Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneesstack72

Relationships

#2705 serve audit: auth.token.used hardcodes principalKind user for worker tokens

Opened by stack72 · 9/29/2026· Shipped 9/29/2026

In src/serve/token_auth.ts (emit for auth.token.used, around line 313) the audit event sets principalKind to the literal user for every token, and principalId to the full kind-prefixed principal string (for example worker:build-1). A worker token therefore audits as principalKind user with principalId worker:build-1, which is inconsistent with other serve audit events (audited.ts, shared.ts) that store the kind in principalKind and the bare id in principalId. Audit query filters, alert matches and compliance reports that group on principalKind/principalId get the wrong answer for worker tokens. Fix: parse the principal (parsePrincipal) and use its kind and id. Found while triaging swamp-club#2464.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 10 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/29/2026, 8:28:52 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
stack72 assigned stack729/29/2026, 7:10:02 PM

Sign in to post a ripple.