Conversation
logback.xml.example sat in src/main/resources with root level DEBUG,
but the .example suffix means Logback never loads it -- deployments
that never manually copy it over get Logback's own built-in fallback
configurator instead, which also happens to be DEBUG-to-console. Same
visible symptom, but the file itself was inert; there was no actual
lever to turn the level down short of hand-authoring a real logback.xml
per deployment.
Rename it to logback.xml so it's picked up automatically, and change
the hard-coded DEBUG to ${LOG_LEVEL:-INFO} (Logback's standard
default-value substitution, resolved from a system property or OS
environment variable, falling back to the literal default when unset).
Default is INFO, not DEBUG: an opt-out-of-quiet default means every
deployment silently pays full log volume -- including the per-message
masking pass in SecureLogging -- unless someone remembers to turn it
down. Verbose logging should be an explicit per-environment opt-in via
LOG_LEVEL instead.
Also updates the two docs describing the old manual-copy workflow.
logback-test.xml.example is untouched; it's a separate, already-active
setup for test runs.
Follow-up to the previous commit: these two docs both described the old "copy logback.xml.example to logback.xml yourself" workflow, which is now stale now that logback.xml ships active. Point at LOG_LEVEL instead.
The previous commit only renamed logback.xml.example to logback.xml;
the actual level change didn't make it into that commit. Change the
hard-coded DEBUG to ${LOG_LEVEL:-INFO}: an unset LOG_LEVEL now falls
back to INFO instead of DEBUG, and any environment that wants more can
set LOG_LEVEL=DEBUG or TRACE explicitly.
Added a direct test that parses the shipped logback.xml into a fresh LoggerContext via Joran (the same parser Logback uses internally) with LOG_LEVEL set beforehand, since the application's own LoggerContext is configured once at JVM start and wouldn't exercise the default-value resolution this fix depends on. Writing it caught a real bug: the explanatory comment above <root> contained a bare "--", which XML disallows anywhere inside a comment body, not just at the delimiters. Xerces rejected the file outright (SAXParseException) rather than silently ignoring the comment, so this would have broken every deployment picking up this branch, not just this test. Reworded the comment to drop the double dash.
|
This was referenced Sep 23, 2026
Owner
Author
|
Superseded — squashed together with #102 and #103 into one combined commit, PR'd upstream directly: OpenBankProject#2920 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
logback.xml.examplesat insrc/main/resourceswith<root level="DEBUG">, but the.examplesuffix means Logback never auto-loads it. Deployments that never manually copy it over (which, on the affected sandbox, is all of them) get Logback's own built-in fallback configurator instead -- which also happens to default to DEBUG-to-console. Same visible symptom, but the file itself was inert; there was no actual lever to turn the level down short of hand-authoring a reallogback.xmlper deployment.unzip -p obp-api.jar logback.xml) and confirmed nologback.xml(without the suffix) exists inside it.Change
logback.xml.example->logback.xmlso it's picked up automatically.DEBUGto${LOG_LEVEL:-INFO}-- Logback's standard default-value substitution (supported since 1.0.x; this repo is on 1.5.18), resolved from a JVM system property or OS environment variable, falling back to the literal default when unset. A plainLOG_LEVEL=DEBUGcontainer env var is enough to override; no need to route through-Dlogback.configurationFilefor that part.SecureLogging(see fix: gate MdcLoggable masking on log-level and Redis-shipping checks #102) -- unless someone remembers to turn it down. Verbose logging should be an explicit per-environment opt-in instead.README.md,docs/brief_system_documentation.md) that described the old manual-copy workflow.logback-test.xml.exampleis untouched -- it's a separate, already-active setup for test runs (src/test/resources/logback-test.xmlalready exists and takes priority during tests regardless of this change).Test plan
mvn -pl obp-commons,obp-api -am compile -DskipTests -o-- BUILD SUCCESS,logback.xml(not.example) confirmed present intarget/classes.Superseded -- squashed together with #102 and #103 into one combined commit, PR'd upstream directly: OpenBankProject#2920