Skip to content

docs(audit): README and NewServer comment overstate what the purchase audit log records #27

Description

@cristim

Follow-up from the review of #26 (merged). Verified on the merged head by driving cmd/cudly-mcp over real stdio:

  • The README 'Audit log' section says every purchase attempt is appended. Attempts refused before the provider call (operator gate off, missing credential scope, dry_run/confirm validation errors) write no record. Either reword it to 'each preview and each attempt that reaches the provider', or also audit refusals, which is arguably more useful for an audit trail.
  • The server.go NewServer comment says a server with an unusable audit log 'should not accept purchase calls at all'. Only startup is gated; a write failure during a call warns on stderr and leaves the result unchanged (as the README documents). Reword the comment.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions