The rest of the request log's fields #79

Open
opened 2026-10-06 11:41:19 +02:00 by clawbot · 1 comment
Collaborator

The request log line gets the rest of the fields "Request log" in SPEC.md lists, for every feature that exists by then. The build order in SPEC.md puts "the rest of the request log's fields" in the first stage after milestone 2; milestones 1 and 2 log only part of them.

What it builds

  • Compare the fields internal/requestlog writes with the list in "Request log", and add every missing one whose feature is built: among them, as far as they are missing, instance (with SWWAF_INSTANCE, as "Configuration surface" describes it), request_id (taken from traefik's header or generated, and passed to the app), peer_ip, forwarded_for, client_group, content_type, content_length, the headers named in SWWAF_LOG_REQUEST_HEADERS, has_authorization, has_cookie, websocket, response_content_type, upstream_status, cache_control, location, aborted, counts, offence, ban_expires, and the timings duration_total, duration_checks, duration_upstream_connect, duration_upstream_first_byte, duration_upstream_total.
  • Fields for features not built yet (asn, as_name, limit_percent, rule_ids, waf_rule_ids, waf_score, reputation, duration_waf, would_action if observe mode is not on next yet) come with those features; the PR body lists them in one line.
  • Bodies are never logged; header values named in SWWAF_LOG_REQUEST_HEADERS are logged as received, and Authorization and Cookie only as booleans, whatever that setting says.
  • README.md's description of the log line follows.

Definition of done

  • Tests show each added field on a request where it applies and absent where it does not, request_id passed to the app and kept from traefik's header, the timings present and ordered sensibly, and Authorization and Cookie never logged as values.
  • make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

The request log line gets the rest of the fields "Request log" in `SPEC.md` lists, for every feature that exists by then. The build order in `SPEC.md` puts "the rest of the request log's fields" in the first stage after milestone 2; milestones 1 and 2 log only part of them. ## What it builds - Compare the fields `internal/requestlog` writes with the list in "Request log", and add every missing one whose feature is built: among them, as far as they are missing, `instance` (with `SWWAF_INSTANCE`, as "Configuration surface" describes it), `request_id` (taken from traefik's header or generated, and passed to the app), `peer_ip`, `forwarded_for`, `client_group`, `content_type`, `content_length`, the headers named in `SWWAF_LOG_REQUEST_HEADERS`, `has_authorization`, `has_cookie`, `websocket`, `response_content_type`, `upstream_status`, `cache_control`, `location`, `aborted`, `counts`, `offence`, `ban_expires`, and the timings `duration_total`, `duration_checks`, `duration_upstream_connect`, `duration_upstream_first_byte`, `duration_upstream_total`. - Fields for features not built yet (`asn`, `as_name`, `limit_percent`, `rule_ids`, `waf_rule_ids`, `waf_score`, `reputation`, `duration_waf`, `would_action` if observe mode is not on `next` yet) come with those features; the PR body lists them in one line. - Bodies are never logged; header values named in `SWWAF_LOG_REQUEST_HEADERS` are logged as received, and `Authorization` and `Cookie` only as booleans, whatever that setting says. - `README.md`'s description of the log line follows. ## Definition of done - Tests show each added field on a request where it applies and absent where it does not, `request_id` passed to the app and kept from traefik's header, the timings present and ordered sensibly, and `Authorization` and `Cookie` never logged as values. - `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-06 11:41:19 +02:00
Author
Collaborator

The fields are in #82.

Model: opus-5-5

The fields are in https://git.eeqj.de/sneak/smallwebwaf/pulls/82. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#79