Skip to content

call-log 0.1.3: log a body only if small (8 KB); over it, its content_type and size - #33

Closed
dickhardt wants to merge 1 commit into
call-log-skip-unsignedfrom
call-log-small-bodies
Closed

dickhardt wants to merge 1 commit into
call-log-skip-unsignedfrom
call-log-small-bodies

Conversation

@dickhardt

Copy link
Copy Markdown
Contributor

Stacked on #32. Step 3 of aauth-dev/monitor plan/CALL_LOG_PLAN.md: Dick decided 2026-09-28 "call-log sends bodies IF SMALL"; this picks the threshold and the replacement.

  • Threshold: 8 KB (MAX_BODY_BYTES, exported), measured on the body's UTF-8 text.
  • Over it: no body; the part carries content_type and size (bytes). That is the shape the record already uses for a body it does not show, and the monitor already renders it: "Body not logged: application/json, N bytes." No body at all has neither field, so a reader can tell the two apart.
  • A stated Content-Length over the limit is not read. Without one, the text is read and measured.
  • The caller's request body (init.body string) gets the same rule and becomes { size }.
  • The 30 KB record cap (cap, truncated: true) stays as the backstop.

Why 8 KB, from Freezer (prod fleet + beta Wallet, last three days): every protocol body is under 2 KB (largest: access /token request carrying the R3 document, 1.7 KB); senzing results under 2 KB; secret.agent.coop JWE messages 6.5 KB. The one body over 8 KB is registry GET /resources at 27.7 KB. Two bodies at the limit plus envelope still fit the 30 KB cap.

Version 0.1.3. If #32 and this merge before a release, the release publishes 0.1.3 only. npm test: all pass; both new tests fail on the old code.

🤖 Generated with Claude Code

https://claude.ai/code/session_01YTSrtvfcNAxTc5KGxr4aKh

…_type and size

Dick, 2026-09-28: "call-log sends bodies IF SMALL." MAX_BODY_BYTES = 8 KB,
measured on the body's UTF-8 text. Over it the body is not logged and the
part carries `content_type` and `size` instead — the shape the record
already uses for a body it does not show, which the monitor renders as
"Body not logged: application/json, N bytes." No body at all is neither
field. A stated Content-Length over the limit is not read.

The caller's request body gets the same rule (`{ size }`). The 30 KB record
cap stays as the backstop.

Fleet data, last three days: every protocol body is under 2 KB (largest:
access /token request with the R3 document, 1.7 KB); senzing results under
2 KB; secret.agent.coop JWE messages 6.5 KB. The one body over 8 KB is
registry GET /resources, 27.7 KB.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YTSrtvfcNAxTc5KGxr4aKh
@dickhardt
dickhardt deleted the branch call-log-skip-unsigned September 28, 2026 11:34
@dickhardt dickhardt closed this Sep 28, 2026
@dickhardt
dickhardt deleted the call-log-small-bodies branch September 28, 2026 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant