getsentry / getsentry/sentry-javascript

Sensitive values bypass the denylist in header and cookie collection

オープン
#24,085 コメント 1 件 リアクション 0 件 担当者 1 名 @s1gr1d が担当を希望しています GitHub で見る
javascript
主要言語
TypeScript
スター
8.7k
フォーク
1.8k
平均マージ
1日 17時間
マージ済み PR(30日)
523

説明

A cookie header that cannot be split into `name=value` pairs ends up verbatim in an attribute key, and headers listed in `headersToSpanAttributes` skip the denylist, so an `authorization` header is sent in the clear.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。