CodamAIDocs
Topicdone

Audit is not the same as system fields

The difference between _createdOn on the object and the revision history.

Variants
_createdOn_updatedOn_userIdhistorynot audited model

What this is about

Two things in CDMS look similar and are often confused:

  • System fields such as _createdOn, _updatedOn and _userId are on the object itself. Every model has them. They show a single value, the current one. See System fields that the server sets.
  • The history is a list of revisions. Only audited models have it. It shows every state the object ever had, with person and time.

Side by side

System fields and history
System fields
on the object
  • exist for every model
  • one value per field, always the current one
  • _createdOn: time of creation
  • _updatedOn: last PUT or PATCH
  • _userId: who owns the object, only for user models
  • come along with every read and search
  • gone as soon as the object is deleted
History
revisions
  • only for audited models
  • every state the object ever had
  • every change: create, PUT, PATCH, upload, rollback, delete
  • with person, time, IP address and user agent
  • endpoint and role of its own
  • stays readable after deleting

Which question is answered by what?

QuestionSystem fieldsHistory
When was the object created?_createdOnts of the ADD revision
When was it last changed?_updatedOn, but only PUT and PATCHts of the newest revision, any kind of change
Who created it?for user models the person in _userId, otherwise notusername of the ADD revision
Who changed it last?cannot be answeredusername of the newest revision
What was in it before?cannot be answeredrevision of the older revisions
Was it deleted, and by whom?cannot be answered, the object is gonethe DEL revision

Where they meet

System fields and history working together

When: set on create

Never changes after that, not even on a rollback. The ADD revision carries almost the same time in revisionMeta.ts. It is only created at the end of the request, so a fraction of a second later. For models that were audited only later, this revision is missing.

When: set to now on every PUT and PATCH

It stays empty on create and unchanged on a rollback. So a rollback is a change that _updatedOn does not show, but the history does: as a new MOD revision.

When: only for user models, set on create

Says who owns the object and drives the owner filter. It does not say who changed it last. That is only in the history.

Result: See Only your own data (owner filter).

When: for audited models, on every change

Every revision records the whole state, including the system fields. Through + and *, however, the history only returns the business fields, _createdOn and _updatedOn are empty there. You read the time of a revision from revisionMeta.ts.

When: Auditing is off.

There are only the system fields. CDMS does not know who changed something and what was in it before.

Pitfalls

What comes next

Sources in the code and the knowledge base
  • CDMS/cdms-persistence-database – models/AbstractEntityModel (_createdOn, _updatedOn, @Audited), AuditHistoryReader.historyRollback (_updatedOn stays), recursiveRemoveObjects
  • CDMS/cdms-system-layer – AbstractLayer (recursiveCreate: _createdOn/_userId; PUT/PATCH: _updatedOn)
  • CDMS/cdms-rest-api – AbstractRestApi.getHistory (only fields from the response)
  • CDMS/cdms-integrationtest – probe: history with "*" returns _createdOn/_updatedOn empty
  • documentation/50-auditierung/01-auditing-und-historie.md (auditing ≠ system fields)
Search