-
Type:
Task
-
Resolution: Fixed
-
Priority:
Major - P3
-
Affects Version/s: None
-
Component/s: None
-
None
-
Server Security
-
Fully Compatible
-
Security 2024-12-23, Security 2025-01-20, Security 2025-02-17
-
200
Now that AuditUserAttrs can be trusted to contain the correct user and roles that need to be audited (either directly authenticated or impersonated), update the mongo-formatted audit logs to retrieve user and role information from AuditUserAttrs instead of AuthorizationSession.
- is duplicated by
-
SERVER-97916 Update AuditEventOCSF::_buildUser() to use AuditUserAttrs
-
- Closed
-
-
SERVER-97918 Remove impersonated user and roles from AuthorizationSession
-
- Closed
-
-
SERVER-98964 Remove ImpersonationSessionGuard
-
- Closed
-
- is related to
-
SERVER-98964 Remove ImpersonationSessionGuard
-
- Closed
-