bug(sdk): isolate cached auth identity between SDK invocations
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 64/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
- Lĩnh vực
- authentication, backend-api-design, cli
Hướng nghiên cứu
Start at packages/cli/src/lib/sdk-invoke.ts and trace executeWithCapture and executeWithStream through packages/cli/src/lib/env.ts, db/auth.ts, and sentry-client.ts. Review token, identity, host, cleanup, and streaming state at invocation boundaries, then add regressions for sequential valid and malformed tokens, separate hosts or config directories, and cached versus uncached requests; done means each client uses its own credential and cache identity while concurrent behavior remains explicit.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Sequential SDK invocations can reuse a previous client's memoized token and cache identity, allowing one SDK instance to receive another instance's cached response.
Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de through the public createSentrySDK API, using only synthetic credentials and a mocked HTTP boundary. Three clients share a config directory and request the same endpoint:
const first = createSentrySDK({ token: "synthetic-token-A", cwd });
const second = createSentrySDK({ token: "synthetic-token-B", cwd });
const malformed = createSentrySDK({ token: "synthetic\nbad-token", cwd });
await first.api({ endpoint });
await second.api({ endpoint });
await malformed.api({ endpoint });
The mock returns an identity-specific body with Cache-Control: private, max-age=300 and Vary: Authorization. After the first cache write completes, all three calls return the first identity's body. There is exactly one HTTP request, authorized as the first client. The consumer's process.env remains unchanged. No concurrent calls are needed.
executeWithCapture and executeWithStream replace the environment for each invocation, but setEnv only replaces a reference. getAuthToken and getIdentityFingerprint retain their memoized values, which are then used by the response-cache lookup.
Expected: each invocation uses its own effective credential and cache identity. A selected malformed token must not reuse a previous client's identity. Review token, identity, and host-related state together at SDK invocation boundaries, including cleanup and streaming paths. Changing bearer formatting alone cannot fix stale identity selection.
Suggested regressions: sequential clients with distinct valid tokens, a malformed second token, per-client hosts/config directories, and cached versus uncached requests. Keep concurrent invocation behavior explicit rather than assuming cache resets alone make it safe.
Relevant files: packages/cli/src/lib/sdk-invoke.ts, packages/cli/src/lib/env.ts, packages/cli/src/lib/db/auth.ts, and packages/cli/src/lib/sentry-client.ts.
- Ngôn ngữ chính
- TypeScript
- Star
- 121
- Fork
- 14
- Merge trung bình
- 1 ngày 3 giờ
- Pull request đã merge (30 ngày)
- 86
Chuẩn bị môi trường
Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của getsentry/cli
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Evaluate Twinkleplop for terminal code highlightingCó thể đã có người làm @MathurAditya724 đã nhận 5 ngày trước. Đang mởjared
getsentry/cli#1633 · 1 bình luận · 2 reaction · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Evaluate Twinkleplop for local UI JSON highlightingCó thể đã có người làm @MathurAditya724 đã nhận 5 ngày trước. Đang mởjared
getsentry/cli#1632 · 1 bình luận · 2 reaction · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của getsentry/cli
Issue tương tự
-
needs:triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
ai-discovered
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
jessepollak/home#1627 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent-canvas bug llm priority:low ready-for-dev
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
OpenHands/OpenHands#17806 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
radius-project/ai-extensions#923 ·
Maintainer thường phản hồi trong vòng 1 ngày