Re^4: RFC / Audit: Mojo Login Example

by sundialsvc4 (Abbot)
on Mar 24, 2020 at 18:11 UTC

in reply to Re^3: RFC / Audit: Mojo Login Example
in thread RFC / Audit: Mojo Login Example

Replies are listed 'Best First'.
Re^5: RFC / Audit: Mojo Login Example
by haj (Curate) on Mar 24, 2020 at 22:06 UTC

    Well, yes, plain text logging is fine. Apache and nginx log files are machine-readable. There is a RFC for the meaning of status codes, and LogFileFormat together with the server's documentation provide information about the fields you can expect.

    But that's not enough: The typical form-based login will result in a redirection for both success (to whatever the application decides, probably just back to the page which caused a redirect to the login form in the first place) and failure (back to login). Frontend servers also don't log information from POST requests. Therefore, it is up to the application to provide the login name and the result. "Make the log entries machine-readable" doesn't imply a particular format, but rather: document how a log collector software can interpret your entries.

