Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

bug(sdk): isolate cached auth identity between SDK invocations

オープン
#1,645 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
64/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript

調査の方向性

Start at packages/cli/src/lib/sdk-invoke.ts and trace executeWithCapture and executeWithStream through packages/cli/src/lib/env.ts, db/auth.ts, and sentry-client.ts. Review token, identity, host, cleanup, and streaming state at invocation boundaries, then add regressions for sequential valid and malformed tokens, separate hosts or config directories, and cached versus uncached requests; done means each client uses its own credential and cache identity while concurrent behavior remains explicit.

索引モデルが issue の本文から書いたものです。

説明

Sequential SDK invocations can reuse a previous client's memoized token and cache identity, allowing one SDK instance to receive another instance's cached response.

Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de through the public createSentrySDK API, using only synthetic credentials and a mocked HTTP boundary. Three clients share a config directory and request the same endpoint:

const first = createSentrySDK({ token: "synthetic-token-A", cwd });
const second = createSentrySDK({ token: "synthetic-token-B", cwd });
const malformed = createSentrySDK({ token: "synthetic\nbad-token", cwd });

await first.api({ endpoint });
await second.api({ endpoint });
await malformed.api({ endpoint });

The mock returns an identity-specific body with Cache-Control: private, max-age=300 and Vary: Authorization. After the first cache write completes, all three calls return the first identity's body. There is exactly one HTTP request, authorized as the first client. The consumer's process.env remains unchanged. No concurrent calls are needed.

executeWithCapture and executeWithStream replace the environment for each invocation, but setEnv only replaces a reference. getAuthToken and getIdentityFingerprint retain their memoized values, which are then used by the response-cache lookup.

Expected: each invocation uses its own effective credential and cache identity. A selected malformed token must not reuse a previous client's identity. Review token, identity, and host-related state together at SDK invocation boundaries, including cleanup and streaming paths. Changing bearer formatting alone cannot fix stale identity selection.

Suggested regressions: sequential clients with distinct valid tokens, a malformed second token, per-client hosts/config directories, and cached versus uncached requests. Keep concurrent invocation behavior explicit rather than assuming cache resets alone make it safe.

Relevant files: packages/cli/src/lib/sdk-invoke.ts, packages/cli/src/lib/env.ts, packages/cli/src/lib/db/auth.ts, and packages/cli/src/lib/sentry-client.ts.

主要言語
TypeScript
スター
123
フォーク
14
平均マージ
21時間 48分
マージ済み PR(30日)
64

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

getsentry/cli のほかの issue

getsentry/cli の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。