microsoft / microsoft/ApplicationInsights-JS
Security of InstrumentationKey in Client Side Code
Open
enhancement
- Dominant language
- TypeScript
- Stars
- 685
- Forks
- 261
- Avg merge
- 21h 33m
- Merged PRs (30d)
- 5
Description
Is there a more secure alternative to providing the InstrumentationKey directly in client-side code? I'd be concerned about a malicious user being able to easily add garbage telemetry data to my logs.
Contributor guide
Research direction
No file, test, or entry point is identified in the issue. Begin by locating the client-side InstrumentationKey handling in the SDK, then determine whether a secure alternative can prevent unauthorized garbage telemetry and document the supported outcome.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, javascript, typescript
- Domain
- frontend, observability, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100