getsentry / getsentry/sentry-java

Generate low-cardinality SQL summaries for database spans

Đang mở
#5,981 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Feature Java Platform: Java Spans
Ngôn ngữ chính
Kotlin
Star
1.4k
Fork
478
Merge trung bình
2 ngày 22 giờ
Pull request đã merge (30 ngày)
69

Mô tả

## Problem

When `dataCollection.databaseQueryData` disables raw SQL collection, database spans lose their SQL description entirely. Keeping the raw statement is not safe because inline literals and other query values can contain sensitive data and create high-cardinality span descriptions.

We should provide useful, low-cardinality descriptions without retaining query values, for example:

- `SELECT users`
- `UPDATE orders`
- `INSERT products`

This is follow-up work from #5801 and supports #5666.

## Proposed solution

Add a SQL summarizer that extracts only a safe operation and target from a statement. Use the summary for JDBC and Android SQLite span descriptions when raw database query data is disabled. Preserve the full statement only when the effective Data Collection policy allows it.

Consider adapting OpenTelemetry Java's Apache-2.0 SQL query analyzer instead of depending on its incubating API. If code is adapted, include the required source attribution and update `THIRD_PARTY_NOTICES.md`.

The summarizer must fail closed: malformed or unsupported SQL must never fall back to the raw statement.

## Acceptance criteria

- JDBC and Android SQLite spans use low-cardinality summaries when raw query collection is disabled.
- Summaries do not contain inline literals, bound values, comments, or other query values.
- Parsing covers common operations such as `SELECT`, `INSERT`, `UPDATE`, and `DELETE`.
- Malformed and unsupported SQL produces a generic description or no description, never the raw statement.
- Tests cover inline literals, placeholders, mixed literal-and-bound queries, malformed SQL, and representative dialect-specific syntax.
- Any adapted third-party code includes complete license attribution.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start by locating the JDBC and Android SQLite span-description entry points and how the effective dataCollection.databaseQueryData policy is applied. Trace the existing tests, then add coverage for supported operations, literals, placeholders, malformed SQL, and dialect-specific syntax. Done means both integrations use safe summaries when raw collection is disabled, never expose raw SQL on failure, and any adapted analyzer code is attributed in THIRD_PARTY_NOTICES.md.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
android, java, kotlin, sqlite
Lĩnh vực
backend, databases, mobile
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
55/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.