Skip to content

@aauth/call-log 0.1.0: the aauth.call record, at each end - #30

Merged
dickhardt merged 3 commits into
mainfrom
call-log
Sep 25, 2026
Merged

dickhardt merged 3 commits into
mainfrom
call-log

Conversation

@dickhardt

Copy link
Copy Markdown
Contributor

The shared logging code for the AAuth call log (aauth-dev/monitor plan/CALL_LOG_PLAN.md, step 6): one aauth.call record per HTTP call between AAuth roles, at each end, per plan/CALL_RECORD.md. Wallet already writes these from its own Fastify hooks (#4334); this is the same builder for the fleet's Hono workers.

  • record.ts — pure: call_id = SHA-256 of the Signature header; tokens as {type, payload} anywhere in a body; the signer and caller from Signature-Key (no verification); AAuth-Requirement / Signature-Error / AAuth-Budget / Location parsed; levels; the 30 KB cap that cuts the larger body to text.
  • callee.ts — a Hono-shaped middleware, typed against c.req.raw / c.res / c.executionCtx only. Names the call before the handler, reads the cloned bodies in waitUntil, skips OPTIONS/HEAD/.well-known/health.
  • caller.ts — loggedFetch for @aauth/agent's createSignedFetch (one signed fetch per call via onSigned, so concurrent calls never swap reports), loggedHttpsigFetch for @hellocoop/httpsig (returnSent), failedFetch for a fetch that can't be wrapped. The response is cloned before the caller gets it, and read later.
  • context.ts — parent in AsyncLocalStorage (decided 2026-09-25): the middleware runs the handler inside it; a logged fetch reads it; parent can be passed explicitly where the chain is broken on purpose. nameAgent lets a verifier tell the record which agent a person-token call is for.
  • No dependencies. node:async_hooks under nodejs_compat.

17 tests. Added to the workspace, the vitest aliases and the release build/publish list. No other package changes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SdTYzN8NvzehCVCSqhadH5

dickhardt and others added 3 commits September 25, 2026 22:44
One log record per HTTP call between AAuth roles. A pure builder (tokens
as type + payload, the signer from Signature-Key, the three AAuth headers
parsed, the 30 KB cap), a Hono-shaped middleware for the callee side, and
logged fetch wrappers for the caller side (@aauth/agent's onSigned, or
@hellocoop/httpsig's returnSent). `parent` rides in AsyncLocalStorage from
the middleware to any logged fetch in its continuation.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SdTYzN8NvzehCVCSqhadH5
The monitor learns which agent holds a key from any record that names
both, and fills in the rows where only the key is known.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SdTYzN8NvzehCVCSqhadH5
@dickhardt
dickhardt merged commit a81a047 into main Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant