Commit 2028874
feat(core): Data Collection (#5759)
* ref(core): Rename URL query parameter resolver
Keep the internal resolver and its tests aligned with the canonical public Data Collection option name.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* ref(http): Use URL query parameter option name
Update URL filtering and integration coverage to consume the renamed canonical Data Collection option.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* test(spring): Bind URL query parameter policies
Use the canonical URL query parameter property name in Spring Boot 2, 3, and 4 binding coverage.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(core): Preserve Data Collection on null setter
Ignore null assignments so the always-present Data Collection configuration and its current values remain intact.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(android): Preserve installation ID independently of Data Collection
Keep the Android installation ID available for distinct ID, user ID, device ID, and hybrid scope fallbacks regardless of the userInfo setting. Continue applying userInfo only to automatic user details such as IP addresses and remove the now-unused legacy-always resolver variant.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(ktor): Exclude query parameters from span descriptions
Parse Ktor client request URLs through the shared URL utility so span descriptions omit query parameters and fragments. Keep the raw URL for trace propagation and avoid introducing query span data.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* test(apollo): Cover response header filtering
Verify Apollo 4 applies deny-list behavior to response headers for both supported execution implementations.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(opentelemetry): Exclude queries from span descriptions
Parse the url.full fallback through the shared URL utility before using it as an HTTP span description. This removes query parameters and fragments while preserving route and target handling.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(opentelemetry): Preserve completed request headers
Do not apply Data Collection policies while converting completed OpenTelemetry attributes. Preserve the existing sendDefaultPii behavior because completed attributes may have been supplied manually by customers.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(opentelemetry): Preserve completed URL attributes
Do not apply Data Collection policies while converting completed OpenTelemetry URL attributes. Preserve manually supplied values and leave attribute collection controls to OpenTelemetry.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(opentelemetry): Normalize legacy HTTP target descriptions
Exclude query parameters and fragments when deriving Sentry span descriptions from the legacy http.target attribute. Leave the completed OpenTelemetry attribute unchanged.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(database): Preserve query descriptions
Keep sanitized or parameterized query text independent of databaseQueryData. The option only controls bound parameters, write payloads, and result data, which the current JDBC and SQLite integrations do not collect.
Remove the unused legacy resolver path and its policy-specific tests.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(replay): Keep Replay independent from Data Collection
Restore Session Replay network privacy settings as the only controls for
Replay data. Data Collection and sendDefaultPii do not affect Replay, which
avoids changing behavior for existing Replay users.
Add coverage that restrictive Data Collection settings leave explicitly
enabled Replay network details unchanged.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* test(graphql): Cover GraphqlUtils request body filtering
Add focused coverage for parsing a single GraphQL request object and
independently removing document and variable content while preserving
operation metadata and allowed fields.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(graphql): Filter batched GraphQL request bodies
Apply document and variable collection policies to every operation in a
batched GraphQL request. Fail closed when a batch contains non-object
entries instead of attaching partially filtered content.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* test(graphql): Cover malformed batched request body entries
Verify GraphQL request filtering fails closed when a batch contains a non-object entry.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* ref(core): Clarify forced Data Collection configuration
Rename the internal override marker to explain that it forces an empty Data Collection object into explicit mode. Align the related tests with the clarified semantics.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* test(core): Clarify Data Collection resolver scenarios
Separate legacy sendDefaultPii fallback coverage from configured Data Collection behavior. Give each resolver test a name that describes one configuration state.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* test(apollo): Cover request header filtering in Apollo 4
Verify that Apollo 4 applies configured Data Collection deny-list behavior to captured request headers across both supported execution paths.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* feat(core): Add Data Collection external options
Parse flattened Data Collection settings from properties, system properties, and environment variables. Merge only configured values so omitted settings retain their documented or legacy behavior.
Refs #5666
* fix(core): Use URL query parameter external option name
Align the flattened external configuration key with the Data Collection option name used by the specification and Android manifest configuration.\n\nRefs #5666\nCo-Authored-By: Claude <noreply@anthropic.com>
* feat(android): Add Data Collection manifest options
Parse flattened Data Collection metadata while preserving existing option values for fields omitted from the manifest. Expose internal configuration-state helpers across SDK modules so Android can distinguish absent metadata from explicit settings.\n\nRefs #5666\nCo-Authored-By: Claude <noreply@anthropic.com>
* fix(core): Reject malformed cookie pairs
Validate cookie names and values before applying Data Collection filters.
Fail closed for malformed values that could embed additional sensitive
cookie pairs while preserving valid quoted and padded values.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* revert: fix(android): Apply user info policy to distinct ID
This reverts commit b27d61d.\n\nKeep generated installation IDs independent of the userInfo policy. Restore\ndefault generation before programmatic configuration so applications can\ncontinue clearing the distinct ID in the configuration callback.\n\nRefs #5666\n\nCo-Authored-By: Claude <noreply@anthropic.com>
* fix(core): Skip null filtered cookie headers
Avoid adding nullable filter results to cookie header lists so downstream consumers only receive actual header values.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(core): Preserve blank cookie segments
Keep empty and whitespace-only cookie segments unchanged instead of replacing them with a filtered marker.
Co-Authored-By: Claude <noreply@anthropic.com>
* ref(core): Remove broad cookie filtering catches
Let unexpected implementation errors remain visible instead of swallowing fatal JVM errors during deterministic cookie parsing.
Co-Authored-By: Claude <noreply@anthropic.com>
* ref(core): Extract cookie utilities from HTTP utilities
Move cookie parsing and filtering into a focused internal utility and update integrations to use it. Keep generic query and header filtering in HttpUtils.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(core): Avoid sharing Data Collection fallbacks
Create key-value fallback behaviors for each resolver lookup so mutations cannot leak across cookie, query parameter, and header policies.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(core): Support WebSocket URL parsing
Treat ws and wss as valid hierarchical URIs without requiring JVM URL handlers. This preserves Ktor WebSocket span descriptions and query filtering instead of falling back to an unknown URL.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* changelog
* test(okhttp): Use valid Set-Cookie fixture
Exercise response cookie filtering with a valid cookie and preserve its attributes in the expected output.
Co-Authored-By: Claude <noreply@anthropic.com>
* revert: fix(opentelemetry): Exclude queries from span descriptions
Revert the OpenTelemetry span-description normalization from this stack PR. Preserve completed OpenTelemetry URL and target values when deriving descriptions.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(core): [Data Collection 24] Narrow utility exception handling
Catch only the recoverable failures produced while filtering GraphQL bodies and decoding query parameter names. Preserve fail-closed handling for malformed GraphQL Unicode escapes without swallowing fatal JVM errors.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(spring): Preserve URL credential filtering
Build WebClient span descriptions from sanitized URL details in legacy mode. Avoid exposing URL credentials when Data Collection is not explicitly configured.
Co-Authored-By: Claude <noreply@anthropic.com>
* ref(core): Centralize HTTP client cookie filtering
Move Data Collection and legacy cookie policy selection into CookieUtils. Remove duplicated wrappers from OkHttp, Ktor, and Apollo integrations.
Co-Authored-By: Claude <noreply@anthropic.com>
* docs: Document Data Collection configuration
Describe Data Collection defaults, migration from sendDefaultPii, and the supported configuration mechanisms. Include examples for key-value filtering and HTTP body selection so users can adopt the new controls safely.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* feat(core): [Data Collection 25] Apply file path policy
Add the specification-defined filePaths option across programmatic, external, Spring Boot, and Android manifest configuration. Gate automatically captured File I/O paths through the resolved policy while preserving sendDefaultPii when Data Collection is absent.\n\nRefs #5666
* feat(logback): [Data Collection 26] Add unencoded message opt-in
Allow encoder-equipped Logback appenders to include original message
templates and parameters without relying on sendDefaultPii.
Keep sendDefaultPii as a temporary compatibility exception while Data
Collection replaces its other behavior.
Co-Authored-By: Claude <noreply@anthropic.com>
* docs(logback): Clarify unencoded message behavior
Describe how encoder use, the integration opt-in, and the legacy PII option control original message data.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(logback): Expose mutable Kotlin appender option
Align the includeUnencodedMessage getter and setter names so Kotlin exposes the option as a mutable synthetic property.
Refs #5666
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(core): Expose mutable Kotlin Data Collection options
Align nullable Boolean getters and setters so Kotlin exposes mutable synthetic properties. Allow callers to clear an explicit override by assigning null.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(core): [Data Collection 27] Make opt-in explicit
Stop treating DataCollection construction as an implicit opt-in. Add an explicit forceDataCollection method so callers can select the new defaults without replacing manifest or external configuration.
Co-Authored-By: Claude <noreply@anthropic.com>
* docs: Document explicit Data Collection opt-in
Show how to opt in to the documented Data Collection defaults without configuring an individual option.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent 386030d commit 2028874
119 files changed
Lines changed: 6017 additions & 444 deletions
File tree
- sentry-android-core
- api
- src
- main/java/io/sentry/android/core
- test/java/io/sentry/android/core
- sentry-apollo-3
- api
- src
- main/java/io/sentry/apollo3
- test/java/io/sentry/apollo3
- sentry-apollo-4/src
- main/java/io/sentry/apollo4
- test/java/io/sentry/apollo4
- sentry-apollo/src
- main/java/io/sentry/apollo
- test/java/io/sentry/apollo
- sentry-graphql-core/src
- main/java/io/sentry/graphql
- test/kotlin/io/sentry/graphql
- sentry-ktor-client/src
- main/java/io/sentry/ktorClient
- test/java/io/sentry/ktorClient
- sentry-logback
- api
- src
- main/java/io/sentry/logback
- test/kotlin/io/sentry/logback
- sentry-okhttp/src
- main/java/io/sentry/okhttp
- test/java/io/sentry/okhttp
- sentry-openfeign/src/main/java/io/sentry/openfeign
- sentry-opentelemetry/sentry-opentelemetry-core/src/main/java/io/sentry/opentelemetry
- sentry-servlet-jakarta/src
- main/java/io/sentry/servlet/jakarta
- test/kotlin/io/sentry/servlet/jakarta
- sentry-servlet/src
- main/java/io/sentry/servlet
- test/kotlin/io/sentry/servlet
- sentry-spring-7/src
- main/java/io/sentry/spring7
- tracing
- webflux
- test/kotlin/io/sentry/spring7
- webflux
- sentry-spring-boot-4/src/test/kotlin/io/sentry/spring/boot4
- sentry-spring-boot-jakarta/src/test/kotlin/io/sentry/spring/boot/jakarta
- sentry-spring-boot/src/test/kotlin/io/sentry/spring/boot
- sentry-spring-jakarta/src
- main/java/io/sentry/spring/jakarta
- tracing
- webflux
- test/kotlin/io/sentry/spring/jakarta
- webflux
- sentry-spring/src
- main/java/io/sentry/spring
- tracing
- webflux
- test/kotlin/io/sentry/spring
- webflux
- sentry
- api
- src
- main/java/io/sentry
- instrumentation/file
- util
- test/java/io/sentry
- instrumentation/file
- util
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
8 | 122 | | |
9 | 123 | | |
10 | 124 | | |
| |||
52 | 166 | | |
53 | 167 | | |
54 | 168 | | |
| 169 | + | |
55 | 170 | | |
56 | 171 | | |
57 | 172 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
283 | 283 | | |
284 | 284 | | |
285 | 285 | | |
286 | | - | |
287 | 286 | | |
288 | 287 | | |
289 | 288 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
681 | 681 | | |
682 | 682 | | |
683 | 683 | | |
684 | | - | |
| 684 | + | |
685 | 685 | | |
686 | 686 | | |
687 | 687 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
178 | 178 | | |
179 | 179 | | |
180 | 180 | | |
181 | | - | |
| 181 | + | |
182 | 182 | | |
183 | 183 | | |
184 | 184 | | |
| |||
Lines changed: 1 addition & 22 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
19 | 18 | | |
20 | 19 | | |
21 | 20 | | |
22 | 21 | | |
23 | 22 | | |
24 | 23 | | |
25 | 24 | | |
26 | | - | |
27 | 25 | | |
28 | 26 | | |
29 | 27 | | |
| |||
34 | 32 | | |
35 | 33 | | |
36 | 34 | | |
37 | | - | |
38 | 35 | | |
39 | 36 | | |
40 | 37 | | |
41 | 38 | | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | 39 | | |
49 | 40 | | |
50 | 41 | | |
| |||
80 | 71 | | |
81 | 72 | | |
82 | 73 | | |
83 | | - | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
89 | | - | |
90 | | - | |
91 | | - | |
92 | | - | |
93 | | - | |
94 | | - | |
95 | | - | |
| 74 | + | |
96 | 75 | | |
97 | 76 | | |
98 | 77 | | |
| |||
0 commit comments