Uh oh!
There was an error while loading. Please reload this page.
This repository was archived by the owner on Aug 14, 2024. It is now read-only.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So only sending this in the envelope header if
tracingOriginsallows would mean we have to checktracingOriginsagainst the DSN or proxy to see if we're allowed to send it, correct?There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Are you referring to
user_id? Could you elaborate what you mean here? Generally, in the context of this PR we're not includingtracingOriginsin any way or condition. Just wanted to mention in the description that discussions around it are in the works.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, this referred to
user_id. Once discussed we could add something to clarify whether we need to checktracingOriginsagainst DSN / proxy.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So currently, the JS SDK's
BrowserTracingintegration does not check for the DSN (or a proxy) but it only determines if the URL of the outgoing request matches a string or regex specified intracingOrigins. So far, we haven't considered changing this but sincetracingOriginsis gonna be standardized, we can certainly discuss this. I would suggest though, discussing this in a separate issue about thetracingOriginsspec/changes.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For Java we have our own transport(s) for communication with Sentry so we'd have to separately add the check there if we so choose.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
tracingOriginsdoesn't really matter when determining what is sent to Sentry.tracingOriginsshould simply control which targets should receive a) asentry-traceheader b) DSC in a baggage header.This shouldn't concern transports but rather request instrumentation. I might be wrong though since I don't know specifics on the Java SDK.