getsentry / getsentry/sentry-java

[SR] Network Details - Rationalize regexp matching

Đang mở
#5,432 4 bình luận 0 reaction 0 người được giao Xem trên GitHub
Android Bug Platform: Java Replays
Ngôn ngữ chính
Kotlin
Star
1.4k
Fork
478
Merge trung bình
2 ngày 23 giờ
Pull request đã merge (30 ngày)
67

Mô tả

### Description

https://docs.sentry.io/platforms/javascript/session-replay/configuration/#network-details
_UI screenshot (session replay -> "Network" -> select http request from list)_
Image

The SDK [currently lets](https://github.com/getsentry/sentry-java/blob/main/sentry/src/main/java/io/sentry/SentryReplayOptions.java#L434) clients specify EITHER a regexp OR a regular url as a `String` - and the SDK doesn't know whether the client meant to provide a regexp or an absolute url - it just does [String#matches](https://github.com/getsentry/sentry-java/blob/main/sentry/src/main/java/io/sentry/util/network/NetworkDetailCaptureUtils.java#L102)

So for example // _See [docs.sentry.io](https://docs.sentry.io/platforms/android/session-replay/configuration/#requirements)_
```kotlin
SentryAndroid.init(this) { options ->
options.sessionReplay.networkDetailAllowUrls = listOf("www.google.com")
}
```
Can match unintended URLs like
"wwwXgoogleXcom".

This behaviour differs from
JS SDK - in JS `RegExp` is a first-class type and the SDK can do 'typeof' or similar
iOS SDK - has a [swift protocol](https://github.com/getsentry/sentry-cocoa/blob/main/Sources/Swift/Protocol/SentryUrlMatchable.swift#L20) to enforce specifying whether the input is String or NSUrlExpression

### Impact
For sentry-java It does not seem a huge deal, b/c most developers will test the urls they provide.
**TODO**: are there severe edge-cases that result in details being captured for unexpected urls?

For sentry-react-native, the SDK will passthrough SentryReplayOptions to the underlying native impls on sentry-java|cocoa - it may introduce more of an issue as the behaviour will fork.

### Proposed Changes
Not 100% sure tbh. The concrete soln seems to follow the JS/iOS path of having a way to differentiate whether the String provided is a regexp or an actual url. But that seems like a big lift (API changes)

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.