Skip to content

call-log 0.1.1: tokenize parsed headers, tolerate Hono's executionCtx getter, accept httpsig's fetch - #31

Merged
dickhardt merged 1 commit into
mainfrom
call-log-0.1.1
Sep 27, 2026
Merged

dickhardt merged 1 commit into
mainfrom
call-log-0.1.1

Conversation

@dickhardt

Copy link
Copy Markdown
Contributor

Three defects in @aauth/call-log 0.1.0, found while wiring the seven fleet workers today (access #9, senzing #12, test-resource #2, whoami #3, notes #4, web-agent-demo #7, registry #9). Each worker carries a guard for the first two; once 0.1.1 is on npm, the guards can go.

  1. partOf did not tokenize params. A resource token inside AAuth-Requirement (every auth-token challenge, every step-up) was logged as the presentable JWT. Now tokenized like a body. Test: the parsed challenge carries {type, payload} and the JWT string appears nowhere in the record.
  2. c.executionCtx?.waitUntil throws on Hono outside Workers. Hono's executionCtx is a getter that throws when there is none (the Node entrypoint, app.request in tests), so the middleware 500ed every request there. Read through try/catch now. Test: a context whose getter throws is logged, not failed.
  3. HttpsigFetchLike rejected @hellocoop/httpsig's fetch, which is overloaded on dryRun / returnSent. loggedHttpsigFetch had never been used before access @mntu/hardware-keys v0.11.2 #9 (cast there). Options are any now; the result is unwrapped by shape. Test: an overloaded function typed like httpsig's is accepted and its sent headers name the call.

README: two notes for hosts (the callee record waits on the client reading the response, since workerd's clone() is a tee; a constant fake Signature in a harness gives every call one call_id).

Version 0.1.1. 22 tests pass; tsc clean. Publishing needs the trusted publisher on npmjs (still yours), or a manual publish like 0.1.0.

🤖 Generated with Claude Code

https://claude.ai/code/session_014n2B6Qwjkwkdft4ms5NgMF

… getter, accept httpsig's fetch

Found while wiring the seven fleet workers (access #9, senzing #12,
test-resource #2, whoami #3, notes #4, web-agent-demo #7, registry #9):

- partOf left a resource token inside a parsed AAuth-Requirement (every
  auth-token challenge) as the JWT string. It is tokenized now, like a
  body, so no record holds a presentable token.
- The middleware read `c.executionCtx?.waitUntil` as a property; Hono's
  getter throws where there is no execution context (Node, app.request),
  which 500ed every request on senzing's Node entrypoint and in tests.
- HttpsigFetchLike did not accept @hellocoop/httpsig's fetch, which is
  overloaded on dryRun / returnSent; loggedHttpsigFetch had never been
  used. The options are `any` now, and the result is unwrapped by shape.
- README: the callee record waits on the client reading the response
  (workerd's clone is a tee), and a constant fake Signature in a harness
  gives every call the same call_id.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014n2B6Qwjkwkdft4ms5NgMF
@dickhardt
dickhardt merged commit 04e889d into main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant