getsentry / getsentry/sentry-javascript

HTTP Headers are not sent by default, unless `sendDefaultPii` is enabled.

Open
#20,706 4 comments 0 reactions 0 assignees View on GitHub
Docs
Dominant language
TypeScript
Stars
8.7k
Forks
1.8k
Avg merge
1d 17h
Merged PRs (30d)
515

Description

### SDK

JavaScript SDK

### Description

Sentry version:
```
"@sentry/browser": "10.51.0",
"@sentry/nextjs": "10.51.0",
```

The docs mention [here](https://docs.sentry.io/platforms/javascript/guides/nextjs/data-management/data-collected/#http-headers) that

> By default, the Sentry SDK sends HTTP response or request headers.

However, this is not true or needs clarifying since at least the NextJS SDK requires the SentryConfig to have `sendDefaultPii` to be true.

Response headers;
`sendDefaultPii` disabled;
Image

`sendDefaultPii` enabled;
Image

Request headers do seem to send headers but with some entries omitted, though this isn't mentioned on the docs.

### Suggested Solution

Depending what the expected behavior is here;

- If we do not expect to send headers by default, the docs should be updated here to mention that `sendDefaultPii` should be enabled for response headers and most request headers.
- If we do expect to send headers by default, there may be a bug in the Sentry JavaScript SDK.

Also, it would be useful to understand what exactly is and isn't included behind the `sendDefaultPii` field to make a decision if we should enable this or not. Perhaps also linking to the data-collected page from the interface/config API [here](https://docs.sentry.io/platforms/javascript/configuration/options/#sendDefaultPii).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.