New Case Study:See how Anthropic automated 95% of dependency reviews with Socket.Learn More
Socket
Sign inDemoInstall
Socket

audited_async

Package Overview
Dependencies
Maintainers
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

audited_async

  • 0.2.2
  • Rubygems
  • Socket score

Version published
Maintainers
1
Created
Source

AuditedAsync

CircleCI

AuditedAsync is a plugin for the audited gem which allows to create audits asynchronously using ActiveJob.

It works by injecting the async option into audited model option using functional programming. If enabled, it'll move audit creation logic into an ActiveJob instance, then it's sent to the queue to be executed later.

Installation

Add this line to your application's Gemfile, right after audited gem:

gem 'audited'
gem 'audited_async'

And then execute:

$ bundle

Usage

class Post < ApplicationRecord
  audited async: true
end

Depending on your active job adapter, you may need to make the queue name visible to the adapter.

Sidekiq

# config/sidekiq.yml
...
:queues:
  - [audits, 1] # add this line

All done! Although you can optionally configure some more stuff, check below.

Enabling it programmatically
# config/initializers/audited_async.rb

AuditedAsync.configure do |config|
  config.enabled = Rails.env.production?
end
Changing Job execution
# config/initializers/audited_async.rb

AuditedAsync.configure do |config|
  config.job_name  = 'JobityJob'
  config.job_options = { wait: 1.second }
end

Create your own job:

class JobityJob < ApplicationJob
  queue_as :audits

  def perform(audit_info)
    # audit_info = {
    #   class_name:      'Post',
    #   record_id:       2,
    #   audited_changes: "{\"json_stringified_changes\": \"with_values\"}",
    #   action:          one of %w[create update destroy],
    #   comment:         there will be some string here if audited comments are enabled,
    # }

    # ...
    # run your logic
    # ...

    # job must have this line at the end
    class_name.constantize.send(:write_audit, attributes)
    # attributes = {
    #   audited_changes: {hash_changes: :with_values},
    #   action:          one of %w[create update destroy],
    #   comment:         comment, if enabled
    # }
  end
end

Limitations

  • Audits for destroying an object are subject to soft delete, hard deleted records are ignored, so if you are using some library like paranoia or discard, destroying an object will still create audits, regardless model scoping.
  • Attributes passed down to job are limited to serializable attributes, you can find a list here, other than that would throw an error.

To see how the default job performs, look here.

Sample App

https://github.com/leonardofalk/audited_async_sample.git

Development

Checkout the repository, execute bundle install and you're good to go.

Testing

There are some unit tests now but integration tests are missing. You can run the suite by executing rspec.

Contributing

Bug reports and pull requests are welcome on GitHub at https://github.com/leonardofalk/audited_async. This project is intended to be a safe, welcoming space for collaboration, and contributors are expected to adhere to the Contributor Covenant code of conduct.

To Do

  • Elaborate integration test cases.

License

The gem is available as open source under the terms of the MIT License.

FAQs

Package last updated on 22 Oct 2019

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc