bug(sdk): isolate cached auth identity between SDK invocations
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 64/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- authentication, backend-api-design, cli
Línea de trabajo
Start at packages/cli/src/lib/sdk-invoke.ts and trace executeWithCapture and executeWithStream through packages/cli/src/lib/env.ts, db/auth.ts, and sentry-client.ts. Review token, identity, host, cleanup, and streaming state at invocation boundaries, then add regressions for sequential valid and malformed tokens, separate hosts or config directories, and cached versus uncached requests; done means each client uses its own credential and cache identity while concurrent behavior remains explicit.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Sequential SDK invocations can reuse a previous client's memoized token and cache identity, allowing one SDK instance to receive another instance's cached response.
Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de through the public createSentrySDK API, using only synthetic credentials and a mocked HTTP boundary. Three clients share a config directory and request the same endpoint:
const first = createSentrySDK({ token: "synthetic-token-A", cwd });
const second = createSentrySDK({ token: "synthetic-token-B", cwd });
const malformed = createSentrySDK({ token: "synthetic\nbad-token", cwd });
await first.api({ endpoint });
await second.api({ endpoint });
await malformed.api({ endpoint });
The mock returns an identity-specific body with Cache-Control: private, max-age=300 and Vary: Authorization. After the first cache write completes, all three calls return the first identity's body. There is exactly one HTTP request, authorized as the first client. The consumer's process.env remains unchanged. No concurrent calls are needed.
executeWithCapture and executeWithStream replace the environment for each invocation, but setEnv only replaces a reference. getAuthToken and getIdentityFingerprint retain their memoized values, which are then used by the response-cache lookup.
Expected: each invocation uses its own effective credential and cache identity. A selected malformed token must not reuse a previous client's identity. Review token, identity, and host-related state together at SDK invocation boundaries, including cleanup and streaming paths. Changing bearer formatting alone cannot fix stale identity selection.
Suggested regressions: sequential clients with distinct valid tokens, a malformed second token, per-client hosts/config directories, and cached versus uncached requests. Keep concurrent invocation behavior explicit rather than assuming cache resets alone make it safe.
Relevant files: packages/cli/src/lib/sdk-invoke.ts, packages/cli/src/lib/env.ts, packages/cli/src/lib/db/auth.ts, and packages/cli/src/lib/sentry-client.ts.
- Lenguaje dominante
- TypeScript
- Estrellas
- 121
- Forks
- 14
- Merge medio
- 1 d 3 h
- PR fusionados (30 d)
- 86
Preparar el entorno
Aún no hemos revisado los archivos de configuración de este proyecto. Empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de getsentry/cli
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 52/100
Los mantenedores suelen responder en 1 día
-
Evaluate Twinkleplop for terminal code highlightingPosiblemente ocupada @MathurAditya724 la tomó hace 6 días. Abiertojared
getsentry/cli#1633 · 1 comentario · 2 reacciones · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
Evaluate Twinkleplop for local UI JSON highlightingPosiblemente ocupada @MathurAditya724 la tomó hace 6 días. Abiertojared
getsentry/cli#1632 · 1 comentario · 2 reacciones · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
Todos los issues de getsentry/cli
Issues similares
-
bug via-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
pingdotgg/t3code#14452 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
solana-foundation/program-examples#747 · 1 comentario ·
Los mantenedores suelen responder en 9 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
remotion-dev/remotion#11847 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
openwatersio/slackwater#355 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
melgarafael/DeskcommCRM#1998 · 3 comentarios ·
Los mantenedores suelen responder en 1 día