Skip to content

feat(examples): add audit trail forensic export bridge with independent verification (#65) - #69

Merged
Eras256 merged 1 commit into
nirium-protocol:mainfrom
Santia2004:feat/examples-audit-forensic-bridge
Aug 26, 2026
Merged

Eras256 merged 1 commit into
nirium-protocol:mainfrom
Santia2004:feat/examples-audit-forensic-bridge

Conversation

@Santia2004

Copy link
Copy Markdown
Contributor

Closes #65

Summary

Implements the Forensic Audit Hub Bridge example under examples/audit-forensic-bridge/ demonstrating:

  • Ingestion of webhook events via an Express listener.
  • Direct raw JSON SHA-256 calculation (sha256(JSON.stringify(record))) without key-sorting to preserve insertion order matching the Nirium server specification.
  • Domain-separated agent attestation (nirium-audit-v1:<content_sha256>) signed with an ed25519 Stellar keypair.
  • Automated IPFS anchoring using Agent.anchorAuditRecord().
  • Scheduled/manual export and independent verification (src/export.ts): pulls Agent.getReportingExport('anchors'), retrieves raw content from IPFS gateways, and independently re-verifies SHA-256 and agent signatures rather than trusting API metadata.
  • Unit test suite covering raw hashing behavior, valid attestations, tampered record detection, and domain separation enforcement.
  • Plain-terms README explaining why recomputing hashes locally prevents signature forgery.

Verification

  • Unit tests: npx tsx --test test/bridge.test.ts (4/4 passing).

@Eras256

Eras256 commented Aug 26, 2026

Copy link
Copy Markdown
Collaborator

Merged — verified independently from a clean clone, not just reading the diff. computeRecordSha256 uses a plain JSON.stringify, no key-sorting, and the test proves it (hash changes on key reorder — exactly the failure mode a canonicalizer that alphabetizes would hide). verifyAuditAttestation recomputes from the record rather than trusting an embedded claim. 4/4 tests pass from pnpm install + pnpm test on a fresh checkout. Good work — this is exactly the discipline the issue asked for.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Advanced] Audit Trail forensic export bridge — webhook events auto-anchored + verified reporting export

2 participants