Skip to content

call-log 0.1.2: skip an unsigned request unless the response carries AAuth-Requirement - #32

Merged
dickhardt merged 1 commit into
mainfrom
call-log-skip-unsigned
Sep 28, 2026
Merged

dickhardt merged 1 commit into
mainfrom
call-log-skip-unsigned

Conversation

@dickhardt

Copy link
Copy Markdown
Contributor

Finding 4 in aauth-dev/monitor plan/CALL_LOG_PLAN.md, approved by Dick 2026-09-28: "skip unsigned unless AAuth-Requirement."

  • callLogMiddleware drops the record for a request with no Signature and no Signature-Key header unless the response carries AAuth-Requirement.
  • Applied after skip, so the workers that pass their own skip (access, test-resource, playground, registry) inherit it too.
  • A request carrying only Signature-Key is not unsigned — it is an AAuth attempt and is still logged.

What it removes, checked live today: whoami and notes answer an unsigned GET with 401 signature_required and no AAuth-Requirement; a scanner's /.env gets 404. Both are dropped. senzing POST /v1/search_entities and encrypt POST /send answer unsigned with 401 AAuth-Requirement: requirement=person-token; both are kept.

Version 0.1.2; lockfile workspace entry edited by hand (it still said 0.1.0). npm test: 802 passed. The new test fails on 0.1.1.

After release, each fleet worker needs a lockfile bump — every worker's package-lock.json on main still resolves @aauth/call-log 0.1.0.

🤖 Generated with Claude Code

https://claude.ai/code/session_01YTSrtvfcNAxTc5KGxr4aKh

…AAuth-Requirement

An unsigned request (no Signature, no Signature-Key) is a browser or a
scanner, not a call between roles. notes.aauth.dev logged ~100 records of a
vulnerability scan in two seconds on 2026-09-27, roughly the whole fleet tap
ring. The exception is the challenge: a 401 with AAuth-Requirement is the
first step of a call and is still logged. The rule runs after `skip`, so a
host's own `skip` keeps it and every worker inherits it with the upgrade.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YTSrtvfcNAxTc5KGxr4aKh
@dickhardt
dickhardt merged commit d898f2e into main Sep 28, 2026
1 check passed
@dickhardt
dickhardt deleted the call-log-skip-unsigned branch September 28, 2026 11:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant