AUTH4D-7: Structured logs and audit records
The observability package emits JSON log records containing only a timestamp, severity, a fixed event name, and validated correlation fields. Request IDs correlate records across one request. Headers, cookies, request bodies, response bodies, arbitrary error messages, email addresses and credentials are not accepted as log fields.
Audit events are immutable D1 records scoped by tenant_id. Event names are selected from the
authentication, session, provider and management allowlist in @auth4/observability. Metadata is a
small object of enumerated values and bounded counters. It must not contain user supplied text.
Stable evt_ identifiers are SHA-256 digests of the validated canonical event. Retrying the same
event is idempotent through (tenant_id, event_id) conflict handling.
Management repositories can build an audit insert with createAuditStatement(event) and include
that prepared statement in the same D1Database.batch() as the related mutation. The audit query
requires tenantId, supports bounded event, outcome, actor, target, request and time filters, caps
pages at 100 records, and orders them by event time and ID. Audit query and write failures increment
operational counters, emit a safe error log, and reject with an explicit storage error.
The package counters are operational diagnostics scoped to a running Worker instance. They are not durable usage measurements and must not be used for billing.
Source: docs/api-spec/auth4d-7.md