getsentry / getsentry/sentry-javascript
Sensitive values bypass the denylist in header and cookie collection
Đang mở
javascript
- Ngôn ngữ chính
- TypeScript
- Star
- 8.7k
- Fork
- 1.8k
- Merge trung bình
- 1 ngày 17 giờ
- Pull request đã merge (30 ngày)
- 523
Mô tả
A cookie header that cannot be split into `name=value` pairs ends up verbatim in an attribute key, and headers listed in `headersToSpanAttributes` skip the denylist, so an `authorization` header is sent in the clear.
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.