Default `EventScrubber` uses `recursive=False`, so nested denylist keys are not scrubbed |
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 65/100
Direzione di ricerca
The issue is in sentry_sdk/scrubber.py where EventScrubber.init sets recursive=False by default. Review sentry_sdk/client.py to see how the scrubber is instantiated. Write a test that creates an event with a nested denylist key (like under 'extra') and verify it's not scrubbed with the default, then is scrubbed after setting recursive=True. Check if there are performance concerns with deep recursion and consider limiting to known containers.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Static review of public source at commit 85e7ce66fcca. No traffic was sent to any Sentry environment.
EventScrubber only walks nested dict/list values when recursive=True, and that flag defaults to False:
sentry_sdk/scrubber.py:
class EventScrubber:
def __init__(
self,
denylist: "Optional[List[str]]" = None,
recursive: bool = False,
...
) -> None:
if isinstance(k, str) and k.lower() in self.denylist:
d[k] = AnnotatedValue.substituted_because_contains_sensitive_data()
elif self.recursive:
self.scrub_dict(v)
self.scrub_list(v)
The default client wires a scrubber without enabling recursion:
sentry_sdk/client.py:
rv["event_scrubber"] = EventScrubber(
send_default_pii=False
if rv["send_default_pii"] is None
else rv["send_default_pii"]
)
Top-level keys such as authorization are scrubbed; the same key nested under extra, request.data, or breadcrumb data is not. Integrators who assume “Sentry scrubs secrets by default” get shallow coverage only.
Suggested change:
- Default
recursive=TrueonEventScrubber, or passrecursive=Truefrom the client bootstrap. - If recursion cost is the concern, recurse only into known containers (
extra,request.data, breadcrumbdata, framevars) rather than the whole event. - Document the flag next to
send_default_piiin the scrubbing guide.
Severity: low–medium data-protection hardening (secret leakage via nested event fields). No proof-of-concept; no events were submitted.
Happy to send a focused PR + regression test with a nested denylist key if useful.
- Lingua principale
- Python
- Stelle
- 2.2k
- Fork
- 672
- Merge medio
- 22h 47m
- PR unite (30g)
- 224
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di getsentry/sentry-python
-
Python
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
getsentry/sentry-python#7569 · 1 commento ·
-
Python
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
getsentry/sentry-python#7568 · 2 commenti ·
-
Python
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
getsentry/sentry-python#7567 · 1 commento ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
getsentry/sentry-python#7543 · 2 commenti · 1 assegnatario ·
-
Python
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
getsentry/sentry-python#6992 · 1 commento ·
Tutte le issue di getsentry/sentry-python
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
anthropics/skills#1811 · 1 commento ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
speaches-ai/speaches#678 ·
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
datalayer/mcp-compose#42 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
conda-forge/spacy-feedstock#177 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
UKGovernmentBEIS/inspect_evals#2523 ·