`wrapMcpServerWithSentry` defaults `recordInputs` / `recordOutputs` to `true` (via `dataCollection.genAI`) |
Mantenedores costumam responder em até 1 dia
@s1gr1d já está trabalhando nisso.
Desde 23/9/2026.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 55/100
- Tipo de issue
- Bug
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Stack de tecnologia
- typescript
- Domínio
- backend-api-design, security
Direção de pesquisa
Start in packages/core/src/integrations/mcp-server/transport.ts, especially resolveMcpOptions, and compare its capture defaults with dataCollection.genAI and the scrubbing posture in piiFiltering.ts. Clarify which explicit-option and genAI settings should enable capture, then verify that a bare MCP wrapper is metadata-only or emits the documented warning when both flags resolve true.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Static review of public source at commit b633c8153250. No traffic was sent to any Sentry environment.
MCP server instrumentation resolves capture flags like this:
packages/core/src/integrations/mcp-server/transport.ts:
function resolveMcpOptions(options: McpServerWrapperOptions): ResolvedMcpOptions {
// ...
const genAI = getClient()?.getDataCollectionOptions().genAI;
return {
recordInputs: options.recordInputs ?? genAI?.inputs ?? true,
recordOutputs: options.recordOutputs ?? genAI?.outputs ?? true,
};
}
dataCollection.genAI itself documents { inputs: true, outputs: true } as the default. So a bare Sentry.wrapMcpServerWithSentry(server) will put tool/prompt arguments and results on spans (tokens, file paths, user content, etc.) unless the operator remembers to pass { recordInputs: false, recordOutputs: false } or tighten dataCollection.genAI.
That is great for AI debugging; it is a surprising default for MCP servers that often proxy secrets and private data.
Suggested change:
- Default MCP wrapper capture to
false/ metadata-only unlessrecordInputs/recordOutputsordataCollection.genAIis explicitly enabled; or - Keep genAI defaults but make
wrapMcpServerWithSentry()document and prefer explicit{ recordInputs, recordOutputs }with a one-time startup log when both resolve totrue. - Mirror the scrubbing posture already used for network PII in
piiFiltering.ts.
Severity: low–medium / privacy & data-minimization defense-in-depth (parallel to the Python SDK EventScrubber recursive default discussion). Not claiming a Sentry platform vulnerability. No proof-of-concept.
Happy to send a focused PR if useful.
- Linguagem predominante
- TypeScript
- Estrelas
- 8.7k
- Forks
- 1.9k
- Merge médio
- 1d 15h
- PRs com merge (30d)
- 523
Preparar o ambiente
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de getsentry/sentry-javascript
-
Next.js: basePath is concatenated onto absolute router.push hrefs, corrupting navigation transaction namesTalvez já em andamento @Lms24 assumiu há 3 dias. AbertaBrowser Bug Next.js Traces
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
getsentry/sentry-javascript#24672 · 2 comentários · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
javascript
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
getsentry/sentry-javascript#24200 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
javascript Task
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
getsentry/sentry-javascript#24134 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Cloudflare Workers javascript Tests
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
getsentry/sentry-javascript#24051 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Bug Bun javascript
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 92/100
getsentry/sentry-javascript#24045 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
Todas as issues de getsentry/sentry-javascript
Issues semelhantes
-
bug
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
StabilityNexus/Fate-EVM-Frontend#153 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
code-yeongyu/oh-my-openagent#9039 ·
Mantenedores costumam responder em até 1 dia
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
Tencent/teamai-cli#862 ·
Mantenedores costumam responder em até 1 dia
-
bug good first issue hacktoberfest redis
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
libredb/libredb-studio#1164 ·
Mantenedores costumam responder em até 1 dia
-
flake
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
coder/xum#4920 · 2 comentários ·
Mantenedores costumam responder em até 1 dia