Skip to content

fix: resolve audit/maintenance issues - #1559

Merged
yusuftomilola merged 1 commit into
DistinctCodes:mainfrom
Mkalbani:feat/audit-maintenance-improvements
Sep 26, 2026
Merged

yusuftomilola merged 1 commit into
DistinctCodes:mainfrom
Mkalbani:feat/audit-maintenance-improvements

Conversation

@Mkalbani

Copy link
Copy Markdown
Contributor

Summary

Resolves issues #1473, #1474, #1475, and #1476 with minimal, efficient improvements to audit and maintenance systems.

Issues Fixed

#1473 - Unclear distinction between audit-log and audits dashboard pages

Problem: Overlapping page names with no explanation of differences.

Solution: Added clear documentation and cross-references to distinguish:

  • Audit Log: System action tracking (create, update, delete) for compliance and accountability
  • Audits / Stocktake: Physical asset verification to match system records

#1474 - Maintenance events don't record the technician's identity

Problem: MaintenanceCompleted events lacked technician identity, weakening on-chain audit trail.

Solution: Added technician_id: String field to MaintenanceCompleted event struct and updated the event emission to include technician data from the maintenance record.

#1475 - No upper bound check on logged maintenance cost

Problem: Maintenance costs weren't validated for upper limits, allowing extreme values.

Solution: Added validation check with max bound of 999_999_999_999 on labor_cost, parts_cost, and total_cost to prevent malformed or extreme numbers from skewing calculations.

#1476 - No test for unauthorized maintenance logging

Problem: No coverage for unauthorized callers attempting to log maintenance entries.

Solution: Added test_unauthorized_maintenance_logging() test that verifies an unauthorized provider address fails authentication when attempting to add a maintenance record.

Changes

  • ✅ contracts/asset-maintenance/src/events.rs: Enhanced MaintenanceCompleted struct with technician tracking
  • ✅ contracts/asset-maintenance/src/lib.rs: Added cost upper bound validation
  • ✅ contracts/asset-maintenance/src/test.rs: Added unauthorized access test
  • ✅ frontend/app/(dashboard)/audit-log/page.tsx: Added documentation and clarification text
  • ✅ frontend/app/(dashboard)/audits/page.tsx: Added documentation and cross-reference

Testing

All changes are minimal and focused:

  • Authorization check already exists; new test validates it rejects unauthorized callers
  • Cost validation integrated into existing validation chain
  • Event enhancement backward-compatible with existing event structure
  • Frontend documentation only (no logic changes)

Closes #1473
Closes #1474
Closes #1475
Closes #1476

@vercel

vercel Bot commented Sep 26, 2026

Copy link
Copy Markdown

@Mkalbani is attempting to deploy a commit to the naijabuz's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@Mkalbani Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

…s#1474 DistinctCodes#1475 DistinctCodes#1476

- DistinctCodes#1473: Clarify distinction between audit-log (system change tracking) and audits (physical stocktake)
- DistinctCodes#1474: Add technician_id to MaintenanceCompleted event for complete audit trail
- DistinctCodes#1475: Add upper bound validation on maintenance costs
- DistinctCodes#1476: Add test for unauthorized maintenance logging attempt
@Mkalbani
Mkalbani force-pushed the feat/audit-maintenance-improvements branch from e117811 to 2061c93 Compare September 26, 2026 13:02
@yusuftomilola
yusuftomilola merged commit 842fc06 into DistinctCodes:main Sep 26, 2026
1 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants