app.use(morgan("combined")) is the entire logging story: unstructured Apache-format access logs with no request-correlation ID threading through to the errorHandler's console.error(err), making it impossible to correlate a specific failed /wallet/send with its corresponding Horizon interaction in the logs during an incident. Implement structured, correlated logging.
Definition of done:
- Every request gets a correlation/request ID, propagated into any error logging for that request
- Logs are structured (JSON) for machine parsing, not just morgan's text format
- Confirmed no secret material (sourceSecretKey, generated secretKey) ever appears in any log line, including error logs
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.
app.use(morgan("combined")) is the entire logging story: unstructured Apache-format access logs with no request-correlation ID threading through to the errorHandler's console.error(err), making it impossible to correlate a specific failed /wallet/send with its corresponding Horizon interaction in the logs during an incident. Implement structured, correlated logging.
Definition of done:
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.