feat(recorder): log replayable query records for allowlisted developers - #303
Merged
Conversation
Add a ReplayLogger gqlgen extension that emits one structured log line per operation submitted by a developer on the RECORDED_DEVELOPERS allowlist. Each line carries the raw query, variables, operation name, subject, and vehicle token ID so requests can be replayed against test environments. Recording is disabled when the setting is empty; both the HTTP GraphQL and MCP paths are covered. Co-Authored-By: Claude Fable 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ReplayLoggergqlgen extension that emits one structured log line per operation from developers on a configured allowlist, containing the raw query, variables, operation name, JWT subject, and vehicle token ID — everything needed to replay the request against a test environment.RECORDED_DEVELOPERSsetting: comma-separated developer license addresses (comma-separated string because the shared env loader only overrides scalars). Empty/unset disables recording entirely — the extension is not registered. Invalid addresses fail at startup.configureGQLExtensions, so the HTTP GraphQL and MCP paths record identically.Notes
common.HexToAddress, so config casing vs. JWT checksum casing doesn't matter.query replay recordand thedeveloperfield.Test plan
go test ./internal/queryRecorder/— covers allowlist parsing, a recorded request (field-level assertions on the JSON line), non-allowlisted developers, and unauthenticated requests.make lintclean.🤖 Generated with Claude Code