1. Introduction

This Library brings back the Groovy DSL for configuring Logback. There was some concern about security of the DSL so this library adds security via the SecureASTCustomizer.

Note while this is meant to be more secure than the initial implementation, and while I will give some opinions on how you might be use this library is a more secure manner, your application security is up to you. You use this library at your own risk. If you find any flaws/security risks you can log them on the GitHub Issues Page: https://github.com/virtualdogbert/logback-groovy-config/issues

It is suggested that you use or make a sample app when submitting an issue. A shell app is provided under the examples directory. You can alter this adding your logback groovy config, and dependencies relevant to the issue.

This library uses a Java Service Configuator GroovyConfigurator.groovy which is dynamically called by logback-classic on startup.

Pull requests are welcome provided you provide any tests demonstrating/testing any new features, and documentation to go along with it.

The app does have default security configuration, which can be overridden see the section:

Pull request changing the default configuration will not be accepted unless they fix a security flaw, or there is a really good reason provided, that makes sense for all users of the library.

You can find the default configuration here:

These defaults limit what can be done in the DSL, in terms of imports and method calls.

The overrides do not provide for overriding the ScriptExpressionChecker this checker, checks for methods that are allowed by the DSL and are part of the over all security. If you find that a DSL method is missing, or if an extension library like the logstash-logback-encoder adds DSL methods that are not allowed you can open an issue on GitHub: https://github.com/virtualdogbert/logback-groovy-config/issues

Please be sure to include sample configuration showing all the DSL methods you used, preferably is a sample app. If the DSL method comes from an Opensource extension please provide a link to the project. Additions to the DSL allowed methods will be handled on a case by case basis, at my description, and the documentation will be updated noting the additions in the version history.

2. Version History

  • 1.14.5, 1.13.5, 1.12.5

    • Adding jsonGeneratorDecorator and fieldNames as accepted DSL methods for use with the logstash-logback-encoder.

  • 1.14.4, 1.13.4, 1.12.4

    • Adding missing DSL element, adding some more default imports and making the defaults always apply, and are just added on to, rather than overwritten with the logbackCompiler.groovy

  • 1.14.3, 1.13.3, 1.12.3

    • Adding on to default to make the default a little nicer.

  • 1.14.2, 1.13.2, 1.12.2

    • Found that the DSL methods are "added" to Object, because the dynamic nature of the runtime DSL. So I added on to the ScriptExpressionChecker accounting for that. I also updated the default config explaining the config of the ScriptExpressionChecker asking if there is a missing DSL method to submit a bug report.

  • 1.14.1, 1.13.1, 1.12.1

    • Found an issue in #4 where the ScriptExpressionChecker was being overzealous on method calls from objects that has sub objectExpressions that had types. So I loosened that up, and check for System and String types under the object type, and those have a restricted set of methods that they can call.

    • Upgraded to versions 1.4.6, 1.3.6, and 1.2.12 for logback versions

    • 1.2.12 is being release because there are still a lot of popular projects still using the old version(updated recently). With this version the config file will be name logback-config.groovy, because at this point logback will error if you have a logback.groovy.

  • 1.14.0

    • Upgrading to Logback 1.4.5

  • 1.13.0

    • Upgrading to Logback 1.3.5

    • Changing default filename back to logback.groovy

    • removing JMX config because it was removed from 1.3.5 because of potential vulnerability

  • 1.0

    • Initial Release

3. Getting Started

  1. Add the following dependency to .build.gradle:

Logback version 1.4.x:

implementation 'io.github.virtualdogbert:logback-groovy-config:1.14.5'

Logback version 1.3.x:

implementation 'io.github.virtualdogbert:logback-groovy-config:1.13.5'

Logback version 1.2.x:

implementation 'io.github.virtualdogbert:logback-groovy-config:1.12.5'

Add a logback.groovy file to your resources(e.g. grails-app/config, src/main/resources) using the Groovy DSL. The file name was defaulted to logback-config.groovy in 1.12.1 but was rolled back to logback.groovy because newer versions of logback shouldn’t throw and exception. However, you can be the config file name to anything you want. To change the file name you can use the system property: logback.config.file or the environment variable: LOGBACK_CONFIG_FILE

You can provide an external config file by setting the VM property logback.config.external.file or the environment property LOGBACK_CONFIG_EXTERNAL_FILE. The external file if provided will take president over the config in the resource.

Depending on the environment external files might make sense, although an alternative is to have environment variables in your internal config that can control aspects of your logging.

4. Examples

Here are some base example for the logback-config.groovy using the Logback Groovy DSL:

4.1. Spring Boot/Grails

import ch.qos.logback.classic.encoder.PatternLayoutEncoder
import ch.qos.logback.core.ConsoleAppender
import ch.qos.logback.core.FileAppender
import grails.util.BuildSettings
import org.springframework.boot.logging.logback.ColorConverter
import org.springframework.boot.logging.logback.WhitespaceThrowableProxyConverter

import java.nio.charset.StandardCharsets

import static grails.util.Environment.isDevelopmentMode

conversionRule 'clr', ColorConverter
conversionRule 'wex', WhitespaceThrowableProxyConverter

// See http://logback.qos.ch/manual/groovy.html for details on configuration
appender('STDOUT', ConsoleAppender) {
    encoder(PatternLayoutEncoder) {
        charset = StandardCharsets.UTF_8

        pattern =
                '%clr(%d{yyyy-MM-dd HH:mm:ss.SSS}){faint} ' + // Date
                        '%clr(%5p) ' + // Log level
                        '%clr(---){faint} %clr([%15.15t]){faint} ' + // Thread
                        '%clr(%-40.40logger{39}){cyan} %clr(:){faint} ' + // Logger
                        '%m%n%wex' // Message

def targetDir = BuildSettings.TARGET_DIR

if (isDevelopmentMode() && targetDir != null) {
    appender("FULL_STACKTRACE", FileAppender) {
        file = "${targetDir}/stacktrace.log"
        append = true

        encoder(PatternLayoutEncoder) {
            charset = StandardCharsets.UTF_8
            pattern = "%level %logger - %msg%n"

    logger("StackTrace", ERROR, ['FULL_STACKTRACE'], false)

root(INFO, ['STDOUT'])

4.2. Micronaut

import ch.qos.logback.classic.encoder.PatternLayoutEncoder
import ch.qos.logback.core.ConsoleAppender
import ch.qos.logback.core.FileAppender
import java.nio.charset.StandardCharsets

// See http://logback.qos.ch/manual/groovy.html for details on configuration
appender('STDOUT', ConsoleAppender) {
    encoder(PatternLayoutEncoder) {
        charset = StandardCharsets.UTF_8

        pattern = '%cyan(%d{HH:mm:ss.SSS}) %gray([%thread]) %highlight(%-5level) %magenta(%logger{36}) - %msg%n' // Message

root(INFO, ['STDOUT'])

5. Default Config

The following is the default accept lists that are used by SecureASTCustomizer to help add security to the Groovy DSL for Logback.

package ch.qos.logback.classic.gaffer

import ch.qos.logback.classic.LoggerContext
import ch.qos.logback.core.boolex.Matcher
import groovy.transform.CompileStatic

import static org.codehaus.groovy.syntax.Types.*

 * Default Accept Lists for the AST Customizer used to limit what can be done in the Groovy DSL for Logback.
class DefaultAcceptLists {

     * This Limits the acceptable tokens that can bs use in the Groovy DSL file. Like +-/% etc.
    static final List tokensAcceptList = [
            DIVIDE, PLUS, MINUS,
            MULTIPLY, MOD, POWER,

     * This limits the acceptable constant types that can be used in the DSL
    static final List constantTypesClassesAcceptList = [

     * This limits the acceptable static imports for the Groovy DSL
    static final List<String> staticImportsAcceptList = [

     * This limits the acceptable imports for the Groovy DSL.
    static final List<String> importsAcceptList = [
            'org.springframework.beans.factory.annotation.Autowired', //Grails requires this for some reason, but you can not autowire any service because those classes are not on the import list.





     * This limits the acceptable star imports for the Groovy DSL.
    static final List<String> starImportsAcceptList = []

     * This limits the acceptable star static imports for the Groovy DSL.
    static final List<String> staticStarImportsAcceptList = [

6. Overriding Default Config

The default config can be added on to by providing a logbackCompiler.groovy file in your resources directory. This makes it so that you can add to the default in your code, but not externally. If you are working where resources could be exposed externally, like in an exploded war scenario or something similar, then you will have to secure that directory. The following are the lists from the default config that you can override:

  • tokensAcceptList

  • constantTypesClassesAcceptList

  • staticImportsAcceptList

  • importsAcceptList

  • starImportsAcceptList

  • staticStarImportsAcceptList

The format in the file will be:

tokensAcceptList = [
        //your list here.

constantTypesClassesAcceptList = [
        //your list here.

staticImportsAcceptList = [
        //your list here.

importsAcceptList = [
        //your list here.

starImportsAcceptList = [
        //your list here.

staticStarImportsAcceptList = [
        //your list here.

Here is an example given every class you could import from the parent library Logback library:

importsAcceptList = [

