Skip to content

feat(proxy): label webhook and form calls on the existing audit log - #85

Merged
syucream merged 3 commits into
mainfrom
feat/proxy-trigger-audit-log
Sep 19, 2026
Merged

syucream merged 3 commits into
mainfrom
feat/proxy-trigger-audit-log

Conversation

@syucream

Copy link
Copy Markdown
Contributor

Summary

  • Classify n8n inbound trigger URLs (/webhook, /form, waiting, /mcp, -test variants) as surface=trigger / operation=invoke on the existing proxy audit logger (logger: n8n-cli-proxy), not a separate stream.
  • Identity is the same --log-identity stack as REST/MCP: IAP X-Goog-Authenticated-User-Email when no verified middleware identity exists. Trigger paths still do not run server middleware (public webhooks stay ungated).
  • Forwarding and auth are unchanged; this is a label on the line that was already emitted as transparent.

Test plan

  • bun test tests/proxy/trigger-path.test.ts tests/proxy/logging.test.ts tests/proxy/proxy.logging.test.ts
  • make quality-gate (1968 tests)
  • Confirm a POST /webhook/... log line has surface=trigger and, with --log-identity plus IAP in front, identitySource=iap-header
  • Confirm /mcp-server/ stays surface=mcp when the gate is on, and is not swallowed by /mcp

Made with Cursor

syucream and others added 3 commits September 12, 2026 20:20
Inbound trigger URLs were forwarded as surface=transparent, so they
were indistinguishable from other ungated traffic. Classify n8n's
webhook/form/waiting/mcp-trigger prefixes as surface=trigger with the
same logger and --log-identity IAP fallback already used elsewhere.

Co-authored-by: Cursor <cursoragent@cursor.com>
n8n's default MCP test endpoint is a sibling of /mcp, not a child, so
it was still logged as transparent.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@syucream
syucream merged commit 175b482 into main Sep 19, 2026
6 checks passed
@syucream
syucream deleted the feat/proxy-trigger-audit-log branch September 19, 2026 01:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant