Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
<parent>
<groupId>org.jenkins-ci.plugins</groupId>
<artifactId>plugin</artifactId>
<version>4.18</version>
<version>4.38</version>
<relativePath />
</parent>

Expand All @@ -14,7 +14,7 @@
<name>Audit Trail</name>
<version>3.11-SNAPSHOT</version>
<properties>
<jenkins.version>2.263.1</jenkins.version>
<jenkins.version>2.319.1</jenkins.version>
<java.level>8</java.level>
<slf4jVersion>1.7.30</slf4jVersion>
</properties>
Expand Down Expand Up @@ -80,6 +80,7 @@
<dependency>
<groupId>org.jenkins-ci.plugins</groupId>
<artifactId>credentials</artifactId>
<version>999999-SNAPSHOT</version>
</dependency>
</dependencies>

Expand Down Expand Up @@ -116,8 +117,8 @@
<dependencies>
<dependency>
<groupId>io.jenkins.tools.bom</groupId>
<artifactId>bom-2.263.x</artifactId>
<version>807.v6d348e44c987</version>
<artifactId>bom-2.319.x</artifactId>
<version>1210.vcd41f6657f03</version>
<scope>import</scope>
<type>pom</type>
</dependency>
Expand All @@ -129,7 +130,6 @@
Does not include caffeine in the hpi file. -->
<groupId>com.github.ben-manes.caffeine</groupId>
<artifactId>caffeine</artifactId>
<version>2.9.1</version>
<exclusions>
<!-- do not bring in the annotations -->
<exclusion>
Expand Down
14 changes: 12 additions & 2 deletions src/main/java/hudson/plugins/audit_trail/AuditTrailPlugin.java
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ public class AuditTrailPlugin extends GlobalConfiguration {

private static final Logger LOGGER = Logger.getLogger(AuditTrailPlugin.class.getName());
private boolean logBuildCause = true;

private boolean logCredentialsUsage = true;
private List<AuditLogger> loggers = new ArrayList<>();

private transient String log;
Expand Down Expand Up @@ -108,11 +108,15 @@ public class AuditTrailPlugin extends GlobalConfiguration {
public boolean getLogBuildCause() {
return shouldLogBuildCause();
}

public boolean shouldLogBuildCause() {
return logBuildCause;
}

public boolean getLogCredentialsUsage() { return shouldLogCredentialsUsage(); }

public boolean shouldLogCredentialsUsage() { return logCredentialsUsage; }

public List<AuditLogger> getLoggers() { return loggers; }

public AuditTrailPlugin() {
Expand Down Expand Up @@ -155,6 +159,12 @@ public void setLogBuildCause(boolean logBuildCause) {
save();
}

@DataBoundSetter
public void setLogCredentialsUsage(boolean logCredentialsUsage) {
this.logCredentialsUsage = logCredentialsUsage;
save();
}

private void updateFilterPattern() {
try {
AuditTrailFilter.setPattern(pattern);
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
package hudson.plugins.audit_trail;

import com.cloudbees.plugins.credentials.Credentials;
import com.cloudbees.plugins.credentials.CredentialsUseListener;
import com.cloudbees.plugins.credentials.impl.BaseStandardCredentials;
import hudson.Extension;
import hudson.model.AbstractModelObject;
import hudson.model.Item;
import hudson.model.Run;

import javax.inject.Inject;
import java.util.logging.Level;
import java.util.logging.Logger;


@Extension
public class CredentialUsageListener extends CredentialsUseListener {
@Inject
AuditTrailPlugin configuration;

@Override
public void onUse(Credentials c, AbstractModelObject obj) {
if (!configuration.shouldLogCredentialsUsage())
return;

StringBuilder builder = new StringBuilder(100);
String objName = obj.toString();
String objType = obj.getClass().toString();
builder.append("'" + objName
+ "' (" + objType + ") ");
auditlog(c, builder);
}

@Override
public void onUse(Credentials c, Item item) {
if (!configuration.shouldLogCredentialsUsage())
return;

StringBuilder builder = new StringBuilder(100);
String itemName = item.getFullDisplayName();
String itemType = item.getClass().toString();

builder.append("'" + itemName
+ "' (" + itemType + ") ");

auditlog(c, builder);
}

private void auditlog(Credentials c, StringBuilder builder) {
String credsType = c.getClass().toString();
if (!(c instanceof BaseStandardCredentials)) {
builder.append("used an unsupported credentials type (" + credsType + ") that can't be audit-logged");
Logger.getLogger(CredentialUsageListener.class.getName()).log(Level.WARNING, null,builder.toString());
return;
}

String credsId = ((BaseStandardCredentials) c).getId();

builder.append("used credentials '" + credsId + "' (" + credsType + ").");

for (AuditLogger logger : configuration.getLoggers()) {
logger.log(builder.toString());
}
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@
<f:entry title="${%Log how each build is triggered}">
<f:checkbox name="logBuildCause" checked="${descriptor.logBuildCause}"/>
</f:entry>
<f:entry title="${%Log credentials usage}">
<f:checkbox name="logCredentialsUsage" checked="${descriptor.logCredentialsUsage}"/>
</f:entry>
</f:advanced>
</f:section>
</j:jelly>