Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove 3.0 from "Servlet 3.0 APIs" in the audit event description #7629

Closed
una-tapa opened this issue Oct 11, 2024 · 4 comments · Fixed by #7653
Closed

Remove 3.0 from "Servlet 3.0 APIs" in the audit event description #7629

una-tapa opened this issue Oct 11, 2024 · 4 comments · Fixed by #7653
Assignees
Milestone

Comments

@una-tapa
Copy link
Member

una-tapa commented Oct 11, 2024

In the following documentation,
https://openliberty.io/docs/latest/audit-log-events-list-cadf.html#_security_api_authn
https://openliberty.io/docs/latest/json-log-events-list.html#_supported_audit_events_and_their_audit_data

Please remove 3.0 from "Servlet 3.0 APIs" to make it clear that the audit events applies to all servlet releases after 3.0 (4.0+)

Current Description:

You can use the SECURITY_API_AUTHN event to capture the audit information from the login and authentication for servlet 3.0 APIs. The following table provides the fields for the SECURITY_API_AUTHN event and a description of each field.

When this issue is addressed, I would like to see..

You can use the SECURITY_API_AUTHN event to capture the audit information from the login and authentication for servlet APIs. The following table provides the fields for the SECURITY_API_AUTHN event and a description of each field.

I got @volosied and @jhanders34 's assistance (private link) to confirm that the audit tests cover the EE 6 through 10 features to verify that the audits are correctly processed and E11 will also be added soon.

@dmuelle dmuelle added this to the 24.0.0.11 milestone Oct 11, 2024
ramkumar-k-9286 added a commit that referenced this issue Oct 15, 2024
7629-Remove 3.0-Servlet 3.0 APIs-audit event description-1

#7629
@ramkumar-k-9286
Copy link
Contributor

@una-tapa
Copy link
Member Author

@ramkumar-k-9286

Thank you for your help with the update.

I noticed that when searching for "servlet" on the pages, there are still references to the functionality being limited to Servlet 3.0. Since the content applies to versions 4.0, 5.0, 6.0, and beyond, we don't want to restrict it to 3.0. Could you please review the pages and remove all mentions of specific servlet versions?

I apologize for initially requesting changes to just one paragraph. Thanks again for your assistance.

ramkumar-k-9286 added a commit that referenced this issue Oct 17, 2024
7629-Remove 3.0-Servlet 3.0 APIs-audit event description-2

#7629
@ramkumar-k-9286
Copy link
Contributor

Hi @una-tapa

Suggested corrections have been made.

Draft links:

Audit log events reference list (CADF format)

JSON log events reference list

Please review the same and add the Developer Reviewed label if you are satisfied with the changes.

Regards,
Ramkumar.

CC @dmuelle

@una-tapa
Copy link
Member Author

Looks great! Thanks @ramkumar-k-9286

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants