Hi,
What is the best path to make this entity fullyauditable? [AbpPermissions]
We'd like to be able to see then changes in EntityChanges table etc going forward to understand who made what changes to each Permission. There does not seem to be a straightforward way to do so unless I am missing something.
Thank you.
4 Answer(s)
-
0
To make the
AbpPermissionsentity fully auditable and track changes in theEntityChangestable, you can follow the entity history feature's configuration steps. However, sinceAbpPermissionis an internal entity of the ABP framework, direct auditing might not be straightforward or recommended. Here is a suggested path and an alternative, more robust solution.Enabling Entity History for
AbpPermissionYou can try to enable entity history for the
AbpPermissionentity by following these steps, which are similar to how you would enable it for a custom entity:Enable Entity History: In your module's
PreInitializemethod (usually inYourProjectNameEntityFrameworkCoreModule.cs), ensure that entity history is enabled.public override void PreInitialize() { Configuration.EntityHistory.IsEnabled = true; }Register the Entity for Auditing: In the same file, you need to add
AbpPermissionto the list of tracked entities.public override void PreInitialize() { Configuration.EntityHistory.IsEnabled = true; Configuration.EntityHistory.Selectors.Add( new NamedTypeSelector( "Abp.Authorization.Permissions.AbpPermission", type => typeof(AbpPermission).IsAssignableFrom(type) ) ); }
- Framework Entity: Directly auditing a framework entity like
AbpPermissionmight have unintended side effects, as it's deeply integrated into the framework's authorization system. It's generally safer to avoid direct modifications or deep integrations with internal framework entities. Of course, here is the English version of that explanation.
Recommended and Safer Approach: Auditing the
RoleManagerMethodInstead of tracking the
AbpPermissionentity itself, a better and safer way is to audit the methods that perform these changes. You can do this by using the[Audited]attribute on the manager method that updates the permissions. This will give you a clear log of who changed which role's permissions and when.For example, you can override the
SetGrantedPermissionsAsyncmethod in your existing customRoleManagerclass and add the[Audited]attribute://... public class RoleManager : AbpRoleManager<Role, User> { // ... [Audited] public override Task SetGrantedPermissionsAsync(Role role, IEnumerable<Permission> permissions) { CheckPermissionsToUpdate(role, permissions); return base.SetGrantedPermissionsAsync(role, permissions); } // ... }By doing this, every time the
SetGrantedPermissionsAsyncmethod is called from anywhere in your application, an audit log entry will automatically be created in theAbpAuditLogstable. This log will capture the user who made the call, the parameters (including therolebeing changed and the list of grantedpermissions), and the time of the action. This gives you the desired traceability without interfering with the internal workings of theAbpPermissionentity.This approach is generally the most robust and recommended way to handle auditing for such core functionalities centrally.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Thank you, I like the idea of overriding the RoleManager class. Unfortunately our list of permissions often exceeds the max length (1024) of the Parameters column in the auditlogs table but we could of course capture this information in another table if needed.
I understand we don't want to make the parameters length too long as it could impact performance.
Making a new table with this roles auditing information may be the way to go.
Thanks,
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @KieranIrl
The AuditLogs table comes from ASP.NET Boilerplate. Here, the maximum length of the Parameters property is set to
4096. If your ABP packages are older versions, you can update them, or you can override the maximum length limitation for the AuditLog Parameters property within your ASP.NET Zero project.Related Code Line
Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Thank you, Even with 4k characters I suspect we still may run out. We'll certainly be able to work with overridding SetGrantedPermissionsAsync . Thanks
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)