feat(http): [Data Collection 13] Apply cookie collection policy - #5811
Conversation
Filter automatically captured request and response cookies according to the Data Collection policy across Spring and HTTP client integrations. Preserve existing sendDefaultPii behavior when Data Collection is absent. Co-Authored-By: Claude <noreply@anthropic.com>
|
📲 Install BuildsAndroid
|
Performance metrics 🚀
|
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| adae5de | 372.16 ms | 476.20 ms | 104.04 ms |
App size
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| adae5de | 0 B | 0 B | 0 B |
Previous results on branch: feat/data-collection-cookies
Startup times
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 670b3d8 | 329.76 ms | 371.15 ms | 41.39 ms |
| df76abc | 308.28 ms | 356.24 ms | 47.96 ms |
| b0be236 | 316.30 ms | 372.60 ms | 56.30 ms |
App size
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 670b3d8 | 0 B | 0 B | 0 B |
| df76abc | 0 B | 0 B | 0 B |
| b0be236 | 0 B | 0 B | 0 B |
Replace malformed request cookie pairs and invalid Set-Cookie values with the filtered placeholder. Preserve valid empty values, padded values, and response cookie attributes. Co-Authored-By: Claude <noreply@anthropic.com>
Keep mocked OkHttp responses consistent with the non-null headers contract so failed-request capture can inspect response cookies. Co-Authored-By: Claude <noreply@anthropic.com>
Semver Impact of This PR🟡 Minor (new features) 📋 Changelog PreviewThis is how your changes will appear in the changelog. This PR will not appear in the changelog. 🤖 This preview updates automatically when you update the PR. |
Validate cookie names and values before applying Data Collection filters. Fail closed for malformed values that could embed additional sensitive cookie pairs while preserving valid quoted and padded values. Refs #5666 Co-Authored-By: Claude <noreply@anthropic.com>
Bring the latest data collection behavior into the cookie filtering branch and retain coverage for both cookie and request header filtering. Co-Authored-By: Claude <noreply@anthropic.com>
runningcode
left a comment
There was a problem hiding this comment.
added some comments!
Avoid adding nullable filter results to cookie header lists so downstream consumers only receive actual header values. Co-Authored-By: Claude <noreply@anthropic.com>
Keep empty and whitespace-only cookie segments unchanged instead of replacing them with a filtered marker. Co-Authored-By: Claude <noreply@anthropic.com>
Let unexpected implementation errors remain visible instead of swallowing fatal JVM errors during deterministic cookie parsing. Co-Authored-By: Claude <noreply@anthropic.com>
Move cookie parsing and filtering into a focused internal utility and update integrations to use it. Keep generic query and header filtering in HttpUtils. Co-Authored-By: Claude <noreply@anthropic.com>
Merge the latest main and landed Data Collection changes into the cookie policy branch. Co-Authored-By: Claude <noreply@anthropic.com>
Exercise response cookie filtering with a valid cookie and preserve its attributes in the expected output. Co-Authored-By: Claude <noreply@anthropic.com>
| final @Nullable Enumeration<String> headers, | ||
| final @Nullable String headerName, | ||
| final @Nullable List<String> additionalCookieNamesToFilter) { | ||
| if (headers == null) { |
There was a problem hiding this comment.
This is redundant since the next line does the same thing.
There was a problem hiding this comment.
Collections.list(null) would throw a NPE so this is needed.
| scopes.captureEvent(event, hint) | ||
| } | ||
|
|
||
| private fun getRequestCookies(scopes: IScopes, cookies: String?): String? = |
There was a problem hiding this comment.
All of the getRequestCookies and getResponseCookies are copy pasted. Can we move them in to the Cookies.java class to reduce the copy/paste?
runningcode
left a comment
There was a problem hiding this comment.
pre-emptively giving a ✅ let me know if you'd like another review.
Bring the latest base branch fixes into the cookie policy branch. Co-Authored-By: Claude <noreply@anthropic.com>
Move Data Collection and legacy cookie policy selection into CookieUtils. Remove duplicated wrappers from OkHttp, Ktor, and Apollo integrations. Co-Authored-By: Claude <noreply@anthropic.com>
PR Stack (Data Collection)
📜 Description
Apply the cookie Data Collection policy to automatically captured request and response cookies.
The policy is used by Spring MVC/WebFlux, OkHttp, Ktor, and Apollo 3/4 failed-request events. Explicit Data Collection supports off, deny-list, and allow-list behavior. Built-in sensitive cookie names and Spring integration-provided session cookie names are always filtered, including when allow-listed.
Set-Cookievalues are parsed separately so attributes such asPath,HttpOnly, andSameSiteare preserved.When Data Collection is absent, integrations preserve their existing
sendDefaultPiibehavior, including Spring's legacy security-cookie filtering and raw HTTP-client cookie values.💡 Motivation and Context
Cookie collection previously relied on
sendDefaultPiias an on/off gate, with filtering only in Spring integrations. This wires the existingdataCollection.cookiesoption across cookie capture paths and provides consistent explicit-mode filtering without changing the legacy bridge for applications that have not configured Data Collection.Refs #5666
💚 How did you test it?
./gradlew spotlessApply apiDump./gradlew :sentry:apiCheckgit diff --check📝 Checklist
sendDefaultPIIis enabled.🔮 Next steps
Complete the remaining Data Collection configuration, documentation, and migration work.
#skip-changelog