Skip to content

fix(logging): resolve caller identity before early-return rejections - #133

Merged
cboettig merged 1 commit into
mainfrom
log-origin-on-rejections
Aug 19, 2026
Merged

cboettig merged 1 commit into
mainfrom
log-origin-on-rejections

Conversation

@cboettig

Copy link
Copy Markdown
Member

Follow-up to #131, caught by verifying the deploy rather than trusting it.

Right after the rollout I checked that the new streaming rejection actually logged, and it did — but anonymously:

"provider": "streaming-unsupported", "model": "qwen3", "origin": null, "latency_ms": 0, ...

The request was sent with Origin: https://deploy-verify.local.

Cause

origin, client, session_id and request_id are derived after routing succeeds, but three rejections log a response row before reaching that point:

  1. unroutable model (unrouted) — pre-existing
  2. missing provider API key — pre-existing
  3. the streaming refusal added in fix(api): reject stream: true with a 400 instead of ignoring it (#129) #131

So all three logged "origin": null. For the streaming row that defeats the stated reason it's logged at all: "who is asking for streaming?" needs the calling app, not just a model id and a timestamp. Same for unrouted — a model-id miss you can't attribute to an app is much less actionable.

Fix

Resolve caller identity immediately after auth, ahead of all three rejections, and pass it to each. No behavior change beyond what lands in the log rows.

Tests

Both rejection tests now assert origin and request_id are captured. Mutation-checked: reverting the hoist fails both (2 failed, 1 passed), so they're load-bearing.

pytest test_logging.py — 59 passed.

`origin`, `client`, `session_id` and `request_id` were derived only after
routing succeeded, but three rejections log a response row before that
point — unroutable model, missing provider key, and the new streaming
refusal. Every one of those rows carried "origin": null.

Caught by grepping the live pod straight after deploying the streaming
rejection: the row was there, but anonymous. That defeats the reason it is
logged — "who is asking for streaming?" needs the calling app, not just a
model id and a timestamp.

Resolve identity immediately after auth, ahead of all three rejections.
This also fixes the pre-existing gap on the `unrouted` path, so a
model-id miss is attributable to the app that sent it.

Both rejection tests now assert origin and request_id are captured;
reverting the hoist fails them.
@cboettig
cboettig merged commit 661cc3c into main Aug 19, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant