19cdf8dc9f
The first cut spliced the timestamp on via a logback pattern:
{"ts":"%d{...}",%replace(%msg){'^\{',''}%n
Logback's variable substitution chokes on the literal braces
("All tokens consumed but was expecting }"), so the encoder failed to
configure. Caught by running the real jar and noticing logback had dumped its
internal status — which it only does when something failed to parse. The build
was green throughout: nothing asserted the audit trail was machine-readable.
AuditLog now emits the complete object including its own ISO-8601 "ts", and the
appender pattern is a bare %msg. Adds AuditLogTest, which parses each emitted
line with Jackson (so a malformed record fails the build) and pins that hostile
ids cannot escape their field to forge a second record.
311 tests green; logback now configures with zero internal errors.
45 lines
1.9 KiB
XML
45 lines
1.9 KiB
XML
<configuration>
|
|
<appender name="STDOUT" class="ch.qos.logback.core.ConsoleAppender">
|
|
<encoder>
|
|
<pattern>%d{HH:mm:ss.SSS} %-5level [%thread] %logger{28} - %msg%n</pattern>
|
|
</encoder>
|
|
</appender>
|
|
|
|
<!--
|
|
CB-505 audit trail. Its own file, deliberately not the app log: privileged actions
|
|
(spawn/stop/send/reply/drain) must stay greppable and shippable without dragging DEBUG noise
|
|
along. AuditLog emits a complete JSON object including its own ISO-8601 "ts" field, so the
|
|
pattern is a bare %msg — a pattern that spliced literal braces around the message would
|
|
collide with logback's own variable substitution. Rolls daily, 30 days retained, 100MB cap.
|
|
|
|
NOTE: records carry who/what/target/outcome only. Message CONTENT is never written here —
|
|
this bridge carries source code and prompts, and an audit log that accumulated them would be
|
|
a transcript archive rather than a control.
|
|
-->
|
|
<appender name="AUDIT" class="ch.qos.logback.core.rolling.RollingFileAppender">
|
|
<file>logs/audit.log</file>
|
|
<rollingPolicy class="ch.qos.logback.core.rolling.SizeAndTimeBasedRollingPolicy">
|
|
<fileNamePattern>logs/audit.%d{yyyy-MM-dd}.%i.log</fileNamePattern>
|
|
<maxFileSize>10MB</maxFileSize>
|
|
<maxHistory>30</maxHistory>
|
|
<totalSizeCap>100MB</totalSizeCap>
|
|
</rollingPolicy>
|
|
<encoder>
|
|
<pattern>%msg%n</pattern>
|
|
</encoder>
|
|
</appender>
|
|
|
|
<logger name="dev.ltms.bridged" level="DEBUG"/>
|
|
<logger name="io.javalin" level="INFO"/>
|
|
<logger name="org.eclipse.jetty" level="WARN"/>
|
|
|
|
<!-- additivity=false keeps the audit stream out of stdout; it is its own record. -->
|
|
<logger name="audit" level="INFO" additivity="false">
|
|
<appender-ref ref="AUDIT"/>
|
|
</logger>
|
|
|
|
<root level="INFO">
|
|
<appender-ref ref="STDOUT"/>
|
|
</root>
|
|
</configuration>
|