====================================================================== STEP 1: JWT/TOKEN CAPTURE FROM SIGNIN RESPONSES ====================================================================== --- Q1: /api/v1/auth/signin RESPONSE (30d) --- lines: 0 Tokens found: 0 --- Q2: /api/v1/auth/signup RESPONSE (30d) --- lines: 0 --- Q3: /api/v1/auth/current-user RESPONSE (7d, 50 lines) --- lines: 12 [1] user= role= company=77 [2] user= role= company=77 [3] user= role= company=77 [4] user= role= company=77 [5] user= role= company=76 [6] user= role= company=76 [7] user= role= company=76 [8] user= role= company=76 [9] user= role= company=74 [10] user= role= company=74 --- Q4: Bearer/JWT/token in logs (7d) --- lines: 0 ====================================================================== STEP 2: INTERNALTOKENFILTER REVERSE ====================================================================== --- Q5: /internal/ requests (30d) --- lines: 8 [1] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@5f4dd848, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@964d5e9, org.springframework.security.web.context.SecurityContextHolderFilter@20707ea9, org.springframework.security.web.header.HeaderWriterFilter@b7eb48f, org.springframework.web.filter.CorsFilter@4f13aa50, org.springframework.security.web.authentication.logout.LogoutFilter@466f1d3e, tv.adgentic.filter.InternalTokenFilter@35ae35ac, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@68e73d7f, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@6d8481b6, org.springframework.security.web.authentication.AnonymousAuthenticationFilter [2] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@381398ff, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@307ee048, org.springframework.security.web.context.SecurityContextHolderFilter@3c5955bc, org.springframework.security.web.header.HeaderWriterFilter@61241c4d, org.springframework.web.filter.CorsFilter@71b92428, org.springframework.security.web.authentication.logout.LogoutFilter@707189ac, tv.adgentic.filter.InternalTokenFilter@4e891054, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@619d83bf, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@7308bd1d, org.springframework.security.web.authentication.AnonymousAuthenticationFilt [3] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@5941fc14, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@605f08ed, org.springframework.security.web.context.SecurityContextHolderFilter@20bc49f4, org.springframework.security.web.header.HeaderWriterFilter@520077a5, org.springframework.web.filter.CorsFilter@ae93fb7, org.springframework.security.web.authentication.logout.LogoutFilter@58a4a9dc, tv.adgentic.filter.InternalTokenFilter@49e4d31e, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@4d55e486, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@3e528738, org.springframework.security.web.authentication.AnonymousAuthenticationFilte [4] BadGatewayException on uri=/internal/campaigns/75/audience-segments/fetch: Audience segment provider unavailable: MCP HTTP error 500 INTERNAL_SERVER_ERROR: 500 Internal Server Error from POST https://mcp.pubmatic.com/mcp [5] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@6449485a, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@56d812e8, org.springframework.security.web.context.SecurityContextHolderFilter@18d61c2f, org.springframework.security.web.header.HeaderWriterFilter@65eabb9c, org.springframework.web.filter.CorsFilter@772b75d2, org.springframework.security.web.authentication.logout.LogoutFilter@701f8b18, tv.adgentic.filter.InternalTokenFilter@65821a3e, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@2d4db28e, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@4e6bcc39, org.springframework.security.web.authentication.AnonymousAuthenticationFilt [6] BadGatewayException on uri=/internal/campaigns/70/audience-segments/fetch: Audience segment provider unavailable: MCP HTTP error 500 INTERNAL_SERVER_ERROR: 500 Internal Server Error from POST https://mcp.pubmatic.com/mcp [7] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@6b0bad4b, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@622720d5, org.springframework.security.web.context.SecurityContextHolderFilter@359c5f44, org.springframework.security.web.header.HeaderWriterFilter@13c81d6e, org.springframework.web.filter.CorsFilter@2cf4e4db, org.springframework.security.web.authentication.logout.LogoutFilter@48f58c66, tv.adgentic.filter.InternalTokenFilter@69b2c2e3, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@26f5f022, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@5effaf0f, org.springframework.security.web.authentication.AnonymousAuthenticationFilt [8] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@241d942b, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@41518c1d, org.springframework.security.web.context.SecurityContextHolderFilter@63d7cfc, org.springframework.security.web.header.HeaderWriterFilter@328530d4, org.springframework.web.filter.CorsFilter@1349f34a, org.springframework.security.web.authentication.logout.LogoutFilter@2b579862, tv.adgentic.filter.InternalTokenFilter@88403e9, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@32c8b088, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@2e1cc6ff, org.springframework.security.web.authentication.AnonymousAuthenticationFilter --- Q6: InternalTokenFilter (30d) --- lines: 6 [1] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@5f4dd848, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@964d5e9, org.springframework.security.web.context.SecurityContextHolderFilter@20707ea9, org.springframework.security.web.header.HeaderWriterFilter@b7eb48f, org.springframework.web.filter.CorsFilter@4f13aa50, org.springframework.security.web.authentication.logout.LogoutFilter@466f1d3e, tv.adgentic.filter.InternalTokenFilter@35ae35ac, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@68e73d7f, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@6d8481b6, org.springframework.security.web.authentication.AnonymousAuthenticationFilter [2] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@381398ff, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@307ee048, org.springframework.security.web.context.SecurityContextHolderFilter@3c5955bc, org.springframework.security.web.header.HeaderWriterFilter@61241c4d, org.springframework.web.filter.CorsFilter@71b92428, org.springframework.security.web.authentication.logout.LogoutFilter@707189ac, tv.adgentic.filter.InternalTokenFilter@4e891054, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@619d83bf, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@7308bd1d, org.springframework.security.web.authentication.AnonymousAuthenticationFilt [3] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@5941fc14, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@605f08ed, org.springframework.security.web.context.SecurityContextHolderFilter@20bc49f4, org.springframework.security.web.header.HeaderWriterFilter@520077a5, org.springframework.web.filter.CorsFilter@ae93fb7, org.springframework.security.web.authentication.logout.LogoutFilter@58a4a9dc, tv.adgentic.filter.InternalTokenFilter@49e4d31e, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@4d55e486, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@3e528738, org.springframework.security.web.authentication.AnonymousAuthenticationFilte [4] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@6449485a, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@56d812e8, org.springframework.security.web.context.SecurityContextHolderFilter@18d61c2f, org.springframework.security.web.header.HeaderWriterFilter@65eabb9c, org.springframework.web.filter.CorsFilter@772b75d2, org.springframework.security.web.authentication.logout.LogoutFilter@701f8b18, tv.adgentic.filter.InternalTokenFilter@65821a3e, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@2d4db28e, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@4e6bcc39, org.springframework.security.web.authentication.AnonymousAuthenticationFilt [5] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@6b0bad4b, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@622720d5, org.springframework.security.web.context.SecurityContextHolderFilter@359c5f44, org.springframework.security.web.header.HeaderWriterFilter@13c81d6e, org.springframework.web.filter.CorsFilter@2cf4e4db, org.springframework.security.web.authentication.logout.LogoutFilter@48f58c66, tv.adgentic.filter.InternalTokenFilter@69b2c2e3, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@26f5f022, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@5effaf0f, org.springframework.security.web.authentication.AnonymousAuthenticationFilt [6] Will secure Or [Mvc [pattern='/internal/**']] with [org.springframework.security.web.session.DisableEncodeUrlFilter@241d942b, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@41518c1d, org.springframework.security.web.context.SecurityContextHolderFilter@63d7cfc, org.springframework.security.web.header.HeaderWriterFilter@328530d4, org.springframework.web.filter.CorsFilter@1349f34a, org.springframework.security.web.authentication.logout.LogoutFilter@2b579862, tv.adgentic.filter.InternalTokenFilter@88403e9, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@32c8b088, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@2e1cc6ff, org.springframework.security.web.authentication.AnonymousAuthenticationFilter --- Q7: approve_user / verify_email (30d) --- lines: 0 --- Q8: X-Auth / X-Token / X-Internal headers (30d) --- lines: 0 ====================================================================== SUMMARY ====================================================================== Tokens found in signin responses: 0 InternalTokenFilter observations: - filter position 7 in Spring Security chain (from actuator/prometheus) - 324 requests processed by InternalTokenFilter (from actuator/prometheus)