Default `EventScrubber` uses `recursive=False`, so nested denylist keys are not scrubbed |
還沒有人認領這個 Issue。
評估
研究方向
The issue is in sentry_sdk/scrubber.py where EventScrubber.init sets recursive=False by default. Review sentry_sdk/client.py to see how the scrubber is instantiated. Write a test that creates an event with a nested denylist key (like under 'extra') and verify it's not scrubbed with the default, then is scrubbed after setting recursive=True. Check if there are performance concerns with deep recursion and consider limiting to known containers.
由索引模型根據 Issue 內容生成。
描述
Static review of public source at commit 85e7ce66fcca. No traffic was sent to any Sentry environment.
EventScrubber only walks nested dict/list values when recursive=True, and that flag defaults to False:
sentry_sdk/scrubber.py:
class EventScrubber:
def __init__(
self,
denylist: "Optional[List[str]]" = None,
recursive: bool = False,
...
) -> None:
if isinstance(k, str) and k.lower() in self.denylist:
d[k] = AnnotatedValue.substituted_because_contains_sensitive_data()
elif self.recursive:
self.scrub_dict(v)
self.scrub_list(v)
The default client wires a scrubber without enabling recursion:
sentry_sdk/client.py:
rv["event_scrubber"] = EventScrubber(
send_default_pii=False
if rv["send_default_pii"] is None
else rv["send_default_pii"]
)
Top-level keys such as authorization are scrubbed; the same key nested under extra, request.data, or breadcrumb data is not. Integrators who assume “Sentry scrubs secrets by default” get shallow coverage only.
Suggested change:
- Default
recursive=TrueonEventScrubber, or passrecursive=Truefrom the client bootstrap. - If recursion cost is the concern, recurse only into known containers (
extra,request.data, breadcrumbdata, framevars) rather than the whole event. - Document the flag next to
send_default_piiin the scrubbing guide.
Severity: low–medium data-protection hardening (secret leakage via nested event fields). No proof-of-concept; no events were submitted.
Happy to send a focused PR + regression test with a nested denylist key if useful.
- 主要語言
- Python
- 星號
- 2.2k
- 分支
- 672
- 平均合併
- 22 小時 47 分鐘
- 30 天內合併 PR
- 224
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
getsentry/sentry-python 的其他 Issue
-
Python
難度 2/5 1-3 小時 新手友好度 65/100
getsentry/sentry-python#7569 · 1 則留言 ·
-
Python
難度 1/5 1 小時以內 新手友好度 85/100
getsentry/sentry-python#7568 · 2 則留言 ·
-
Python
難度 2/5 1-3 小時 新手友好度 65/100
getsentry/sentry-python#7567 · 1 則留言 ·
-
難度 2/5 1-3 小時 新手友好度 78/100
getsentry/sentry-python#7543 · 2 則留言 · 已指派 1 人 ·
-
Python
難度 2/5 1-3 小時 新手友好度 68/100
getsentry/sentry-python#6992 · 1 則留言 ·
查看 getsentry/sentry-python 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 75/100
anthropics/skills#1811 · 1 則留言 ·
-
難度 2/5 1-3 小時 新手友好度 75/100
speaches-ai/speaches#678 ·
-
bug
難度 2/5 1-3 小時 新手友好度 75/100
datalayer/mcp-compose#42 ·
-
難度 2/5 1-3 小時 新手友好度 75/100
conda-forge/spacy-feedstock#177 ·
-
難度 2/5 1-3 小時 新手友好度 70/100
UKGovernmentBEIS/inspect_evals#2523 ·