Skip to content

feat: add coverage report, audit trail panel and phishing-resistant-only setting - #283

Merged
Bccorb merged 1 commit into
mainfrom
feat/audit-coverage-and-strict-login
Oct 7, 2026
Merged

Bccorb merged 1 commit into
mainfrom
feat/audit-coverage-and-strict-login

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Dashboard side of the GovRAMP P2 work in the auth API: fells-code/seamless-auth-api#173, #174, #177 and #178, all merged. It depends on fells-code/seamless-auth-server#191 (merged) for the passthroughs and the raw download mode.

Coverage page (/coverage, new nav item)

  • Stat cards: active users, passkey holders, passkey coverage, and the share of sign-ins in the period that were phishing resistant.
  • Enforced Policy: phishing-resistant-only, login methods, fallback, and the authenticator policy. The report states coverage and policy, as the issue asks.
  • Tables for coverage by organization (no-organization row last), the trend by month or week, the authenticator mix (named where the API knows the AAGUID, "Unknown (aaguid)" otherwise), and the sign-in mix with readable method names.
  • Filters: from/to as whole UTC days, organization, and bucket. An inverted range is flagged and blocks the download.
  • Download CSV saves the API's own CSV under the filename the API gives. It does not re-render the CSV in the browser, so the file matches what the API documents.

Audit Trail panel (Security page)

  • Verify integrity runs GET /admin/auth-events/integrity on demand. It is a mutation, not a query, because the API recomputes every hash, which is too heavy to repeat on each visit or window focus.
    • A pass shows the event count, the chain head, the oldest event and the anchor, with a note to record the head outside the deployment.
    • A failure names the event where the trail breaks and what that means (edited, missing, reordered, or tail removed).
  • Export events asks for a fresh step-up first (the API requires one too), then downloads the period as the API's NDJSON file. Whole UTC days become the API's half-open bounds, with the end day included. Leaving both dates empty exports the whole trail.

System page

  • Phishing-resistant only toggle. Turning it on adds a warning to the save confirmation: users without a passkey, including admins, cannot sign in afterwards. Turning it off needs no confirmation.
  • While it is on, the login method checkboxes and passkey fallback are disabled, with a note that they are kept for when the mode is turned off.
  • The Login Methods stat card reads "Phishing-resistant only".
  • The save confirmation title changed from "Confirm WebAuthn changes" to "Confirm sign-in changes", since it now covers more than WebAuthn.

Plumbing

  • apiDownload(path, fallbackName) in src/lib/api.ts shares apiFetch's request and error handling, so 401 still triggers the session-expired flow and error messages are unchanged. It takes the filename from Content-Disposition and keeps only the last path segment.
  • saveBlob was factored out of downloadCsv.
  • @seamless-auth/types is bumped to ^0.27.0, and check:types-current passes.
  • e2e: the mock API now keeps a content type that a registration sets, so file downloads can be mocked. The deployment seed includes a coverage report, and the nav walk includes Coverage.

Checks

  • npm run typecheck, npm run lint, npm run format:check, npm run build
  • npm run coverage: 87 files, 569 tests pass
  • npm run test:e2e: 147 pass, including new specs for the coverage page (render, filters reach the API, CSV filename), the audit panel (verify pass and fail, NDJSON export with step-up and bounds), and the nav item
  • Two existing system-config e2e locators (/passkeys/i) now also matched the new checkbox, whose description mentions passkeys. They are anchored to /^passkeys/i.

…nly setting

Adds a Coverage page for the authentication coverage report with its CSV
download, an Audit Trail panel on the Security page for the integrity check
and NDJSON export, and a phishing-resistant-only toggle on the System page.

Refs fells-code/seamless-auth-api#173, #174, #177, #178.
@Bccorb
Bccorb merged commit 1d11a13 into main Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant