Security News
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" by Security Experts
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
@ovotech/axios-logger
Advanced tools
Log request and response, redact all possible PII sources by default, but allow to add custom redact paths so more info can be logged.
yarn add @ovotech/axios-logger
import { axiosLogger, redactHeader } from '@ovotech/axios-logger';
import axios from 'axios';
const logger = axiosLogger((level, meta, config) => console.log(level, meta, config.url));
const api = axios.create();
api.interceptors.request.use(logger.request.onFullfilled);
api.interceptors.response.use(logger.response.onFullfilled, logger.response.onRejected);
// ...
api.get('/my/path');
const body = { user: { cards: [{ id: '111' }, { id: '222' }] } };
api.post('/update/path', body, { headers: { [redactHeader]: 'requestBody.user.cards.*.id' } });
You have 3 interceptors. logger.request.onFullfilled
, logger.response.onFullfilled
and logger.response.onRejected
.
logger.request.onFullfilled
used to setup the initial execution time. If omitted request time would not be logged.logger.response.onFullfilled
logs a successful responselogger.response.onRejected
logs an errorEach one can be omitted if you don't want or need that feature.
The log function will receive 3 arguments - level, meta and axios request config. The first one indicates what type of log level to use - "info" for success and "error" for error. The second contains an object of data to log.
{
uri: '/my/path',
method: 'get',
params: { id: '10' }
requestBody: { id: '10' },
responseBody: { user: 'Name' },
status: 200,
responseTime: 21,
}
By default uri
, params
, requestBody
and responseBody
will be "redacted", since they can contain personally identifiable information. You can control that with the redactHeader
. Its a comma separated list of dot delimited field paths to be redacted. Can contain wildcard *
path to target all array items.
For example to redact some fields.
api.post('/update/path', body, { headers: { [redactHeader]: 'requestBody.id, responseBody.user' });
You can also set redact at the axios instance level for global redaction rules:
const api = axios.create({ redact: ['requestBody'] });
You can perform different things on error / success by inspecting the "level" argument, passed to the log function.
import { axiosLogger } from '@ovotech/axios-logger';
import axios from 'axios';
const logger = axiosLogger((level, meta) => {
if (level === 'info') {
myOwnLogger.info('Successful request', meta);
graphResponseTimes(meta.responseTime);
}
if (level === 'error') {
myOwnLogger.error('Error request', meta);
}
});
You can run the tests with:
yarn test
Style is maintained with prettier and tslint
yarn lint
Deployment is preferment by lerna automatically on merge / push to master, but you'll need to bump the package version numbers yourself. Only updated packages with newer versions will be pushed to the npm registry.
Have a bug? File an issue with a simple example that reproduces this so we can take a look & confirm.
Want to make a change? Submit a PR, explain why it's useful, and make sure you've updated the docs (this file) and the tests (see test folder).
This project is licensed under Apache 2 - see the LICENSE file for details
FAQs
Log responses with sanitization
We found that @ovotech/axios-logger demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 77 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
Security News
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approaches.
Security News
Bun 1.2 enhances its JavaScript runtime with 90% Node.js compatibility, built-in S3 and Postgres support, HTML Imports, and faster, cloud-first performance.