Skip to content

Added client caching and logger enhancements - #2180

Merged
anushasunkada merged 3 commits into
mosip:develop-gofrom
anushasunkada:develop-go
Jul 20, 2026
Merged

anushasunkada merged 3 commits into
mosip:develop-gofrom
anushasunkada:develop-go

Conversation

@anushasunkada

@anushasunkada anushasunkada commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • New Features
    • Added configurable client-detail caching with automatic cache invalidation after client changes.
    • Added scope-to-claims configuration for OpenID, profile, email, phone, and address.
    • Added correlation IDs and request access logging (status, timing, and request metadata) for easier tracing.
  • Bug Fixes
    • Improved resilience when shared caching is unavailable or cache operations fail, ensuring reliable client retrieval.
  • Chores
    • Enhanced structured logging and startup/engine diagnostics, including clearer warnings for non-production authorization modes and missing config files.

Signed-off-by: anushasunkada <anushasunkada@gmail.com>
Signed-off-by: anushasunkada <anushasunkada@gmail.com>
@coderabbitai

coderabbitai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

Client management now uses runtime-store caching with configurable TTL and invalidation. The service also adds structured JSON logging, correlation/access middleware, dynamic OAuth scope claims, endpoint scope enforcement, and diagnostic logs across startup and providers.

Changes

Runtime, observability, and authorization

Layer / File(s) Summary
Structured logging foundation
esignet-service/internal/log/*
Logging emits structured JSON records with application and logger metadata, numeric severity values, and access records.
Correlation and access middleware
esignet-service/internal/httpmiddleware/*, esignet-service/cmd/esignet/main.go
Requests receive propagated or generated correlation IDs, while access logs capture response status, bytes, duration, and request metadata.
Runtime-backed client caching
esignet-service/internal/clientmgmt/*, esignet-service/internal/config/app.go, esignet-service/cmd/esignet/main.go
Client reads use the runtime store before Postgres, writes invalidate cached rows, and cache failures fall back to database results.
OAuth scope mapping and security enforcement
esignet-service/internal/engine/actor_provider.go, esignet-service/internal/security/scope_middleware.go, esignet-service/data/deployment.yaml
OAuth responses derive configured scopes and claims, and management endpoints require mapped scopes with templated path matching.
Service and provider diagnostics
esignet-service/internal/consentmgmt/*, esignet-service/internal/engine/*, esignet-service/internal/security/*
Structured logs cover initialization, provider modes, consent operations, file loading, JWKS refreshes, OTP failures, and security rejection paths.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant CorrelationID
  participant ScopeMiddleware
  participant Mux
  participant AccessLog
  Client->>CorrelationID: Send request
  CorrelationID->>ScopeMiddleware: Attach trace ID
  ScopeMiddleware->>Mux: Validate token and mapped scope
  Mux-->>AccessLog: Return response
  AccessLog-->>Client: Return response and access record
Loading

Possibly related PRs

Poem

Cache rows glow,
Trace IDs flow,
Scopes guard each route,
JSON logs speak out.
Providers start bright—
Errors meet the light.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 41.07% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: client caching plus broader logger enhancements.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain main module or its selected dependencies"


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 7

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
esignet-service/internal/security/scope_middleware.go (1)

55-62: 🔒 Security & Privacy | 🔴 Critical | 🏗️ Heavy lift

Replace hardcoded scope validation with dynamic configuration.

Hardcoding the "test" scope in the security middleware bypasses proper authorization checks. This will either improperly block valid users or grant unauthorized access to sensitive endpoints, which directly violates MOSIP compliance and access control standards.

Please implement the TODO and resolve the required scope dynamically from config.SecurityConfig.ScopeMapping.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@esignet-service/internal/security/scope_middleware.go` around lines 55 - 62,
Replace the hardcoded "test" scope check in the scope middleware with validation
derived from config.SecurityConfig.ScopeMapping. Resolve the required scope for
the current request or endpoint, pass that value to claimHasScope, and use it in
the warning and forbidden error messages while preserving the existing rejection
behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@esignet-service/internal/clientmgmt/service.go`:
- Around line 309-318: The client lookup flow around GetClient and cacheRow must
cache sql.ErrNoRows results using the cache’s established negative-entry
mechanism, with a short TTL or not-found marker, before returning
ErrClientNotFound. Preserve existing positive-result caching and error handling
for other database failures.
- Around line 363-370: Update Service.invalidateCache to return the cache
deletion error instead of logging and swallowing it, while preserving the
no-cache early return. In esignet-service/internal/clientmgmt/service.go lines
193-194, make UpdateClient check and propagate this error; likewise check and
propagate it in PatchClient at lines 299-301 so both operations fail when
invalidation fails.

In `@esignet-service/internal/engine/actor_provider.go`:
- Around line 60-62: Rename the local pkceRequired boolean to isPKCERequired in
both affected sections of actor_provider.go (lines 60-62 and 107-109), and
update all references to that local value while preserving pkceRequired as the
map-key constant.
- Around line 240-249: Update getAllowedScopes to sort the keys collected from
standardScopeClaims before returning them, ensuring deterministic base-scope
ordering. Replace the direct []string assertion for
additionalConfig[allowedAuthorizationScopes] with handling that accepts
JSON-decoded []any values and converts valid string elements into []string,
while preserving support for []string and avoiding dropped authorization scopes.

In `@esignet-service/internal/httpmiddleware/accesslog.go`:
- Around line 21-41: Update AccessLog to sanitize the request URI before logging
it, replacing the raw r.RequestURI value passed to applog.String with
sanitizeURI(r.RequestURI). Implement or reuse sanitizeURI so sensitive query
parameters including state, nonce, code, login_hint, and id_token_hint are
redacted while preserving the rest of the URI.
- Around line 43-58: Update statusRecorder to forward the underlying
http.ResponseWriter’s http.Flusher and http.Hijacker capabilities, delegating
Flush and Hijack calls to the wrapped writer so streaming and protocol-upgrade
handlers retain their optional interfaces.

In `@esignet-service/internal/log/log.go`:
- Around line 127-160: Update all six Logger methods—Debug, Info, Warn, Error,
Fatal, and Access—to call convertFields on the caller-provided fields before
appending the level field. Append the converted level field only to the newly
created slice, preserving each method’s existing logging behavior and Fatal
process exit.

---

Outside diff comments:
In `@esignet-service/internal/security/scope_middleware.go`:
- Around line 55-62: Replace the hardcoded "test" scope check in the scope
middleware with validation derived from config.SecurityConfig.ScopeMapping.
Resolve the required scope for the current request or endpoint, pass that value
to claimHasScope, and use it in the warning and forbidden error messages while
preserving the existing rejection behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 86ce4c18-003e-4448-87d5-7313df2acaf6

📥 Commits

Reviewing files that changed from the base of the PR and between 51c38cf and c8f6519.

📒 Files selected for processing (35)
  • esignet-service/cmd/esignet/main.go
  • esignet-service/data/deployment.yaml
  • esignet-service/internal/clientmgmt/handler.go
  • esignet-service/internal/clientmgmt/handler_test.go
  • esignet-service/internal/clientmgmt/service.go
  • esignet-service/internal/clientmgmt/service_test.go
  • esignet-service/internal/config/app.go
  • esignet-service/internal/consentmgmt/model.go
  • esignet-service/internal/consentmgmt/model_test.go
  • esignet-service/internal/consentmgmt/service.go
  • esignet-service/internal/consentmgmt/service_test.go
  • esignet-service/internal/consentmgmt/util.go
  • esignet-service/internal/consentmgmt/util_test.go
  • esignet-service/internal/engine/actor_provider.go
  • esignet-service/internal/engine/actor_provider_test.go
  • esignet-service/internal/engine/authz_provider.go
  • esignet-service/internal/engine/consent_provider.go
  • esignet-service/internal/engine/consent_provider_test.go
  • esignet-service/internal/engine/design_provider.go
  • esignet-service/internal/engine/executors.go
  • esignet-service/internal/engine/flow_provider.go
  • esignet-service/internal/engine/i18n_provider.go
  • esignet-service/internal/engine/mock/authenticator_test.go
  • esignet-service/internal/engine/mock/init.go
  • esignet-service/internal/engine/mosip/init.go
  • esignet-service/internal/engine/sunbird/init.go
  • esignet-service/internal/httpmiddleware/accesslog.go
  • esignet-service/internal/httpmiddleware/accesslog_test.go
  • esignet-service/internal/httpmiddleware/correlationid.go
  • esignet-service/internal/httpmiddleware/correlationid_test.go
  • esignet-service/internal/log/log.go
  • esignet-service/internal/log/log_test.go
  • esignet-service/internal/security/jwks.go
  • esignet-service/internal/security/requesttime.go
  • esignet-service/internal/security/scope_middleware.go

Comment thread esignet-service/internal/clientmgmt/service.go
Comment thread esignet-service/internal/clientmgmt/service.go Outdated
Comment thread esignet-service/internal/engine/actor_provider.go Outdated
Comment thread esignet-service/internal/engine/actor_provider.go
Comment thread esignet-service/internal/httpmiddleware/accesslog.go
Comment thread esignet-service/internal/httpmiddleware/accesslog.go
Comment thread esignet-service/internal/log/log.go
Comment thread esignet-service/internal/httpmiddleware/correlationid.go
Comment thread esignet-service/internal/clientmgmt/service.go
Signed-off-by: anushasunkada <anushasunkada@gmail.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@esignet-service/internal/httpmiddleware/accesslog.go`:
- Around line 62-79: Add an Unwrap method to statusRecorder that returns its
wrapped http.ResponseWriter, allowing http.ResponseController to inspect the
underlying writer’s actual capabilities. Keep the existing Flush and Hijack
delegation unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 820fd0fc-7f8d-4556-8c97-4f956b1afe32

📥 Commits

Reviewing files that changed from the base of the PR and between c8f6519 and 4ebc108.

📒 Files selected for processing (14)
  • esignet-service/data/deployment.yaml
  • esignet-service/internal/clientmgmt/service.go
  • esignet-service/internal/clientmgmt/service_test.go
  • esignet-service/internal/consentmgmt/service.go
  • esignet-service/internal/consentmgmt/util.go
  • esignet-service/internal/engine/actor_provider.go
  • esignet-service/internal/engine/actor_provider_test.go
  • esignet-service/internal/httpmiddleware/accesslog.go
  • esignet-service/internal/httpmiddleware/accesslog_test.go
  • esignet-service/internal/httpmiddleware/correlationid.go
  • esignet-service/internal/httpmiddleware/correlationid_test.go
  • esignet-service/internal/log/log.go
  • esignet-service/internal/security/scope_middleware.go
  • esignet-service/internal/security/scope_middleware_test.go

Comment thread esignet-service/internal/httpmiddleware/accesslog.go
@anushasunkada
anushasunkada merged commit c1ddaf1 into mosip:develop-go Jul 20, 2026
17 of 22 checks passed
@coderabbitai coderabbitai Bot mentioned this pull request Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants