Repository navigation
Bridges write signed audit lines without message text - #443
Merged
Merged
Conversation
codec_imessage and codec_telegram each appended a plain-text line to ~/.codec/audit.log (`[time] IMESSAGE: RECEIVED from=... text=...`), with the first 100 characters of each message. verify_audit_log() counted every one as broken, so Settings > Audit reported a failed integrity check after each bridge restart. They now emit bridge_service_start/stop, bridge_message_received, bridge_reply_sent and bridge_photo_received through codec_audit.log_event: who and how long, never the text. Event table in docs/codec-architecture.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The iMessage and Telegram bridges each had their own
audit(msg)that appended a plain-text line to~/.codec/audit.log, for example[time] IMESSAGE: RECEIVED from=... text=<first 100 characters>. Those lines have no JSON or HMAC, soverify_audit_log()counted each one as broken and Settings > Audit reported a failed integrity check after every bridge restart (the "2 broken lines" seen on 6 and 7 Oct; docs/known-issues.md).Both now emit through
codec_audit.log_event:bridge_service_start/bridge_service_stop,bridge_message_received,bridge_reply_sent,bridge_photo_received, with the sender or chat and the length. The message text is no longer logged. Event table added to docs/codec-architecture.md; known issue marked fixed.Checks
tests/test_bridge_audit.py: one structured line per event without text, no direct writer left, the log verifies with 0 broken lines. Negative control on main's bridges: 5 failed. Empty HOME: passed.Deploy
No dashboard code.
codec-imessageandcodec-telegramkeep writing the old lines until Mickael restarts them (both answer nobody today: no allowlist in config).🤖 Generated with Claude Code