v0.5.0
Campsend now keeps a record of what happened, for the person it happened to.
An audit log
Wide events answer an operator's question during an incident, for as long as the logs are kept. They could never answer a customer's: who revoked that delivery, and when, months later, after the records involved may be gone.
audit_events is an append-only table recording deliveries created, scheduled, canceled, revoked and rotated, files replaced and removed, tokens created and revoked, recipients opening and downloading, and every refusal the policy raised.
Three things make it worth reading a year on:
- Identities are snapshotted. A deleted user's actions stay attributable and a deleted delivery still has a name, because the label is written at the time rather than looked up later.
- Refusals are kept. A free account hitting the monthly delivery limit is the highest-signal row in the table, and nothing kept it before.
- Rows join to wide events through
request_id, so an operator and a customer can look at the same moment from their own side.
Rows are removed after a year by SecurityCleanupJob.
Two ways to read it
Every delivery page shows its own history. /activity shows the account's, filtered by action and by date rather than by free text.
A recipient's actions appear in the sender's log, named as the recipient. Another account's log is not found rather than forbidden.
Self-hosting
Nothing here is gated. A self-hosted installation gets the same table, the same retention and the same pages.
Full changelog: v0.4.0...v0.5.0