mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-05 20:28:23 +00:00
Trim redundant client attribution comments
This commit is contained in:
@@ -183,10 +183,9 @@ class RequestIdFilter(logging.Filter):
|
|||||||
|
|
||||||
|
|
||||||
class ClientAppFilter(logging.Filter):
|
class ClientAppFilter(logging.Filter):
|
||||||
"""Filter to add the requesting client app to all log records."""
|
"""Attach request-local app attribution to log records."""
|
||||||
|
|
||||||
def filter(self, record: logging.LogRecord) -> bool:
|
def filter(self, record: logging.LogRecord) -> bool:
|
||||||
"""Add the client app to the log record if available."""
|
|
||||||
# Import here to avoid circular imports
|
# Import here to avoid circular imports
|
||||||
from .middleware import UNKNOWN_CLIENT_APP, client_app_context
|
from .middleware import UNKNOWN_CLIENT_APP, client_app_context
|
||||||
|
|
||||||
|
|||||||
@@ -15,13 +15,11 @@ logger = get_logger(__name__)
|
|||||||
# Context variable to store request ID across async context
|
# Context variable to store request ID across async context
|
||||||
request_id_context: ContextVar[str | None] = ContextVar("request_id")
|
request_id_context: ContextVar[str | None] = ContextVar("request_id")
|
||||||
|
|
||||||
# Context variable to store the client app across async context
|
|
||||||
client_app_context: ContextVar[str | None] = ContextVar("client_app")
|
client_app_context: ContextVar[str | None] = ContextVar("client_app")
|
||||||
|
|
||||||
UNKNOWN_CLIENT_APP = "unknown"
|
UNKNOWN_CLIENT_APP = "unknown"
|
||||||
|
|
||||||
# Identity headers in priority order. X-Title and HTTP-Referer are the
|
# Prefer OpenRouter app headers, then browser and SDK fallbacks.
|
||||||
# OpenRouter convention; User-Agent covers SDKs and scripts that set neither.
|
|
||||||
_CLIENT_APP_HEADERS: tuple[str, ...] = (
|
_CLIENT_APP_HEADERS: tuple[str, ...] = (
|
||||||
"x-title",
|
"x-title",
|
||||||
"http-referer",
|
"http-referer",
|
||||||
@@ -29,8 +27,7 @@ _CLIENT_APP_HEADERS: tuple[str, ...] = (
|
|||||||
"user-agent",
|
"user-agent",
|
||||||
)
|
)
|
||||||
|
|
||||||
# Header values are attacker-controlled: cap the length so one request can't
|
# Limit untrusted header data repeated in every log record.
|
||||||
# bloat every log line.
|
|
||||||
_CLIENT_APP_MAX_LENGTH = 120
|
_CLIENT_APP_MAX_LENGTH = 120
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -93,7 +93,6 @@ def test_value_is_truncated_to_120_chars() -> None:
|
|||||||
|
|
||||||
|
|
||||||
def test_control_characters_are_stripped() -> None:
|
def test_control_characters_are_stripped() -> None:
|
||||||
"""A crafted header must not be able to forge log records."""
|
|
||||||
headers = Headers({"user-agent": "evil-app\x1b[0m fake INFO line"})
|
headers = Headers({"user-agent": "evil-app\x1b[0m fake INFO line"})
|
||||||
assert client_app_from_headers(headers) == "evil-app[0m fake INFO line"
|
assert client_app_from_headers(headers) == "evil-app[0m fake INFO line"
|
||||||
|
|
||||||
@@ -178,7 +177,6 @@ def test_filter_defaults_to_unknown_outside_request_context() -> None:
|
|||||||
|
|
||||||
|
|
||||||
def test_handler_logs_carry_client_app(caplog: pytest.LogCaptureFixture) -> None:
|
def test_handler_logs_carry_client_app(caplog: pytest.LogCaptureFixture) -> None:
|
||||||
"""A log line emitted inside a handler still names the app that triggered it."""
|
|
||||||
app = FastAPI()
|
app = FastAPI()
|
||||||
handler_logger = logging.getLogger("routstr.test.handler")
|
handler_logger = logging.getLogger("routstr.test.handler")
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user