mirror of
https://github.com/tiennm99/goclaw.git
synced 2026-10-04 06:13:15 +00:00
prefilter() had zero logging -- matcher regex failures, tool-name mismatches, CEL compile errors, and CEL evaluating to false were all completely silent, making a misconfigured hook impossible to debug. A user's PreToolUse script hook silently failed to block an unauthorized file write with no way to determine why. - Added slog.Debug/Warn logging throughout prefilter() and the dispatch chain: hooks.prefilter.considered, matcher_checked, condition_evaluated, error, and hooks.dispatch.decision -- covering matcher match/miss, CEL compile/eval result, and final decision with reasoning. - console.log/console.error output from script hooks (captured via the existing goja sandbox stdout buffer, previously discarded after execution) now surfaces via slog.Debug and persists into HookExecution.ConsoleOutput / Metadata["console_output"] in the audit record, using the existing metadata JSON column (no migration needed). - Fail-closed, narrowly scoped: when a hook's matcher successfully matches a tool call but CEL condition or script execution then errors, the dispatcher now blocks that specific tool call (previously: silently treated as non-match, call proceeded allowed). Hooks that legitimately don't match remain unaffected pass-through -- this does not turn one broken hook into a global outage, it only blocks the specific gated action that couldn't be confidently evaluated. Added tests: matched-then-CEL-errors blocks the call and never invokes the handler; matcher-doesn't-match proceeds normally unaffected (confirms narrow scope); console.log output is captured in the audit record. Co-authored-by: Bruno Clermont <bruno.clermont@gmail.com>