getsentry / getsentry/sentry-java

[SR] Network Details - Rationalize regexp matching

未關閉
#5,432 4 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Android Bug Platform: Java Replays
主要語言
Kotlin
星號
1.4k
分支
478
平均合併
3 天 4 小時
30 天內合併 PR
72

描述

### Description

https://docs.sentry.io/platforms/javascript/session-replay/configuration/#network-details
_UI screenshot (session replay -> "Network" -> select http request from list)_
Image

The SDK [currently lets](https://github.com/getsentry/sentry-java/blob/main/sentry/src/main/java/io/sentry/SentryReplayOptions.java#L434) clients specify EITHER a regexp OR a regular url as a `String` - and the SDK doesn't know whether the client meant to provide a regexp or an absolute url - it just does [String#matches](https://github.com/getsentry/sentry-java/blob/main/sentry/src/main/java/io/sentry/util/network/NetworkDetailCaptureUtils.java#L102)

So for example // _See [docs.sentry.io](https://docs.sentry.io/platforms/android/session-replay/configuration/#requirements)_
```kotlin
SentryAndroid.init(this) { options ->
options.sessionReplay.networkDetailAllowUrls = listOf("www.google.com")
}
```
Can match unintended URLs like
"wwwXgoogleXcom".

This behaviour differs from
JS SDK - in JS `RegExp` is a first-class type and the SDK can do 'typeof' or similar
iOS SDK - has a [swift protocol](https://github.com/getsentry/sentry-cocoa/blob/main/Sources/Swift/Protocol/SentryUrlMatchable.swift#L20) to enforce specifying whether the input is String or NSUrlExpression

### Impact
For sentry-java It does not seem a huge deal, b/c most developers will test the urls they provide.
**TODO**: are there severe edge-cases that result in details being captured for unexpected urls?

For sentry-react-native, the SDK will passthrough SentryReplayOptions to the underlying native impls on sentry-java|cocoa - it may introduce more of an issue as the behaviour will fork.

### Proposed Changes
Not 100% sure tbh. The concrete soln seems to follow the JS/iOS path of having a way to differentiate whether the String provided is a regexp or an actual url. But that seems like a big lift (API changes)

貢獻指南

開啟貢獻指南

研究方向

先查看連結的設定文件和 SentryReplayOptions.java。追蹤 networkDetailAllowUrls 如何在 NetworkDetailCaptureUtils.java 中進入比對流程,然後將文件中的 URL 範例與目前 String#matches 的行為進行比較。當已就區分 regexp 輸入和 URL 輸入的方法達成共識,並涵蓋對 sentry-react-native 和原生 SDK 的影響時,即視為完成。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java, kotlin
領域
mobile-dev, networking
Issue 類型
缺陷
難度
5/5
預估耗時
一週以上
活躍度
冷清
描述清晰度
需要釐清
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。