Eigenverft.WebLib.RequestTrafficLogging 1.0.0.10

dotnet add package Eigenverft.WebLib.RequestTrafficLogging --version 1.0.0.10
                    
NuGet\Install-Package Eigenverft.WebLib.RequestTrafficLogging -Version 1.0.0.10
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Eigenverft.WebLib.RequestTrafficLogging" Version="1.0.0.10" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Eigenverft.WebLib.RequestTrafficLogging" Version="1.0.0.10" />
                    
Directory.Packages.props
<PackageReference Include="Eigenverft.WebLib.RequestTrafficLogging" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Eigenverft.WebLib.RequestTrafficLogging --version 1.0.0.10
                    
#r "nuget: Eigenverft.WebLib.RequestTrafficLogging, 1.0.0.10"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Eigenverft.WebLib.RequestTrafficLogging@1.0.0.10
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Eigenverft.WebLib.RequestTrafficLogging&version=1.0.0.10
                    
Install as a Cake Addin
#tool nuget:?package=Eigenverft.WebLib.RequestTrafficLogging&version=1.0.0.10
                    
Install as a Cake Tool

Eigenverft.WebLib.RequestTrafficLogging

NuGet Version NuGet Downloads Repository CI Targets License

ASP.NET Core request traffic logging that combines framework HTTP capture with one structured completion record and explicit outcome semantics.

✨ At a glance

Capability Details
Record One combined request/response record with pipeline outcome and duration.
Capture Framework HTTP Logging provides optional bounded body capture; the default fields are Core and Routing.
Header safety Allow-listed headers and sensitive-value redaction are the defaults.
Dependency Uses Eigenverft.WebLib.ClientNetwork transitively for optional forwarded-IP details.

📦 Installation

dotnet add package Eigenverft.WebLib.RequestTrafficLogging

🚀 Quick start

using Eigenverft.WebLib.RequestTrafficLogging;

builder.Services.AddRequestTrafficLogging();

WebApplication app = builder.Build();
app.UseRequestTrafficLogging();

The package registers and activates ASP.NET Core UseHttpLogging() internally. Do not add a second UseHttpLogging() in the same linear pipeline. Place UseRequestTrafficLogging() before exception-handling middleware when handled exceptions should be classified as faulted with their final response status.

Record shape and completion semantics

The default record uses hierarchical property names in a stable diagnostic order:

  • request: Request.*, Request.Header.*, and Request.Body.*
  • connection: Connection.Remote.*, Connection.Local.*, and forwarded-IP information
  • identity and routing: Identity.* and Routing.*
  • response: Response.*, Response.Header.*, and Response.Body.*
  • pipeline result: Pipeline.Outcome, Pipeline.Aborted, Pipeline.DurationMs, and Pipeline.ExceptionType

Pipeline.Outcome describes how the middleware pipeline finished; it is independent of the HTTP status:

  • Completed: the downstream pipeline returned normally and no handled-exception feature remained. This can coexist with Pipeline.Aborted: true when the cancellation signal was observed only at the final snapshot, as commonly happens after a completed streaming or SSE response.
  • Aborted: an OperationCanceledException or IOException escaped while RequestAborted was set.
  • Faulted: another exception escaped, or the exception-handler feature reports an exception that was handled into a response.

Pipeline.Aborted is the raw value of RequestAborted.IsCancellationRequested at completion and does not by itself determine Pipeline.Outcome. Response.Started is sampled at the same point. Connection.ForwardedIpChain is rendered as a readable ->-separated chain.

The body text itself remains the framework-owned RequestBody or ResponseBody field. Its related WebLib metadata uses Request.Body.ContentType, Request.Body.DeclaredLength, Request.Body.Truncated and the corresponding Response.Body.* names. DeclaredLength is the HTTP Content-Length when known, not a byte counter invented by the logger. Body field groups are opt-in; configured body limits default to 4 KiB.

To populate forwarded-IP details, enable app.UseClientNetworkFeature() before the logging middleware. The feature's position relative to trusted Forwarded Headers determines which remote peer address it observes.

Header capture and sensitivity

For a deliberate full-header diagnostic session, opt in to raw header capture:

builder.Services.AddRequestTrafficLogging(options =>
{
    options.Fields = RequestTrafficLoggingFields.All;
    options.HeaderCaptureMode = HeaderCaptureMode.AllRaw;
});

AllRaw captures every incoming request and outgoing response header value, including previously unknown header names, bearer credentials and cookies. Multiple values are recorded individually as Request.Header.Name[0], Request.Header.Name[1], and similarly under Response.Header.*. The default AllowListed mode and SensitiveValueMode behavior remain unchanged. Raw mode requires the corresponding RequestHeaders or ResponseHeaders field flag and does not expand body limits or change middleware placement. Protect the resulting logs accordingly.

🎯 Target frameworks

Targets net8.0 and net10.0; .NET 9 applications can consume the compatible net8.0 asset.

📄 License

MIT; see the repository license.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0.10 88 9/29/2026
1.0.0.9 89 9/28/2026
1.0.0.8 82 9/24/2026
1.0.0.7 95 9/24/2026
1.0.0.6 97 9/23/2026
1.0.0.5 85 9/23/2026
1.0.0.4 120 9/12/2026

Corrected Pipeline.Outcome cancellation semantics.

- Keeps Pipeline.Outcome=Completed when the downstream pipeline returned normally, even if RequestAborted is set at the final snapshot.
- Reserves Pipeline.Outcome=Aborted for an escaping OperationCanceledException or IOException accompanied by the cancellation signal.
- Keeps Pipeline.Aborted as the independent raw cancellation signal, so completed streaming and SSE responses can report Completed together with Pipeline.Aborted=true.
- Preserves all hierarchical field names introduced in 1.0.0.7.
- This is a breaking behavioral change for log queries or dashboards that treated every observed cancellation signal as Pipeline.Outcome=Aborted.

Introduced hierarchical traffic diagnostics fields as the default output contract.

- Groups fields under Request.*, Connection.*, Identity.*, Routing.*, Response.*, and Pipeline.*.
- Emits both allowlisted and raw headers under Request.Header.* and Response.Header.*.
- Renames body length metadata to *.Body.DeclaredLength to reflect Content-Length semantics.
- Orders the controlled fields from request input through response and final pipeline outcome.
- This is a breaking field-name change for log queries and dashboards; framework body text remains RequestBody/ResponseBody.

Previously clarified traffic diagnostics fields for flat log output.

- Renamed Outcome to PipelineOutcome and ResponseStarted to ResponseStartedAtCapture.
- Renders ForwardedIpChain as readable text instead of an array type name.
- These log-field changes require consumers of the previous field names to update their queries.

Previously added opt-in AllRaw request and response header capture for traffic diagnostics.

- Captures every header value, including unknown names and sensitive values, without framework redaction when enabled.
- Keeps the existing allowlisted, redacted behavior as the default.
- Preserves multiple values separately and respects the existing header field flags.