import { describe, expect, it, vi } from "vitest"; import { controlRequest, fetchWorker } from "@tests/worker/helpers/http"; import { withEnvBinding } from "@tests/worker/helpers/env"; describe("Worker observability", () => { it("logs request context without sensitive headers or raw client identifiers", async () => { const log = vi.spyOn(console, "log").mockImplementation(() => {}); try { await withEnvBinding("LOG_LEVEL", "info", async () => { const response = await fetchWorker( controlRequest("/healthz", { headers: { authorization: "Bearer secret-token", cookie: "dab_session=secret-cookie", "cf-connecting-ip": "203.0.113.10", "cf-ray": "test-ray", "x-request-id": "client-request-id", "user-agent": "secret-user-agent", }, }), ); expect(response.status).toBe(200); }); expect(log).toHaveBeenCalled(); const raw = String(log.mock.calls.at(-1)?.[0] ?? ""); const entry = JSON.parse(raw) as Record; expect(entry).toMatchObject({ event: "request.complete", eventType: "request.complete", requestId: "test-ray", method: "GET", pathPrefix: "/healthz", status: 200, }); expect(entry).not.toHaveProperty("ipHash"); expect(entry).not.toHaveProperty("userAgentHash"); expect(raw).not.toContain("secret-token"); expect(raw).not.toContain("secret-cookie"); expect(raw).not.toContain("203.0.113.10"); expect(raw).not.toContain("client-request-id"); expect(raw).not.toContain("secret-user-agent"); } finally { log.mockRestore(); } }); });