AUTH4D-7: Structured logs and audit records

The observability package emits JSON log records containing only a timestamp, severity, a fixed event name, and validated correlation fields. Request IDs correlate records across one request. Headers, cookies, request bodies, response bodies, arbitrary error messages, email addresses and credentials are not accepted as log fields.

Audit events are immutable D1 records scoped by tenant_id. Event names are selected from the authentication, session, provider and management allowlist in @auth4/observability. Metadata is a small object of enumerated values and bounded counters. It must not contain user supplied text. Stable evt_ identifiers are SHA-256 digests of the validated canonical event. Retrying the same event is idempotent through (tenant_id, event_id) conflict handling.

Management repositories can build an audit insert with createAuditStatement(event) and include that prepared statement in the same D1Database.batch() as the related mutation. The audit query requires tenantId, supports bounded event, outcome, actor, target, request and time filters, caps pages at 100 records, and orders them by event time and ID. Audit query and write failures increment operational counters, emit a safe error log, and reject with an explicit storage error.

The package counters are operational diagnostics scoped to a running Worker instance. They are not durable usage measurements and must not be used for billing.

Source: docs/api-spec/auth4d-7.md