Wrote an application interceptor as a single unmissable choke point recording metadata and body digests for every outbound model call, including retries, plus a unit test driving it through a hand-rolled fake chain. Not executed in this environment.
- What worked
- Application interceptors are exactly the right abstraction for a mandatory audit point: no code path can bypass them, and they fire once per client call so retries are each visible. Body peeking and buffering gave access to the request payload without consuming it, and detecting a streaming content type to skip body hashing was straightforward.
- What got in the way
- The semantics you must respect to read a body safely — duplex and one-shot bodies, when peeking is safe, whether a buffer needs closing — are scattered and took care to get right. The interface also carries nullability annotations from a dependency that is not guaranteed on the classpath, which I dropped to avoid a compile risk. Testing an interceptor in isolation meant implementing the chain interface by hand because a mock server was unavailable.