Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,48 +1,63 @@
package com.objectcomputing.checkins.logging;

import com.objectcomputing.checkins.Environments;
import io.micronaut.context.annotation.Requires;
import io.micronaut.http.HttpAttributes;
import io.micronaut.http.HttpRequest;
import io.micronaut.http.MutableHttpResponse;
import io.micronaut.http.annotation.Filter;
import io.micronaut.http.filter.HttpServerFilter;
import io.micronaut.http.filter.ServerFilterChain;
import io.micronaut.http.filter.ServerFilterPhase;
import io.micronaut.inject.ExecutableMethod;
import io.micronaut.security.authentication.Authentication;
import io.micronaut.security.filters.SecurityFilter;
import io.micronaut.web.router.MethodBasedRouteInfo;
import org.reactivestreams.Publisher;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import reactor.core.publisher.Flux;
import reactor.core.publisher.Mono;

import java.security.Principal;
import java.util.Optional;
import java.util.stream.Collectors;

import static io.micronaut.http.annotation.Filter.MATCH_ALL_PATTERN;

@Filter(MATCH_ALL_PATTERN)
@Requires(env = Environments.LOCAL)
public class RequestLoggingInterceptor implements HttpServerFilter {
private final Logger LOG = LoggerFactory.getLogger(RequestLoggingInterceptor.class);

public boolean intercept(HttpRequest request) {
String requestVerb = request.getMethodName();
String username = "not authenticated";
Optional<Authentication> auth = request.getAttribute("micronaut.AUTHENTICATION", Authentication.class);
if (auth.isEmpty()) {
return false; //Seems to fire twice per request. First time without auth, so we just skip that one.
}
else if (!auth.get().getName().isBlank()){
username = auth.get().getName();
}
Optional<MethodBasedRouteInfo> route = request.getAttribute("micronaut.http.route", MethodBasedRouteInfo.class);
if(route.isPresent()) {
MethodBasedRouteInfo routeBuilder = route.get();

private static final Logger LOG = LoggerFactory.getLogger(RequestLoggingInterceptor.class);

@Override
public int getOrder() {
// Run after the security filter, so we can log the user
return ServerFilterPhase.SECURITY.order() + 1;
}

private boolean intercept(HttpRequest<?> request) {
Optional<Authentication> auth = request.getAttribute(SecurityFilter.AUTHENTICATION, Authentication.class);
request.getAttribute(HttpAttributes.ROUTE_INFO, MethodBasedRouteInfo.class).ifPresent(routeBuilder -> {
String username = auth.map(Principal::getName).map(n -> n.isBlank() ? null : n).orElse("not authenticated");
String requestVerb = request.getMethodName();
ExecutableMethod targetMethod = routeBuilder.getTargetMethod().getExecutableMethod();
String params = "";
request.getParameters().forEach((key, value) -> params.concat(key).concat(":").concat(value.toString()));
Optional<String> requestBody = request.getBody(String.class);
LOG.info(String.format("User %s %s request to %s with body %s and parameters %s being handled by %s.%s",
username, requestVerb, request.getUri().getPath(), requestBody.orElse("empty"), params.isEmpty() ? "empty" : params,
targetMethod.getDeclaringType().getSimpleName(), targetMethod.getName()));
}
String params = request.getParameters().asMap().entrySet().stream()
.map(e -> e.getKey() + ":" + e.getValue())
.collect(Collectors.joining(","));
String requestBody = request.getBody(String.class).orElse("empty");
LOG.info(
"User {} {} request to {} with body {} and parameters {} being handled by {}.{}",
username,
requestVerb,
request.getUri().getPath(),
requestBody,
params.isEmpty() ? "empty" : params,
targetMethod.getDeclaringType().getSimpleName(),
targetMethod.getName()
);
});
return true;
}

Expand Down