getsentry / getsentry/sentry-javascript

Sensitive values bypass the denylist in header and cookie collection

未关闭
#24,085 1 条评论 0 个 reaction 已指派 1 人 已被 @s1gr1d 认领 在 GitHub 查看
javascript
主要语言
TypeScript
星标
8.7k
派生
1.8k
平均合并
1 天 17 小时
30 天内合并 PR
523

描述

A cookie header that cannot be split into `name=value` pairs ends up verbatim in an attribute key, and headers listed in `headersToSpanAttributes` skip the denylist, so an `authorization` header is sent in the clear.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。