feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Merged
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Aug 26, 2026
Merged

feat!: Replace the deprecated http.target span attribute#23575
msonnb merged 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnbmsonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actionsBot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

PathSize% ChangeChange
@sentry/browser28.57 kB--
@sentry/browser - with treeshaking flags26.92 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.82 kB--
@sentry/browser (incl. Tracing)48.58 kB-0.02%-8 B 🔽
@sentry/browser (incl. Tracing + Span Streaming)48.6 kB-0.01%-4 B 🔽
@sentry/browser (incl. Tracing, Profiling)51.51 kB+0.01%+4 B 🔺
@sentry/browser (incl. Tracing, Replay)88.04 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.44 kB-0.02%-11 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas)92.75 kB-0.01%-1 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback)105.44 kB-0.01%-6 B 🔽
@sentry/browser (incl. Feedback)45.81 kB--
@sentry/browser (incl. sendFeedback)33.36 kB--
@sentry/browser (incl. FeedbackAsync)38.46 kB--
@sentry/browser (incl. Metrics)29.51 kB--
@sentry/browser (incl. Logs)29.8 kB--
@sentry/browser (incl. Metrics & Logs)30.43 kB--
@sentry/react30.31 kB--
@sentry/react (incl. Tracing)50.79 kB-0.02%-6 B 🔽
@sentry/vue35.69 kB--
@sentry/vue (incl. Tracing)50.82 kB--
@sentry/svelte28.59 kB--
CDN Bundle30.36 kB--
CDN Bundle (incl. Tracing)49.07 kB+0.02%+6 B 🔺
CDN Bundle (incl. Logs, Metrics)32.56 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.95 kB+0.02%+10 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)72.98 kB--
CDN Bundle (incl. Tracing, Replay)86.56 kB+0.01%+3 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.44 kB+0.01%+2 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.33 kB-0.02%-14 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.25 kB-0.02%-15 B 🔽
CDN Bundle - uncompressed89.97 kB--
CDN Bundle (incl. Tracing) - uncompressed146.69 kB-0.04%-55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed96.26 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.38 kB-0.04%-55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed225.36 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.12 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.79 kB-0.03%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.81 kB-0.02%-55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.48 kB-0.02%-55 B 🔽
@sentry/nextjs (client)53.33 kB-0.02%-6 B 🔽
@sentry/sveltekit (client)49.03 kB+0.02%+8 B 🔺
@sentry/core/server65.14 kB-0.12%-76 B 🔽
@sentry/core/browser52.34 kB+0.01%+2 B 🔺
@sentry/node121.5 kB-0.16%-187 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing87.51 kB-0.03%-20 B 🔽
@sentry/aws-serverless95.71 kB-0.25%-238 B 🔽
@sentry/cloudflare (withSentry) - minified199.5 kB+0.01%+13 B 🔺
@sentry/cloudflare (withSentry)495.46 kB+0.01%+20 B 🔺

View base workflow run

@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570CompareAugust 25, 2026 13:07
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8cCompareAugust 25, 2026 14:01
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4CompareAugust 25, 2026 14:39
@msonnb

Copy link
Copy Markdown
MemberAuthor

bugbot run

@msonnbmsonnb changed the title ref(core)!: Replace the deprecated http.target span attributefeat!: Replace the deprecated http.target span attributeAug 25, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code ownersAugust 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a teamAugust 25, 2026 14:44
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch 2 times, most recently from c0f52f9 to e71bd7aCompareAugust 25, 2026 14:52
msonnband others added 2 commits August 26, 2026 09:22
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.
`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnbforce-pushed the ms/http-attrs-target branch from e71bd7a to fc3aaaaCompareAugust 26, 2026 07:26
Comment threadpackages/nextjs/src/server/enhanceHandleRequestRootSpan.ts
@msonnb
msonnb merged commit 964e438 into developAug 26, 2026
276 of 305 checks passed
@msonnb
msonnb deleted the ms/http-attrs-target branch August 26, 2026 08:18
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
…ery`
`http.target` carried the path, the query string and the fragment in one
value, so it cannot be renamed onto a single replacement. v11 of the
JavaScript SDK splits it into `url.path`, `url.query` and `url.fragment`.
Adds the `http_target_to_url_path_and_query` transformation and sets
`http.target` to `_status: "transform"`. No aliases are added on purpose:
an alias group is symmetric, so aliasing `http.target` to both `url.path`
and `url.query` would declare those two equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…et` (#587)
`http.target` holds the path, the query string and the fragment in one
value. v11 of the JavaScript SDK splits it into `url.path`, `url.query`
and `url.fragment`.
The deprecation stays `_status: null` and drops the `replacement` field,
because there is no single replacement. The three replacements are named
in the reason instead.
No aliases are added on purpose. An alias group is symmetric, so aliasing
`http.target` to both `url.path` and `url.query` would declare those two
equivalent to each other.
Replaced by getsentry/sentry-javascript#23575
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@msonnb@logaretm