getsentry / getsentry/sentry-java

Capture all repeated `Cookie` and `Set-Cookie` header values

Open
#5,982 1 comment 0 reactions 0 assignees View on GitHub
Feature Java Platform: Java
Dominant language
Kotlin
Stars
1.4k
Forks
478
Avg merge
2d 23h
Merged PRs (30d)
67

Description

## Problem

The OkHttp, Ktor, and Apollo integrations capture only one `Cookie` or `Set-Cookie` header value when creating request and response contexts. Their current header accessors select a **single value**, so additional cookie fields are omitted from Sentry telemetry.

This is valid HTTP behavior. In particular, HTTP/2 allows clients to split the `Cookie` field into **multiple header fields** for compression. Responses also commonly contain multiple `Set-Cookie` fields.

This is follow-up completeness work from #5811 and supports #5666.

**Check what other SDKs are doing before implementing.**

## Proposed solution

Make cookie extraction list-aware across OkHttp, Ktor, Apollo 3, and Apollo 4:

- Combine repeated request `Cookie` fields with `; ` before applying the effective cookie policy.
- Process each response `Set-Cookie` field independently because each field represents one cookie and its attributes.
- Do not comma-join or comma-split `Set-Cookie` values. A valid `Expires` attribute contains a comma.
- Add shared core helpers or integration-specific adapters that apply the effective cookie policy to every value.
- Preserve valid `Set-Cookie` attributes and fail closed for malformed input.

Preserve the existing absent-Data-Collection compatibility behavior for each integration.

## Acceptance criteria

- OkHttp, Ktor, Apollo 3, and Apollo 4 capture all repeated cookie header values supported by their header APIs.
- Multiple request `Cookie` fields are combined with `; ` and filtered as one cookie string.
- Multiple response `Set-Cookie` fields are filtered independently without comma splitting or joining.
- Built-in sensitive-cookie filtering and configured allow-list, deny-list, and off behavior apply to every cookie value.
- Malformed cookie values never bypass filtering.
- Integration tests cover at least two request `Cookie` fields and two response `Set-Cookie` fields where the underlying header API supports repeated values.

Contributor guide

Open the contributing guide

Research direction

Start by inspecting the existing cookie extraction and header-accessor paths in the OkHttp, Ktor, Apollo 3, and Apollo 4 integrations, then compare how other SDKs handle repeated headers. Trace the shared cookie policy and absent-Data-Collection behavior before running the integration tests. Done means repeated Cookie and Set-Cookie values are covered without unsafe comma handling, filtering remains effective, and malformed values fail closed.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, kotlin
Domain
api, security, testing
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.