docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

docs(pii): Add comments about conditionals around sending PII data - #16143

Merged
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize
May 5, 2025
Merged

docs(pii): Add comments about conditionals around sending PII data#16143
s1gr1d merged 4 commits into
developfrom
sig/defaultPii-standardize

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Based on the docs work for the issue getsentry/sentry-docs#13407, I went through the repository and looked for places where a conditional check for sendDefaultPii might be missing.

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think content length is something we could send

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!


const includeWithDefaultPiiApplied: RequestDataIncludeOptions = {
...include,
// todo: also exclude cookies and headers if sendDefaultPii is false

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is actually something we should do - the question is if we do this in a minor or major?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Http Client integration for browser, we only include the cookie data if this is explicitly enabled:

if(_shouldSendDefaultPii()){
try{
constcookieString=xhr.getResponseHeader('Set-Cookie')||xhr.getResponseHeader('set-cookie')||undefined;
if(cookieString){
responseCookies=_parseCookieString(cookieString);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, we should do it but my gut feeling is to do it in a major (see review comment)


/** Get the string representation of a body. */
export function getBodyString(body: unknown, _logger: Logger = logger): [string | undefined, NetworkMetaWarning?] {
// fixme: only add body string if `sendDefaultPii` is enabled?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, we'll just need to add maxRequestBodySize

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is only used in conjunction with Replay and the feature being enabled but I might be missing a case

setHttpStatus(span, response.status);
isolationScope.setContext('response', {
headers: response.headers.toJSON(),
headers: response.headers.toJSON(), // fixme: headers are passed 1:1

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For all the header-related data, we need to decide on whether we want to keep sending them all, filter them by excluding e.g. authorization headers or not send them all when no PII should be sent.

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the data you identified should all be gated by the option (see comments). But to me it seems like we can only make this changes when we ship the next major, just so that users are more aware of the changes and they might need to set this flag.

Therefore, my overall suggestion would be to replace fixme with TODO(v10), merge this and ensure we track the change for v10.

If folks have other opinions that's fine, too. But let's make sure we avoid surprising users with data we no longer send :)

Comment threadpackages/core/src/fetch.ts Outdated
if (handlerData.response) {
setHttpStatus(span, handlerData.response.status);

// fixme: only send if `sendDefaultPii`?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean w/o sendDefaultPii === true? agreed!

Comment threadpackages/vercel-edge/src/sdk.ts Outdated
Comment on lines 62 to 63
// fixme: integration can be included - but integration should not add IP address etc
...(options.sendDefaultPii ? [requestDataIntegration()] : []),

@Lms24Lms24Apr 29, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah I agree that we should handle this within the integration instead of the top-level decision here.

@s1gr1d
s1gr1d marked this pull request as ready for review April 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from a team as a code ownerApril 30, 2025 15:48
@s1gr1d
s1gr1d requested a review from Lms24April 30, 2025 15:48
@s1gr1ds1gr1d changed the title fix(pii): Add more conditionals around sending datadocs(pii): Add comments about conditionals around sending PII dataMay 5, 2025
@s1gr1d
s1gr1d merged commit 4d46e53 into developMay 5, 2025
@s1gr1d
s1gr1d deleted the sig/defaultPii-standardize branch May 5, 2025 08:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@Lms24