QueryAudit

One query as an audit trail sees it: who asked (read the principal from context; Wow does not own identity), what shape of query on which model version, under which restrictions, and what came back. It never carries a filter value, so no personal data from the query reaches the audit log.

Parameters

fingerprinter

computes fingerprint on first read.

Types

Link copied to clipboard

Properties

Link copied to clipboard
val context: ContextView

the subscriber context, for the principal and any other request attribute.

Link copied to clipboard

the time from subscription to the terminal signal.

Link copied to clipboard

the query's entry, as the caller set it.

Link copied to clipboard

the error code of a failed query (ErrorInfo.errorCode and, when it states one, the rule code of its first binding error).

Link copied to clipboard

A hash of the submitted query's shape (queryShapeOf: operators, fields, value counts, sort, projection, groups, metrics and the paging kind and size), with every value, search text, alias and cursor left out, so equal shapes group together. Computed on first read, so an observer that never reads it (a metrics observer, say) does not pay for it.

Link copied to clipboard

the masked fields of the model the response carries, read from the admitted (canonical) projection so an alias cannot hide one; empty for a count, an aggregation or a query rejected before admission.

Link copied to clipboard

the queried model, or null when the query was rejected before its schema loaded.

Link copied to clipboard

the content hash of the model's capabilities (QueryModelSchema.version).

Link copied to clipboard

the aggregate queried.

Link copied to clipboard

how the query ended.

Link copied to clipboard

the QueryPolicy classes that restricted the query (those that returned anything but match-all).

Link copied to clipboard

the gateway operation.

Link copied to clipboard
val rows: Long

the records or aggregation rows delivered; a count delivers one.

Link copied to clipboard

the fields the caller's scope restricts (tenantId, ownerId, ...), not their values.

Functions

Link copied to clipboard
open override fun toString(): String

Leaves context out: it holds scope values and request attributes that must not reach a log line.