Problem/Motivation

Audit Chain exposes settings, Drush verification, the status report, and the evidence exporter. There is no in-browser report of whether the chain last verified or whether recent rows were HMAC-signed. Operators should not need Drush for the module's headline claim.

Proposed resolution

Add a read-only reports page at /admin/reports/audit-chain:

  • Integrity card from the last scheduled-verification record. The page does not re-walk the chain on GET.
  • Keyed-vs-unkeyed split over a 24h / 7d / 30d window, from indexed timestamp and key_id only.
  • Optional Charts API upgrade when a library plugin is present (for example charts_chartjs). Inline SVG fallback when Charts is absent or enabled without a library. The page must never print "No charting library found".
  • Restrict-access permission view audit chain reports.

This is an integrity report, not an operational dashboard. Volume, channel mix, and operation mix stay off the page; those belong in dblog or a consumer module.

No row listing. Metadata, IP addresses, user agents, and entity labels are never queried.

Remaining tasks

  • Land on 1.x (done).
  • Ship in 1.7.0.

User interface changes

New Reports → Audit Chain page. Settings form unchanged.

API changes

None. Optional composer suggest of drupal/charts.

Data model changes

None.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Version: 1.x-dev » 1.7.0

Shipped in 1.7.0.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.