Log incoming HTTP Request headers with a Server Filter

Learn to log every HTTP Request header with a @ServerFilter and a method annotated with @FilterRequest.

1. Getting Started

In this guide, we will create a Python application built with Pyronaut.

2. What you will need

To complete this guide, you will need the following:

  • Some time on your hands

  • GraalPy installed and the Pyronaut CLI available locally

3. Solution

We recommend that you follow the instructions in the next sections and create the application step by step. However, you can go right to the completed example.

4. Writing the Application

Create an application using the Pyronaut CLI (Command Line Interface) or Pyronaut Launch

pyronaut create example.micronaut.micronautguide

5. Logback

Configure logging in src/main.py to log the package example.micronaut with TRACE level.

src/main.py
LOGGING = {
    "version": 1,
    "disable_existing_loggers": False,
    "formatters": {
        "standard": {
            "format": "%(asctime)s [%(levelname)s] %(name)s: %(message)s"
        }
    },
    "handlers": {
        "console": {
            "class": "logging.StreamHandler",
            "level": "TRACE",
            "formatter": "standard",
            "stream": "ext://sys.stdout"
        }
    },
    "root": {
        "level": "INFO",
        "handlers": ["console"]
    },
    "loggers": {
        "example.micronaut": {
            "level": "TRACE"
        }
    }
}

dictConfig(LOGGING)

6. ServerFilter

Create a filter which logs the non-sensitive HTTP request headers.

src/example/micronaut/logging_headers_filter.py
from micronaut.core.order import Ordered
from micronaut.http import HttpRequest
from micronaut.http.annotation import RequestFilter, ServerFilter
from micronaut.http.filter import ServerFilterPhase
from micronaut.http.util import HttpHeadersUtil
from org.slf4j import LoggerFactory


@ServerFilter("/**")  (1)
class LoggingHeadersFilter(Ordered):
    LOG = LoggerFactory.getLogger("example.micronaut.LoggingHeadersFilter")

    @RequestFilter  (2)
    def filterRequest(self, request: HttpRequest) -> None:
        HttpHeadersUtil.trace(self.LOG, request.getHeaders())

    def getOrder(self) -> int:  (3)
        return ServerFilterPhase.FIRST.order()
1 @ServerFilter marks a bean as a filter for the HTTP Server. The annotation value Filter.MATCH_ALL_PATTERN means the filter matches all requests.
2 A filter method annotated with @RequestFilter runs before the request is processed. A filter method must be declared in a bean annotated with @ServerFilter or @ClientFilter.
3 Filters can be ordered by implementing Ordered in the filter class.

7. Controller

Create a controller that responds with a JSON object: {"message":"Hello World"}.

src/example/micronaut/hello_controller.py
from micronaut.http.annotation import Controller, Get


@Controller  (1)
class HelloController:

    @Get  (2)
    def index(self) -> dict[str, str]:
        return {"message": "Hello World"}  (3)
1 The class is defined as a controller with the @Controller annotation mapped to the path /.
2 The @Get annotation maps the method to an HTTP GET request.
3 The Micronaut framework will automatically convert it to JSON before sending it.

8. Running the Application

To run the application, use the pyronaut dev command, which starts the application on port 8080.

curl localhost:8080 -H "X-Request-Id: 1234"

You will see in the logs:

... TRACE e.micronaut.LoggingHeadersFilter - Host: localhost:8080
... TRACE e.micronaut.LoggingHeadersFilter - User-Agent: curl/8.4.0
... TRACE e.micronaut.LoggingHeadersFilter - Accept: */*
... TRACE e.micronaut.LoggingHeadersFilter - X-Request-Id: 1234

9. Tests

10. Logback Dependency in test scope

In addition to the runtime classpath, add the logback-classic dependency to the test classpath:

10.1. Write tests

Use Logback’s ListAppender to ease testing.

Create a test that verifies the filter logs HTTP headers and masks sensitive HTTP headers.

tests/example/micronaut/test_hello_controller.py
import java
import pytest
import requests
from pyronaut.test import MicronautTest, micronaut_test_fixture

ListAppender = java.type("ch.qos.logback.core.read.ListAppender")
LoggerFactory = java.type("org.slf4j.LoggerFactory")
Thread = java.type("java.lang.Thread")


@pytest.fixture
def my_context(request):
    fixture = micronaut_test_fixture(
        request,
        MicronautTest(environments=["test"], transactional=False),
    )  (1)
    yield fixture
    fixture.stop()


@pytest.fixture
def client(my_context):
    return requests.with_context(my_context)  (2)


def formatted_messages(appender) -> set[str]:
    return {
        appender.list.get(index).getFormattedMessage()
        for index in range(appender.list.size())
    }


def test_hello_filter_logging(client):
    appender = ListAppender()
    logger = LoggerFactory.getLogger("example.micronaut.LoggingHeadersFilter")
    logger.addAppender(appender)
    appender.start()

    try:
        response = client.get(
            "/",
            headers={
                "Authorization": "Bearer x",
                "foo": "bar",
            },
        )

        assert response.status_code == 200
        assert response.json() == {"message": "Hello World"}

        for _ in range(20):
            messages = formatted_messages(appender)
            if "foo: bar" in messages and "Authorization: *MASKED*" in messages:
                break
            Thread.sleep(50)

        messages = formatted_messages(appender)
        assert "foo: bar" in messages
        assert "Authorization: Bearer x" not in messages
        assert "Authorization: *MASKED*" in messages
    finally:
        logger.detachAppender(appender)
1 Annotate the class with @MicronautTest so the Micronaut framework will initialize the application context and the embedded server. More info.
2 Inject the HttpClient bean and point it to the embedded server.

11. Testing the Application

To run the tests:

pyronaut install
pyronaut validate-config
pyronaut test

12. Next Steps

Explore more features with Micronaut Guides.

Learn more about Filter Methods.

13. License

All guides are released with an Apache License 2.0 for the code and a Creative Commons Attribution 4.0 license for the writing and media (images).