getsentry / getsentry/sentry-javascript
Sensitive values bypass the denylist in header and cookie collection
オープン
javascript
- 主要言語
- TypeScript
- スター
- 8.7k
- フォーク
- 1.8k
- 平均マージ
- 1日 17時間
- マージ済み PR(30日)
- 523
説明
A cookie header that cannot be split into `name=value` pairs ends up verbatim in an attribute key, and headers listed in `headersToSpanAttributes` skip the denylist, so an `authorization` header is sent in the clear.
コントリビューションガイド
評価
この issue はまだ評価されていません。