted hover:text-fg">
145 Clear filters
146 </Link>
147 )}
148 {filters.run && (
149 <span className="font-mono text-xs text-muted">
150 Run {filters.run}
151 </span>
152 )}
153 <span className="grow" />
154 <ButtonLink variant="quiet" to={exportHref("csv")} reloadDocument>
155 <Download size={14} />
156 CSV
157 </ButtonLink>
158 <ButtonLink variant="quiet" to={exportHref("json")} reloadDocument>
159 <Download size={14} />
160 JSON
161 </ButtonLink>
162 </div>
163 </Form>
164
165 <div className="mt-6">
166 {entries.length === 0 ? (
167 <EmptyState title={filtered ? "Nothing matches these filters" : "Nothing recorded yet"}>
168 {filtered
169 ? "Try a wider time range, or clear the filters."
170 : "Entries appear as agents work and as people change things through the API, MCP and git."}
171 </EmptyState>
172 ) : (
173 <AuditTable entries={entries} base={base} />
174 )}
175 </div>
176
177 {(next || filters.before) && (
178 <div className="mt-4 flex gap-4 text-sm">
179 {filters.before && (
180 <Link to={filterHref(base, { ...filters, before: "" })} className="text-muted hover:text-fg">
181 Newest
182 </Link>
183 )}
184 {next && (
185 <Link to={filterHref(base, filters, { before: next })} className="text-muted hover:text-fg">
186 Older
187 </Link>
188 )}
189 </div>
190 )}
191 </div>
192 );
193}