[Foundation] Complete Record Revision History, Reliable Audit Trail, Auditor Access and Archive Readiness #10
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
#8 [Feature] Storage Driver Abstraction (S3-Compatible & WebDAV / Nextcloud)
JackPrince/GoBDLogBook
Reference
JackPrince/GoBDLogBook#10
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The application already records several trip changes, requires correction reasons and protects audit records using database triggers and a tenant-specific hash chain. However, revision coverage, auditor access and human-readable change history are incomplete. Receipt replacement can remove previous files, period closure changes records without individual revisions, and the exported offline verifier does not match the current audit payload.
Adding S3 Object Lock alone would preserve these gaps.
Objective
Establish complete, attributable and inspectable record history in the application before introducing external WORM storage. Preserve legitimate corrections while ensuring that original records, subsequent changes and supporting documents remain available.
Required capabilities
Acceptance criteria
A tenant auditor can independently identify, inspect and export corrections and historical attachments. Every supported write path produces a corresponding revision and audit event. Concurrent edits cannot silently overwrite one another. Period amendments preserve the original closure. Backend and offline verification agree and detect tested tampering and missing evidence.
Boundaries
S3 Object Lock integration belongs to issue #8. Database backups, snapshots and disaster recovery belong to issue #9. This issue establishes application-level evidence and WORM readiness; it does not claim external WORM protection or automatic legal certification.
[Foundation] Complete Record Revision History, Reliable Audit Trail and Auditor Access — Prerequisite for WORM Storage**to [Foundation] Complete Record Revision History, Reliable Audit Trail, Auditor Access and Archive Readiness