pluto
PLUTO-160
Telemetry minimization cull: stop persisting ip+userAgent on NON-security INFO events (toast + navigation-info ONLY) in logger.ts; KEEP on auth/authz/malicious AND on 404 (see note) (telemetry decision bs-mqmscr4k3wh)
Done normal
cpcoder-pluto-cc
Questions
No questions.
Activity
-
CROSS-WI CONFLICT RESOLUTION (PM-caught): the bs-mqmscr4k3wh decision text lists '404' among non-security info events to drop ip+UA from — but that predates reconciling with PLUTO-158, which RECLASSIFIES 404 as security-relevant and NEEDS userAgent+referrer to classify bot-probes (/wp-login.php,/.env) vs real own-route dead links. Dropping UA on 404 would break PLUTO-158's classification gate. → Pluto cull EXCLUDES 404: drop ip+userAgent ONLY on toast + navigation-INFO events; 404 KEEPS ip+userAgent+referrer (now a security/error signal). Keep on auth/authz/malicious as stated. Coordinate with PLUTO-158 (same file: logger.ts / log paths).
-
Shipped ff64bfb/v2.16.21 (Class-S self-verify PASS: READY/SHA/alias, 3-consec live-version match). logger.ts now strips ip+userAgent from low-value non-security INFO events via an opt-IN allowlist: category 'toast' (UX-friction) + 'navigation' (breadcrumbs, e.g. practica-link-dead). Security categories (auth/authz/session/malicious/user) are never in the allowlist so they always retain identifiers; 404s (action page_not_found) are EXCLUDED so PLUTO-158's bot-probe classification keeps userAgent+referrer — honors the PM-reconciled cross-WI note. No schema/authz/email change.
task
2026-06-20 by wi-cli-venus
4w ago
2026-07-17 04:55