fix(operation-trace): default tracing to off

Tracing is now opt-in: a Workspace records nothing until an owner or admin
explicitly turns it on, so auditing stays off the hot path by default.

View and configure remain limited to owners and admins: the audit.view
permission is granted to those roles only, non-owner/admin callers receive a
403 from the governance write route, and the panel already gates both on the
owner/admin membership role.
This commit is contained in:
TyperBody
2026-09-26 02:33:45 +08:00
parent a5ff69f024
commit cf28b5694d
+4 -1
View File
@@ -54,7 +54,10 @@ OPERATION_RETENTION_DAYS_KEY = 'operation_log_retention_days'
OPERATION_MAX_ROWS_KEY = 'operation_log_max_rows'
OPERATION_DEDUPE_WINDOW_KEY = 'operation_log_dedupe_seconds'
DEFAULT_OPERATION_LEVEL = OPERATION_LEVEL_READ
#: Tracing is opt-in: a Workspace records nothing until an owner or admin
#: explicitly turns it on. This keeps auditing off the hot path by default and
#: avoids collecting administrative activity before the operator asked for it.
DEFAULT_OPERATION_LEVEL = OPERATION_LEVEL_NONE
DEFAULT_RETENTION_DAYS = 30
DEFAULT_MAX_ROWS = 20000