/api/v1/businesses/:businessId/audit-events
auth: jwt (administrator | view_audit)Paginated audit log for a business. Supports filters by eventType (comma-separated → IN clause), resourceType, resourceId, dateFrom/dateTo (epoch ms), and a search term (matches ResourceId or ActorEmail with %term%). Returns items + total + stats (fiscalised/failed/actors counts). Fires VIEW_AUDIT_LOG fire-and-forget after the response is sent.
handlers: AuditController.list
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. Caller's JWT businessId must match (Administrator bypasses via requireBusinessAccess). |
page queryint | no | 1 | 1-based page number; clamped to >= 1. |
pageSize queryint | no | 20 | Page size, clamped 1..100. |
eventType querystring | no | — | AuditEventType, optionally comma-separated for IN(). |
resourceType querystring | no | — | Filter by ResourceType (INVOICE, USER, XERO_CONNECTION, ...). |
resourceId querystring | no | — | Filter by exact ResourceId. |
dateFrom queryint (epoch ms) | no | — | Inclusive lower bound on CreatedAt. |
dateTo queryint (epoch ms) | no | — | Inclusive upper bound on CreatedAt. |
search querystring | no | — | Substring match against ResourceId or ActorEmail. |
APIResponseDataObject<{ items: AuditLogDTO[]; total: number; page: number; totalPages: number; stats: { fiscalised: number; failed: number; actors: number } }>APIError/api/v1/businesses/:businessId/audit-events/export
auth: jwt (administrator)Stream all matching audit events as CSV (Content-Disposition: attachment; filename=audit-log-<businessId>-<yyyy-mm-dd>.csv). Same filters as the list endpoint; Administrator only (requireAdmin). Registered before /:id so Express does not treat 'export' as an id param.
handlers: AuditController.export
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. Administrator bypasses requireBusinessAccess. |
eventType querystring | no | — | AuditEventType, optionally comma-separated. |
resourceType querystring | no | — | Filter by ResourceType. |
resourceId querystring | no | — | Filter by exact ResourceId. |
dateFrom queryint (epoch ms) | no | — | Inclusive lower bound on CreatedAt. |
dateTo queryint (epoch ms) | no | — | Inclusive upper bound on CreatedAt. |
search querystring | no | — | Substring match against ResourceId or ActorEmail. |
text/csvAPIError/api/v1/businesses/:businessId/audit-events/:id
auth: jwt (administrator | view_audit)Fetch a single audit log entry by its BIGINT AuditLogId. Scoped to the business.
handlers: AuditController.getById
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. |
id pathint (BIGINT) | yes | — | AuditLogs.AuditLogId — numeric, parsed via parseInt. |
APIResponseDataObject<AuditLogDTO>APIErrorAPIErrorAPIError