Skip to content

feat: add the activity resource and the security audit log - #20

Merged
alihesari merged 2 commits into
mainfrom
feature/activity-and-audit-log
Sep 20, 2026
Merged

alihesari merged 2 commits into
mainfrom
feature/activity-and-audit-log

Conversation

@alihesari

Copy link
Copy Markdown
Member

Adds an activity resource covering GET /v1/activity, and with it the security audit log shipping in fopost#992 (OWL-127).

The endpoint returns data beside meta, so the page is read whole rather than unwrapped down to the list; the cursor comes back as part of the page and is null at the end.

kind of security is the audit log: members joining, leaving or changing role and access, plus changes to two-step verification, passkeys, single sign-on and signed-in devices. Those rows are append-only and, unlike the rest of the activity log, never expire.

Two tests: reading the audit log keeps the cursor and decodes the actor, and the end of the list is a null cursor. Full suite green.

Merge after fopost#992 — the security kind 404s nothing today, but the enum documents a value the deployed API does not yet return.

client.activity.list() reads GET /v1/activity; kind 'security' is the
append-only audit trail of membership, role, access and sign-in changes.
…audit-log

# Conflicts:
#	src/fopost/client.py
#	src/fopost/models.py
@alihesari
alihesari merged commit 8786991 into main Sep 20, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant