You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit a9a31c5
Browse filesBrowse the repository at this point in the historyBrowse files
exception messages. Endpoint values contain only scheme, host/port and path. Evaluation omits all
442
444
provider events and emits `evaluation_completed`.
443
445
444
-
A successful JavaScript live request emits these separate service events:
446
+
A successful live request emits these separate service events:
445
447
446
448
| Service event | Safe information recorded |
447
449
|---|---|
448
450
|`request_received`| Function invocation and available raw Microsoft trace IDs under their `x-ms-*` names; no raw body or arbitrary headers. |
449
-
|`envelope_validated`| Allowlisted body metadata: validated `envelopeType`, normalized `channel`, `evaluation`, optional `ttlSeconds`, and `encryptedDeliveryContextPresent: true`. |
451
+
|`envelope_validated`/ `payload_validated`| Allowlisted body metadata: validated payload type, normalized `channel`, `evaluation` and optional `ttlSeconds`. |
450
452
|`delivery_context_decrypted`| Decryption completed; no plaintext fields, JWE or key ID. |
451
453
|`provider_selected`| Registered provider and its authentication mode. |
452
454
|`provider_credential_resolution_started`| OAuth client-assertion or Key Vault credential source, with explicitly named raw OAuth application/identity/tenant IDs. |
@@ -455,7 +457,7 @@ A successful JavaScript live request emits these separate service events:
455
457
|`provider_request_built`| Allowlisted HTTP method, final endpoint scheme/host/port/API path, HTTPS and disabled redirects; no query string, authorization headers or body. |
456
458
|`provider_request_started`| The outbound send is beginning, with method, sanitized endpoint and timeout. |
457
459
|`provider_response_received`| Actual upstream HTTP status; emitted before response-body reading completes. |
458
-
|`provider_response_processed`| Mapped provider status/outcome, raw provider message/reference ID, duration and resulting Function HTTP status. |
460
+
|`provider_response_processed`| Mapped provider status/outcome, fixed failure classification and duration. Raw provider descriptions and bodies are excluded. |
459
461
|`response_prepared`| Response status and booleans indicating nonce/correlation inclusion, not their values or the response body. |
460
462
461
463
Body metadata is built from validated fields, **not** from a body dump with a few sensitive
@@ -518,31 +520,13 @@ These are tracing fields, not authentication assertions. In particular, an incom
518
520
does not become a trusted tenant identity in logs. The existing wire correlation precedence,
519
521
provider request IDs and public responses are unchanged.
520
522
521
-
Python retains a comprehensive request summary. JavaScript emits the same safe concepts only on the
522
-
fixed event where each value is known; its `request_completed` event contains the final HTTP status,
523
-
result and elapsed time rather than a cumulative mutable snapshot:
524
-
525
-
| Fields | Purpose |
526
-
|---|---|
527
-
|`httpStatus`, `result`, `elapsedMs`| Final Function response, `accepted` / `evaluated` / `failed`, and total handler time in milliseconds. Acceptance is not handset delivery. |
528
-
|`envelopeType`, `channel`, `evaluation`, `ttlSeconds`| Allowlisted request-body metadata; null until envelope validation succeeds. Omitted TTL remains null; logging does not introduce expiry enforcement. |
529
-
|`providerName`, `providerAuthMode`, `providerAttempted`| Fixed provider ID, its `apiKey` / `oauth` mode, and whether provider HTTP was attempted. Unknown configured names and credentials are never echoed. |
530
-
|`providerCredentialSource`, `providerCredentialElapsedMs`| Credential resolution path and duration, including failed resolution; null if it never started. |
531
-
|`providerTenantId`, `functionOutboundClientId`, `functionOutboundManagedIdentityClientId`| Raw configured OAuth identity IDs; null when OAuth resolution was not attempted. |
532
-
|`providerHttpMethod`, `providerEndpoint`| Final provider request method and scheme/host/port/API path, set only after request construction and URL validation. No query string. |
533
-
|`providerHttpStatus`, `providerStatus`, `providerOutcome`| Actual upstream HTTP status and normalized result. Status is logged only when the provider recognized it; otherwise it is `unmapped`. |
534
-
|`providerMessageId`| Raw provider lookup/reference ID for support escalation. |
535
-
|`providerElapsedMs`, `providerTimeoutMs`| Outbound request duration including response-body reading, and the configured/clamped HTTP timeout. Neither is an end-to-end deadline. |
536
-
|`failureStage`, `failureReason`| Stage and fixed diagnostic reason, such as `provider_credentials` / `credential_unavailable`, `provider_transport` / `provider_timeout`, or `provider_response` / `provider_rejected`. No exception messages. |
537
-
|`encryptionKeyIdMismatch`| Whether the advisory warning was emitted; never the configured or received key ID. |
538
-
|`responseContainsNonce`, `responseContainsCorrelationId`| Whether those fields are in the prepared response, without recording their values. Null if no response was prepared. |
539
-
|`omittedIdFields`| Names of support ID fields whose current values failed the logging format/length guard; empty for ordinary valid IDs. |
540
-
541
-
Provider fields remain null when their stage was not reached. `providerHttpStatus` is captured as
542
-
soon as headers arrive, so a response-body timeout can legitimately show upstream `200` alongside
543
-
Function `httpStatus: 504`, without a mapped provider status or success acknowledgement. Unknown
544
-
provider status text and malformed JSON are never logged; malformed JSON emits only
545
-
`provider_response_invalid_json` before the provider outcome rules run.
523
+
The fixed `request_completed` event contains only the final HTTP status, result and elapsed time.
524
+
Stage-specific fields remain on the event where they become known instead of being accumulated into
525
+
a mutable summary. `providerHttpStatus` is recorded when response headers arrive, so a response-body
526
+
timeout can legitimately produce `provider_response_received` with upstream `200` followed by
527
+
`request_failed` with Function status `504`, without a mapped provider status or success
528
+
acknowledgement. Unknown provider status text and malformed JSON are never logged; malformed JSON
529
+
emits only `provider_response_invalid_json` before the provider outcome rules run.
546
530
547
531
Normal events and completion events use Information; invalid requests, non-success 4xx outcomes and
548
532
advisory warnings use Warning; 5xx failures and timeouts use Error. Keep application Information logs
|[src/models.py](src/models.py)| Envelope, delivery-context, dispatch and normalized `ParsedResponse` dataclasses |
107
-
|[src/dispatch.py](src/dispatch.py)| Boundary validation, JWE, provider registry and outcome mapping |
108
-
|[src/credentials.py](src/credentials.py)|`ApiKeyCache`, `AccessTokenCache` and their shared refresh coordinator |
109
-
|[src/request_log.py](src/request_log.py)| Request-scoped [service events and summaries](../docs/CONTRACT.md#application-logs) with explicit ID sources |
110
-
|[src/providers/](src/providers/)| Adapter manifests and API-specific implementations |
106
+
|[src/models.py](src/models.py)| Typed Entra payload, delivery context, provider request and result dataclasses |
107
+
|[src/jwe.py](src/jwe.py)| Pinned JWE decryption and typed delivery-context conversion |
108
+
|[src/provider.py](src/provider.py)| Shared HTTPS transport, timeout handling and endpoint status mapping |
109
+
|[src/credentials.py](src/credentials.py)|`CredentialTokenService`, `ApiKeyCache` and `AccessTokenCache`|
110
+
|[src/otp_log.py](src/otp_log.py)| Fixed standard-logging event definitions and immutable request context |
111
+
|[src/providers/](src/providers/)| Provider-owned credentials, requests and response mapping |
111
112
|[src/secrets.py](src/secrets.py)| Key Vault transport; bundle caching belongs to `ApiKeyCache`|
112
113
113
-
Add and register an adapter without adding provider-specific branches to the shared pipeline.
114
-
Return `ParsedResponse` from `parse_response` using named fields; the engine reads attributes such as
115
-
`parsed.provider_status_name`. Raw provider JSON remains local to the adapter, not a shared model hierarchy.
114
+
Add a provider by subclassing `PhoneProviderBase`, declaring its credential specification, and
115
+
implementing `build_request` and `map_response`. Return `ProviderResult` with the coarse endpoint
116
+
outcome and a fixed safe failure classification. Raw provider JSON remains local to the provider.
116
117
See [production limitations](../docs/CONTRACT.md#production-limitations) before production use.
0 commit comments