bug(sdk): isolate cached auth identity between SDK invocations
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 64/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- typescript
调研方向
Start at packages/cli/src/lib/sdk-invoke.ts and trace executeWithCapture and executeWithStream through packages/cli/src/lib/env.ts, db/auth.ts, and sentry-client.ts. Review token, identity, host, cleanup, and streaming state at invocation boundaries, then add regressions for sequential valid and malformed tokens, separate hosts or config directories, and cached versus uncached requests; done means each client uses its own credential and cache identity while concurrent behavior remains explicit.
由索引模型根据 Issue 内容生成。
描述
Sequential SDK invocations can reuse a previous client's memoized token and cache identity, allowing one SDK instance to receive another instance's cached response.
Confirmed locally against e0fdee49a347255bbbb072dfc74baf53ae5998de through the public createSentrySDK API, using only synthetic credentials and a mocked HTTP boundary. Three clients share a config directory and request the same endpoint:
const first = createSentrySDK({ token: "synthetic-token-A", cwd });
const second = createSentrySDK({ token: "synthetic-token-B", cwd });
const malformed = createSentrySDK({ token: "synthetic\nbad-token", cwd });
await first.api({ endpoint });
await second.api({ endpoint });
await malformed.api({ endpoint });
The mock returns an identity-specific body with Cache-Control: private, max-age=300 and Vary: Authorization. After the first cache write completes, all three calls return the first identity's body. There is exactly one HTTP request, authorized as the first client. The consumer's process.env remains unchanged. No concurrent calls are needed.
executeWithCapture and executeWithStream replace the environment for each invocation, but setEnv only replaces a reference. getAuthToken and getIdentityFingerprint retain their memoized values, which are then used by the response-cache lookup.
Expected: each invocation uses its own effective credential and cache identity. A selected malformed token must not reuse a previous client's identity. Review token, identity, and host-related state together at SDK invocation boundaries, including cleanup and streaming paths. Changing bearer formatting alone cannot fix stale identity selection.
Suggested regressions: sequential clients with distinct valid tokens, a malformed second token, per-client hosts/config directories, and cached versus uncached requests. Keep concurrent invocation behavior explicit rather than assuming cache resets alone make it safe.
Relevant files: packages/cli/src/lib/sdk-invoke.ts, packages/cli/src/lib/env.ts, packages/cli/src/lib/db/auth.ts, and packages/cli/src/lib/sentry-client.ts.
- 主要语言
- TypeScript
- 星标
- 124
- 派生
- 14
- 平均合并
- 21 小时 48 分钟
- 30 天内合并 PR
- 64
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
getsentry/cli 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 68/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 72/100
维护者通常 1 天内回复
-
Evaluate Twinkleplop for terminal code highlighting可能已有人在做 @MathurAditya724 于 15 天前认领。 未关闭jared
getsentry/cli#1633 · 1 条评论 · 2 个 reaction · 已指派 1 人 ·
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 82/100
apache/rocketmq-dashboard#6103 ·
维护者通常 4 天内回复
-
难度 2/5 1-3 小时 新手友好度 66/100
cockpit-project/cockpit-machines#2835 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
cloudflare/kumo#866 ·
维护者通常 1 天内回复
-
area:connector bug
难度 1/5 1 小时以内 新手友好度 82/100
维护者通常 1 天内回复
-
autoInject recall silently drops memory injection on long / non-Latin prompts (HTTP 400 Query too long)可能已有人在做 @Epsilon006 今天认领。 未关闭integration:coding-agents
难度 2/5 1-3 小时 新手友好度 72/100
vectorize-io/hindsight#5476 · 1 条评论 ·
维护者通常 1 天内回复