getsentry / getsentry/sentry-java

feat(database): Capture query data behind dataCollection

Aperta
#6,021 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
Feature Java Platform: Java Spans
Lingua principale
Kotlin
Stelle
1.4k
Fork
478
Merge medio
2g 23h
PR unite (30g)
67

Descrizione

## Problem

The Java SDK exposes `dataCollection.databaseQueryData`, but the current first-party database integrations do not collect any of the value-bearing data controlled by that option:

- JDBC records the original statement text through P6Spy's `StatementInformation.getSql()`, not bound parameter values.
- Android SQLite receives bind arguments but does not attach them to spans.
- Neither integration captures write payloads or returned result data.

As a result, `databaseQueryData` currently has no production consumer in these integrations.

Sanitized or parameterized `db.query.text`, `db.query.summary`, and structural database metadata are intentionally outside this option and should continue to be collected independently.

## Proposal

In the next major version, add source-time collection of supported database query data and guard it with `dataCollection.databaseQueryData`.

Start with the value-bearing data already available to first-party instrumentation:

- JDBC prepared/callable statement bind values, where P6Spy exposes them safely.
- Android SQLite bind arguments in the SupportSQLite and SQLiteDriver integrations.

Evaluate write-operation payloads and returned result data separately; only add them where useful, bounded, and supported by established Sentry span conventions.

## Requirements

- Apply the policy when first-party instrumentation writes the data, not later during serialization or export.
- Do not put bound values into span descriptions, span names, `db.query.text`, or `db.query.summary`.
- Use standardized structured span attributes for parameters where available, such as `db.query.parameter.`.
- `databaseQueryData=false` must prevent value-bearing query data from being attached.
- Query text must remain sanitized/parameterized independently of this option.
- Add size/count limits and fail-closed handling for unsupported or malformed values.
- Preserve explicitly supplied customer span data.
- Add tests for enabled/disabled behavior, positional and named parameters, null/binary/large values, batch operations, and Android bind arguments.
- Document which integrations and database data categories are supported.

## Related

- Data Collection specification: `databaseQueryData` controls bound query parameters, write-operation payloads, and returned result data.
- SQL sanitization and `db.query.summary` generation are separate concerns and should not be made conditional on this option.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start at the JDBC P6Spy StatementInformation.getSql() path and the Android SupportSQLite and SQLiteDriver integrations, tracing where databaseQueryData is available. Use the listed enabled/disabled, parameter-shape, size, batch, and Android bind-argument cases to define coverage; done means bounded source-time collection without changing sanitized query fields, plus documentation of supported categories.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
android, java, sqlite
Ambito
databases, mobile
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.