File
Blob: tests/worker/runtime/observability/observability.workers.test.ts
| 1 | import { describe, expect, it, vi } from "vitest"; |
| 2 | |
| 3 | import { controlRequest, fetchWorker } from "@tests/worker/helpers/http"; |
| 4 | import { withEnvBinding } from "@tests/worker/helpers/env"; |
| 5 | |
| 6 | describe("Worker observability", () => { |
| 7 | it("logs request context without sensitive headers or raw client identifiers", async () => { |
| 8 | const log = vi.spyOn(console, "log").mockImplementation(() => {}); |
| 9 | try { |
| 10 | await withEnvBinding("LOG_LEVEL", "info", async () => { |
| 11 | const response = await fetchWorker( |
| 12 | controlRequest("/healthz", { |
| 13 | headers: { |
| 14 | authorization: "Bearer secret-token", |
| 15 | cookie: "dab_session=secret-cookie", |
| 16 | "cf-connecting-ip": "203.0.113.10", |
| 17 | "cf-ray": "test-ray", |
| 18 | "x-request-id": "client-request-id", |
| 19 | "user-agent": "secret-user-agent", |
| 20 | }, |
| 21 | }), |
| 22 | ); |
| 23 | expect(response.status).toBe(200); |
| 24 | }); |
| 25 | |
| 26 | expect(log).toHaveBeenCalled(); |
| 27 | const raw = String(log.mock.calls.at(-1)?.[0] ?? ""); |
| 28 | const entry = JSON.parse(raw) as Record<string, unknown>; |
| 29 | expect(entry).toMatchObject({ |
| 30 | event: "request.complete", |
| 31 | eventType: "request.complete", |
| 32 | requestId: "test-ray", |
| 33 | method: "GET", |
| 34 | pathPrefix: "/healthz", |
| 35 | status: 200, |
| 36 | }); |
| 37 | expect(entry).not.toHaveProperty("ipHash"); |
| 38 | expect(entry).not.toHaveProperty("userAgentHash"); |
| 39 | expect(raw).not.toContain("secret-token"); |
| 40 | expect(raw).not.toContain("secret-cookie"); |
| 41 | expect(raw).not.toContain("203.0.113.10"); |
| 42 | expect(raw).not.toContain("client-request-id"); |
| 43 | expect(raw).not.toContain("secret-user-agent"); |
| 44 | } finally { |
| 45 | log.mockRestore(); |
| 46 | } |
| 47 | }); |
| 48 | }); |