Skip to content

Add receipt audit exports, retention, and SOAR certificate trust improvements - #2

Merged
Shorton88 merged 2 commits into
mainfrom
codex/receipt-audit-exports
Sep 22, 2026
Merged

Shorton88 merged 2 commits into
mainfrom
codex/receipt-audit-exports

Conversation

@Shorton88

@Shorton88 Shorton88 commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

ActionStack 0.5.6 adds receipt timeline and audit exports, optional retention of delivered submissions, and improved SOAR certificate trust handling.

  • Add Grouped and Timeline receipt views, downloadable receipt JSON, and CSV export of filtered submissions across pages (up to the existing 200-record limit). Exports retain identity, scope, refresh errors, and truncation flags. The timeline uses reported run timestamps and does not reconstruct historical status changes.
  • Load standard Linux system CA bundles alongside Python's default trust sources, unless SSL_CERT_FILE or SSL_CERT_DIR explicitly overrides them. Preserve hostname and certificate verification. Report verification failures separately from other TLS or connectivity errors.
  • Add an admin-controlled retention setting, disabled by default. Opening or refreshing Submissions removes up to 100 expired delivered receipts per hour across search heads. Preserve failed, unconfirmed, and locked requests, SOAR events, audit entries, and minimal submission ID markers that prevent duplicate delivery. Cleanup is on-access, not a background schedule; administrators should export records before enabling it.
  • Describe the project in README as AI-driven, intended to be useful to the community, maintained on a best-effort basis, and provided without warranty under the existing MIT license.

Validation: all 39 JavaScript and 187 Python tests pass; production build and the 0.5.6 package succeed. Browser checks cover both themes, retention selection, timeline ordering, custom action names, filtered CSV export, receipt JSON, and failed activity refreshes. Tests cover retention boundaries, shared batch limits, preserved unfinished requests, duplicate prevention, runtime CA overrides, and TLS error reporting. SOAR responses were simulated. Live Splunk/SOAR validation and AppInspect remain required before release; the original deployment's certificate failure has not been reproduced.

@Shorton88 Shorton88 changed the title Add receipt timeline and audit exports Add receipt audit exports, retention, and SOAR certificate trust improvements Sep 22, 2026
@Shorton88
Shorton88 merged commit 10278db into main Sep 22, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant