From 9a3d4a101ca13c380ed2366ec4efdb4444810a02 Mon Sep 17 00:00:00 2001 From: Shubham Kumar Date: Mon, 28 Sep 2026 16:31:48 -0500 Subject: [PATCH 1/2] Skip [AUDIT] logs for /v1/api/meta/* by default. Meta metric/status scrapes generate high-volume AUDIT noise with little ops value. Business-route AUDIT is unchanged. Override via AuditExcludeURIPrefixes (empty slice disables the default exclusion). Co-authored-by: Cursor --- repository/logging/config.go | 32 ++++++++++++ repository/logging/logging.go | 2 +- repository/logging/logging_test.go | 80 ++++++++++++++++++++++++++++++ 3 files changed, 113 insertions(+), 1 deletion(-) diff --git a/repository/logging/config.go b/repository/logging/config.go index efc16fcd9..21ac4d1cf 100644 --- a/repository/logging/config.go +++ b/repository/logging/config.go @@ -1,11 +1,19 @@ package logging +import "strings" + type Config struct { EnableTracing *bool EnableAudit *bool IncludeSQL *bool + // AuditExcludeURIPrefixes skips [AUDIT] logging when the request URI has any + // of these prefixes. Nil uses the default (meta introspect/metric scrapes). + // Set to an empty slice to disable path exclusions. + AuditExcludeURIPrefixes []string } +var defaultAuditExcludeURIPrefixes = []string{"/v1/api/meta/"} + func (c *Config) IsTracingEnabled() bool { if c.EnableTracing == nil { return false @@ -26,3 +34,27 @@ func (c *Config) ShallIncludeSQL() bool { } return *c.IncludeSQL } + +func (c *Config) auditExcludePrefixes() []string { + if c == nil || c.AuditExcludeURIPrefixes == nil { + return defaultAuditExcludeURIPrefixes + } + return c.AuditExcludeURIPrefixes +} + +// ShouldAuditURI reports whether [AUDIT] should be emitted for the request URI. +func (c *Config) ShouldAuditURI(uri string) bool { + if !c.IsAuditEnabled() { + return false + } + path := uri + if i := strings.IndexByte(uri, '?'); i >= 0 { + path = uri[:i] + } + for _, prefix := range c.auditExcludePrefixes() { + if prefix != "" && strings.HasPrefix(path, prefix) { + return false + } + } + return true +} diff --git a/repository/logging/logging.go b/repository/logging/logging.go index e32077141..9a4938943 100644 --- a/repository/logging/logging.go +++ b/repository/logging/logging.go @@ -18,7 +18,7 @@ func Log(config *Config, execContext *exec.Context) { if !includeSQL { snap.Metrics = snap.Metrics.HideMetrics() } - if config.IsAuditEnabled() { + if config.ShouldAuditURI(execContext.URI) { data := safeMarshal("EXECCONTEXT", snap) fmt.Println("[AUDIT]", string(data)) } diff --git a/repository/logging/logging_test.go b/repository/logging/logging_test.go index 3214c22e0..64f0b2e40 100644 --- a/repository/logging/logging_test.go +++ b/repository/logging/logging_test.go @@ -256,3 +256,83 @@ func TestLog_RedactsAuditAndTraceErrorsBeforeEmission(t *testing.T) { assert.Contains(t, logged, "[TRACE]") assert.Contains(t, logged, redactedValue) } + +func TestShouldAuditURI(t *testing.T) { + enabled := true + disabled := false + + cases := []struct { + name string + config *Config + uri string + want bool + }{ + { + name: "default excludes meta metric scrapes", + config: &Config{}, + uri: "/v1/api/meta/metric/mdp/adorder/operation/foo/recent", + want: false, + }, + { + name: "default excludes meta status", + config: &Config{}, + uri: "/v1/api/meta/status", + want: false, + }, + { + name: "default keeps business routes", + config: &Config{}, + uri: "/v1/api/mdp/kpiperf/produce", + want: true, + }, + { + name: "strips query before prefix match", + config: &Config{}, + uri: "/v1/api/meta/metric/x?foo=1", + want: false, + }, + { + name: "EnableAudit false disables all", + config: &Config{EnableAudit: &disabled}, + uri: "/v1/api/mdp/kpiperf/produce", + want: false, + }, + { + name: "empty exclude list audits meta", + config: &Config{EnableAudit: &enabled, AuditExcludeURIPrefixes: []string{}}, + uri: "/v1/api/meta/metric/x", + want: true, + }, + { + name: "custom exclude prefix", + config: &Config{AuditExcludeURIPrefixes: []string{"/v1/api/mdp/internal/"}}, + uri: "/v1/api/mdp/internal/health", + want: false, + }, + } + + for _, tc := range cases { + t.Run(tc.name, func(t *testing.T) { + assert.Equal(t, tc.want, tc.config.ShouldAuditURI(tc.uri)) + }) + } +} + +func TestLog_SkipsMetaAudit(t *testing.T) { + oldStdout := os.Stdout + r, w, err := os.Pipe() + require.NoError(t, err) + os.Stdout = w + + execCtx := exec.NewContext("GET", "/v1/api/meta/metric/mdp/adorder/operation/foo/recent", nil, "") + Log(&Config{}, execCtx) + + require.NoError(t, w.Close()) + os.Stdout = oldStdout + defer r.Close() + + var output bytes.Buffer + _, err = io.Copy(&output, r) + require.NoError(t, err) + assert.NotContains(t, output.String(), "[AUDIT]") +} From 62bf77d661fc88151b9a8232995a75eded146157 Mon Sep 17 00:00:00 2001 From: Shubham Kumar Date: Mon, 28 Sep 2026 16:57:12 -0500 Subject: [PATCH 2/2] Make AuditExcludeURIPrefixes opt-in with no library default. Public clients choose which URI prefixes to skip; empty/nil keeps prior behavior (audit all when EnableAudit is on). Co-authored-by: Cursor --- repository/logging/config.go | 19 +++++++------------ repository/logging/logging_test.go | 30 ++++++++++++++++++------------ 2 files changed, 25 insertions(+), 24 deletions(-) diff --git a/repository/logging/config.go b/repository/logging/config.go index 21ac4d1cf..8b27cca75 100644 --- a/repository/logging/config.go +++ b/repository/logging/config.go @@ -7,13 +7,12 @@ type Config struct { EnableAudit *bool IncludeSQL *bool // AuditExcludeURIPrefixes skips [AUDIT] logging when the request URI has any - // of these prefixes. Nil uses the default (meta introspect/metric scrapes). - // Set to an empty slice to disable path exclusions. + // of these prefixes. Empty/nil means no path-based exclusions (library default: + // audit all URIs when audit is enabled). Clients configure this, e.g. + // ["/v1/api/meta/"] for metric/status scrape noise. AuditExcludeURIPrefixes []string } -var defaultAuditExcludeURIPrefixes = []string{"/v1/api/meta/"} - func (c *Config) IsTracingEnabled() bool { if c.EnableTracing == nil { return false @@ -35,23 +34,19 @@ func (c *Config) ShallIncludeSQL() bool { return *c.IncludeSQL } -func (c *Config) auditExcludePrefixes() []string { - if c == nil || c.AuditExcludeURIPrefixes == nil { - return defaultAuditExcludeURIPrefixes - } - return c.AuditExcludeURIPrefixes -} - // ShouldAuditURI reports whether [AUDIT] should be emitted for the request URI. func (c *Config) ShouldAuditURI(uri string) bool { if !c.IsAuditEnabled() { return false } + if c == nil || len(c.AuditExcludeURIPrefixes) == 0 { + return true + } path := uri if i := strings.IndexByte(uri, '?'); i >= 0 { path = uri[:i] } - for _, prefix := range c.auditExcludePrefixes() { + for _, prefix := range c.AuditExcludeURIPrefixes { if prefix != "" && strings.HasPrefix(path, prefix) { return false } diff --git a/repository/logging/logging_test.go b/repository/logging/logging_test.go index 64f0b2e40..9681b913e 100644 --- a/repository/logging/logging_test.go +++ b/repository/logging/logging_test.go @@ -268,29 +268,35 @@ func TestShouldAuditURI(t *testing.T) { want bool }{ { - name: "default excludes meta metric scrapes", + name: "nil config audits all when enabled by zero value", config: &Config{}, uri: "/v1/api/meta/metric/mdp/adorder/operation/foo/recent", - want: false, - }, - { - name: "default excludes meta status", - config: &Config{}, - uri: "/v1/api/meta/status", - want: false, + want: true, }, { - name: "default keeps business routes", + name: "no excludes keeps business routes", config: &Config{}, uri: "/v1/api/mdp/kpiperf/produce", want: true, }, + { + name: "configured exclude skips matching prefix", + config: &Config{AuditExcludeURIPrefixes: []string{"/v1/api/meta/"}}, + uri: "/v1/api/meta/metric/x", + want: false, + }, { name: "strips query before prefix match", - config: &Config{}, + config: &Config{AuditExcludeURIPrefixes: []string{"/v1/api/meta/"}}, uri: "/v1/api/meta/metric/x?foo=1", want: false, }, + { + name: "non-matching URI still audited", + config: &Config{AuditExcludeURIPrefixes: []string{"/v1/api/meta/"}}, + uri: "/v1/api/mdp/kpiperf/produce", + want: true, + }, { name: "EnableAudit false disables all", config: &Config{EnableAudit: &disabled}, @@ -318,14 +324,14 @@ func TestShouldAuditURI(t *testing.T) { } } -func TestLog_SkipsMetaAudit(t *testing.T) { +func TestLog_SkipsExcludedAudit(t *testing.T) { oldStdout := os.Stdout r, w, err := os.Pipe() require.NoError(t, err) os.Stdout = w execCtx := exec.NewContext("GET", "/v1/api/meta/metric/mdp/adorder/operation/foo/recent", nil, "") - Log(&Config{}, execCtx) + Log(&Config{AuditExcludeURIPrefixes: []string{"/v1/api/meta/"}}, execCtx) require.NoError(t, w.Close()) os.Stdout = oldStdout