Skip to content

basalt / http/src / HttpLogSink

Interface: HttpLogSink ​

Defined in: http/src/error-report.ts:59

(fields, message) — pino's own signature, and the reason this is the shape.

Request data goes in fields, NEVER in message. message is always a string literal from this module, which removes format-string injection as a category rather than mitigating it: neither console nor pino can interpret a %s that never reaches the format position. It also removes log forging, since a value inside a structured field is JSON-encoded by pino and quoted by util.inspect on the console — a newline cannot end the line.

An earlier version composed one interpolated string and escaped it by hand. That was correct and tested, but static analysis cannot see a custom sanitiser, so the alert never cleared; and passing the error as a trailing argument to a printf-style call is worse than it looks — pino silently DROPS arguments beyond the placeholders, so the stack we log a 5xx for would have been thrown away.

Methods ​

error() ​

> error(fields, message): void

Defined in: http/src/error-report.ts:60

Parameters ​

fields ​

Record<string, unknown>

message ​

string

Returns ​

void


warn() ​

> warn(fields, message): void

Defined in: http/src/error-report.ts:61

Parameters ​

fields ​

Record<string, unknown>

message ​

string

Returns ​

void

Released under the MIT License.