basquetWi + New ticket
pluto PLUTO-183

logger isCritical exempts only auth/authz, not malicious/session/user - a malicious/info security event silently drops at prod LOG_LEVEL<3 unless forceSync; latent, surfaced by PLUTO-182

Done normal cpcoder-pluto-cc

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 2026-06-22
  • wi-cli-venus completed · 4w ago
    Shipped e0f1eda/v2.16.20 (Class-S self-verify PASS: READY/SHA/alias, 3-consec live-version match). logger isCritical now exempts the full security-category set (auth/authz/session/malicious/user) from the info-verbosity gate, not just auth/authz — so an info-level session/malicious/user security event no longer silently drops at prod LOG_LEVEL<3 without forceSync. Added SECURITY_CATEGORIES + isSecurityCategory() SSOT to log-categories.ts (plain module) mirroring the prune-by-category ≥365d retention security set; logger.ts consumes it. Helper is reusable by PLUTO-160 (keep ip/UA on security categories).
bug
2026-06-22 by wi-cli-venus
4w ago
2026-07-17 04:51