The request log line gets the rest of the fields "Request log" in SPEC.md lists, for every feature that exists by then. The build order in SPEC.md puts "the rest of the request log's fields" in the first stage after milestone 2; milestones 1 and 2 log only part of them.
What it builds
Compare the fields internal/requestlog writes with the list in "Request log", and add every missing one whose feature is built: among them, as far as they are missing, instance (with SWWAF_INSTANCE, as "Configuration surface" describes it), request_id (taken from traefik's header or generated, and passed to the app), peer_ip, forwarded_for, client_group, content_type, content_length, the headers named in SWWAF_LOG_REQUEST_HEADERS, has_authorization, has_cookie, websocket, response_content_type, upstream_status, cache_control, location, aborted, counts, offence, ban_expires, and the timings duration_total, duration_checks, duration_upstream_connect, duration_upstream_first_byte, duration_upstream_total.
Fields for features not built yet (asn, as_name, limit_percent, rule_ids, waf_rule_ids, waf_score, reputation, duration_waf, would_action if observe mode is not on next yet) come with those features; the PR body lists them in one line.
Bodies are never logged; header values named in SWWAF_LOG_REQUEST_HEADERS are logged as received, and Authorization and Cookie only as booleans, whatever that setting says.
README.md's description of the log line follows.
Definition of done
Tests show each added field on a request where it applies and absent where it does not, request_id passed to the app and kept from traefik's header, the timings present and ordered sensibly, and Authorization and Cookie never logged as values.
make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
The request log line gets the rest of the fields "Request log" in `SPEC.md` lists, for every feature that exists by then. The build order in `SPEC.md` puts "the rest of the request log's fields" in the first stage after milestone 2; milestones 1 and 2 log only part of them.
## What it builds
- Compare the fields `internal/requestlog` writes with the list in "Request log", and add every missing one whose feature is built: among them, as far as they are missing, `instance` (with `SWWAF_INSTANCE`, as "Configuration surface" describes it), `request_id` (taken from traefik's header or generated, and passed to the app), `peer_ip`, `forwarded_for`, `client_group`, `content_type`, `content_length`, the headers named in `SWWAF_LOG_REQUEST_HEADERS`, `has_authorization`, `has_cookie`, `websocket`, `response_content_type`, `upstream_status`, `cache_control`, `location`, `aborted`, `counts`, `offence`, `ban_expires`, and the timings `duration_total`, `duration_checks`, `duration_upstream_connect`, `duration_upstream_first_byte`, `duration_upstream_total`.
- Fields for features not built yet (`asn`, `as_name`, `limit_percent`, `rule_ids`, `waf_rule_ids`, `waf_score`, `reputation`, `duration_waf`, `would_action` if observe mode is not on `next` yet) come with those features; the PR body lists them in one line.
- Bodies are never logged; header values named in `SWWAF_LOG_REQUEST_HEADERS` are logged as received, and `Authorization` and `Cookie` only as booleans, whatever that setting says.
- `README.md`'s description of the log line follows.
## Definition of done
- Tests show each added field on a request where it applies and absent where it does not, `request_id` passed to the app and kept from traefik's header, the timings present and ordered sensibly, and `Authorization` and `Cookie` never logged as values.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 11:41:19 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The request log line gets the rest of the fields "Request log" in
SPEC.mdlists, for every feature that exists by then. The build order inSPEC.mdputs "the rest of the request log's fields" in the first stage after milestone 2; milestones 1 and 2 log only part of them.What it builds
internal/requestlogwrites with the list in "Request log", and add every missing one whose feature is built: among them, as far as they are missing,instance(withSWWAF_INSTANCE, as "Configuration surface" describes it),request_id(taken from traefik's header or generated, and passed to the app),peer_ip,forwarded_for,client_group,content_type,content_length, the headers named inSWWAF_LOG_REQUEST_HEADERS,has_authorization,has_cookie,websocket,response_content_type,upstream_status,cache_control,location,aborted,counts,offence,ban_expires, and the timingsduration_total,duration_checks,duration_upstream_connect,duration_upstream_first_byte,duration_upstream_total.asn,as_name,limit_percent,rule_ids,waf_rule_ids,waf_score,reputation,duration_waf,would_actionif observe mode is not onnextyet) come with those features; the PR body lists them in one line.SWWAF_LOG_REQUEST_HEADERSare logged as received, andAuthorizationandCookieonly as booleans, whatever that setting says.README.md's description of the log line follows.Definition of done
request_idpassed to the app and kept from traefik's header, the timings present and ordered sensibly, andAuthorizationandCookienever logged as values.make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
The fields are in #82.
Model: opus-5-5