bug(sdk): isolate cached auth identity between SDK invocations
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 64/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Stack de tecnologia
- typescript
- Domínio
- authentication, backend-api-design, cli
Direção de pesquisa
Start at packages/cli/src/lib/sdk-invoke.ts and trace executeWithCapture and executeWithStream through packages/cli/src/lib/env.ts, db/auth.ts, and sentry-client.ts. Review token, identity, host, cleanup, and streaming state at invocation boundaries, then add regressions for sequential valid and malformed tokens, separate hosts or config directories, and cached versus uncached requests; done means each client uses its own credential and cache identity while concurrent behavior remains explicit.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Sequential SDK invocations can reuse a previous client's memoized token and cache identity, allowing one SDK instance to receive another instance's cached response.
Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de through the public createSentrySDK API, using only synthetic credentials and a mocked HTTP boundary. Three clients share a config directory and request the same endpoint:
const first = createSentrySDK({ token: "synthetic-token-A", cwd });
const second = createSentrySDK({ token: "synthetic-token-B", cwd });
const malformed = createSentrySDK({ token: "synthetic\nbad-token", cwd });
await first.api({ endpoint });
await second.api({ endpoint });
await malformed.api({ endpoint });
The mock returns an identity-specific body with Cache-Control: private, max-age=300 and Vary: Authorization. After the first cache write completes, all three calls return the first identity's body. There is exactly one HTTP request, authorized as the first client. The consumer's process.env remains unchanged. No concurrent calls are needed.
executeWithCapture and executeWithStream replace the environment for each invocation, but setEnv only replaces a reference. getAuthToken and getIdentityFingerprint retain their memoized values, which are then used by the response-cache lookup.
Expected: each invocation uses its own effective credential and cache identity. A selected malformed token must not reuse a previous client's identity. Review token, identity, and host-related state together at SDK invocation boundaries, including cleanup and streaming paths. Changing bearer formatting alone cannot fix stale identity selection.
Suggested regressions: sequential clients with distinct valid tokens, a malformed second token, per-client hosts/config directories, and cached versus uncached requests. Keep concurrent invocation behavior explicit rather than assuming cache resets alone make it safe.
Relevant files: packages/cli/src/lib/sdk-invoke.ts, packages/cli/src/lib/env.ts, packages/cli/src/lib/db/auth.ts, and packages/cli/src/lib/sentry-client.ts.
- Linguagem predominante
- TypeScript
- Estrelas
- 123
- Forks
- 14
- Merge médio
- 23h 39min
- PRs com merge (30d)
- 81
Preparar o ambiente
Este projeto não oferece contêiner de desenvolvimento, Dockerfile nem guia de contribuição, então a configuração fica por sua conta: comece pelo README e veja nosso guia da primeira contribuição para os passos gerais.
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de getsentry/cli
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 52/100
Mantenedores costumam responder em até 1 dia
-
Evaluate Twinkleplop for terminal code highlightingTalvez já em andamento @MathurAditya724 assumiu há 7 dias. Abertajared
getsentry/cli#1633 · 1 comentário · 2 reações · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
Evaluate Twinkleplop for local UI JSON highlightingTalvez já em andamento @MathurAditya724 assumiu há 7 dias. Abertajared
getsentry/cli#1632 · 1 comentário · 2 reações · 1 responsável ·
Mantenedores costumam responder em até 1 dia
Todas as issues de getsentry/cli
Issues semelhantes
-
area/core status/need-triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
google-gemini/gemini-cli#29602 ·
Mantenedores costumam responder em até 1 dia
-
area: backend enhancement priority: low
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
snapotter-hq/SnapOtter#1879 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 86/100
Tencent/BrowserSkill#390 ·
Mantenedores costumam responder em até 1 dia
-
good first issue status: needs triaging type: bug version: 2.0
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
medusajs/medusa#17094 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 86/100
Mantenedores costumam responder em até 1 dia