getsentry / getsentry/sentry-java
feat(database): Capture query data behind dataCollection
- Lingua principale
- Kotlin
- Stelle
- 1.4k
- Fork
- 478
- Merge medio
- 2g 23h
- PR unite (30g)
- 67
Descrizione
## Problem
The Java SDK exposes `dataCollection.databaseQueryData`, but the current first-party database integrations do not collect any of the value-bearing data controlled by that option:
- JDBC records the original statement text through P6Spy's `StatementInformation.getSql()`, not bound parameter values.
- Android SQLite receives bind arguments but does not attach them to spans.
- Neither integration captures write payloads or returned result data.
As a result, `databaseQueryData` currently has no production consumer in these integrations.
Sanitized or parameterized `db.query.text`, `db.query.summary`, and structural database metadata are intentionally outside this option and should continue to be collected independently.
## Proposal
In the next major version, add source-time collection of supported database query data and guard it with `dataCollection.databaseQueryData`.
Start with the value-bearing data already available to first-party instrumentation:
- JDBC prepared/callable statement bind values, where P6Spy exposes them safely.
- Android SQLite bind arguments in the SupportSQLite and SQLiteDriver integrations.
Evaluate write-operation payloads and returned result data separately; only add them where useful, bounded, and supported by established Sentry span conventions.
## Requirements
- Apply the policy when first-party instrumentation writes the data, not later during serialization or export.
- Do not put bound values into span descriptions, span names, `db.query.text`, or `db.query.summary`.
- Use standardized structured span attributes for parameters where available, such as `db.query.parameter.`.
- `databaseQueryData=false` must prevent value-bearing query data from being attached.
- Query text must remain sanitized/parameterized independently of this option.
- Add size/count limits and fail-closed handling for unsupported or malformed values.
- Preserve explicitly supplied customer span data.
- Add tests for enabled/disabled behavior, positional and named parameters, null/binary/large values, batch operations, and Android bind arguments.
- Document which integrations and database data categories are supported.
## Related
- Data Collection specification: `databaseQueryData` controls bound query parameters, write-operation payloads, and returned result data.
- SQL sanitization and `db.query.summary` generation are separate concerns and should not be made conditional on this option.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start at the JDBC P6Spy StatementInformation.getSql() path and the Android SupportSQLite and SQLiteDriver integrations, tracing where databaseQueryData is available. Use the listed enabled/disabled, parameter-shape, size, batch, and Android bind-argument cases to define coverage; done means bounded source-time collection without changing sanitized query fields, plus documentation of supported categories.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- android, java, sqlite
- Ambito
- databases, mobile
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Attiva
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100