You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 566e06a
Browse filesBrowse the repository at this point in the historyBrowse files
fix(core): Apply the sensitive denylist to cookie headers and configured fetch headers (#24090)
Three ways a sensitive value slipped past the denylist, now that cookies
ship as one array attribute (#24231).
A cookie segment without an `=` is a nameless cookie, so the bare token
is its value (RFC 6265bis). The SDK treated it as a name, and no
name-based denylist can match a value, so `Cookie: <session-token>`
shipped the token in the clear. Such segments now become a `[Filtered]`
array element. The `Cookie` header was also split on `"; "`, but the
space is not guaranteed on the wire, so a cookie glued on with a bare
`;` leaked inside the previous cookie's value. The split is now on
`";"`.
Headers listed in `headersToSpanAttributes` skipped the denylist
entirely, so `authorization` went out in the clear. The spec says an
allowlist never exempts a sensitive name, so those now emit
`['[Filtered]']`.
Fixes#24085
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: dev-packages/node-integration-tests/suites/tracing/http-client-spans/fetch-headers-to-span-attributes/instrument.mjs
Copy file name to clipboardExpand all lines: dev-packages/node-integration-tests/suites/tracing/http-client-spans/fetch-headers-to-span-attributes/scenario.mjs
+3-1Lines changed: 3 additions & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -2,5 +2,7 @@ import * as Sentry from '@sentry/node';
Copy file name to clipboardExpand all lines: dev-packages/node-integration-tests/suites/tracing/http-client-spans/fetch-headers-to-span-attributes/test.ts
0 commit comments