feat(logging): AppLog seam — record scrubbed throwables + accountLogRef (#325) #333

Merged
JMR-dev merged 2 commits from feat-325-applog-seam into main 2026-07-05 02:01:39 +00:00
JMR-dev commented 2026-07-05 01:24:01 +00:00 (Migrated from github.com)

Closes #325
Part of #324

Foundational seam for the debug-logging strangler epic. Adds throwable-recording overloads to AppLog.d/AppLog.w and makes AppLog.e record the throwable it is handed: the trace is scrubbed via the existing StackTraceScrubber (exception class names + stack frames kept; host/email-bearing exception messages stripped) and appended to the buffered log line, so a throwable can reach a user-reviewed DebugReport without leaking PII. The no-throwable overloads are unchanged.

Also adds accountLogRef(accountId) — a short, stable, non-reversible reference (scheme: prefix + truncated SHA-256 of the id) so downstream logging can identify an account without logging the raw Account.id, which embeds the email.

Unit-tested (this pure seam is fully JVM-testable; the consuming area tickets #326–#330 carry the E2E surface): scrubbed-throwable buffer recording (host:port + email stripped, class kept), the w/d overloads, and accountLogRef (stable, differs across ids, leaks no @/domain, address-shaped prefixes fall back to acct:).

🤖 Generated with Claude Code

Closes #325 Part of #324 Foundational seam for the debug-logging strangler epic. Adds throwable-recording overloads to `AppLog.d`/`AppLog.w` and makes `AppLog.e` record the throwable it is handed: the trace is scrubbed via the existing `StackTraceScrubber` (exception class names + stack frames kept; host/email-bearing exception messages stripped) and appended to the buffered log line, so a throwable can reach a user-reviewed `DebugReport` without leaking PII. The no-throwable overloads are unchanged. Also adds `accountLogRef(accountId)` — a short, stable, non-reversible reference (`scheme:` prefix + truncated SHA-256 of the id) so downstream logging can identify an account without logging the raw `Account.id`, which embeds the email. Unit-tested (this pure seam is fully JVM-testable; the consuming area tickets #326–#330 carry the E2E surface): scrubbed-throwable buffer recording (host:port + email stripped, class kept), the `w`/`d` overloads, and `accountLogRef` (stable, differs across ids, leaks no `@`/domain, address-shaped prefixes fall back to `acct:`). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.