Repository navigation
fix: stop sending sensitive data to Sentry and Cloud Logging - #120
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BREAKING CHANGE: Sentry events no longer include frame local variables. Set
{PREFIX}SENTRY_INCLUDE_LOCAL_VARIABLES=true to restore them.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add SentrySettings.max_request_body_size (default "never") and pass it
to sentry_sdk.init. The FastAPI integration sends JSON request bodies
even when send_default_pii is false.
BREAKING CHANGE: Sentry events no longer include request bodies. Set
{PREFIX}SENTRY_MAX_REQUEST_BODY_SIZE to small, medium or always to restore them.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BREAKING CHANGE: set_sentry_user no longer sends email, name, nickname, given name, family name, picture, org name or updated_at to Sentry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codecov Report❌ Patch coverage is
|
At traces_sample_rate=0.1, a FastAPI request can also record a sampled
transaction. Then `(event,) = sentry_capture.events` got two payloads
and the Step 3 tests failed about 10% of the time. Read the error event
with items("event"), and look for the secret in every payload.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BREAKING CHANGE: the OTLP log sink drops records below {PREFIX}LOG_LEVEL and
records that the boot() log_filter rejects.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
logging_initialize sets the stdlib loggers httpx, httpx2 and urllib3 to WARNING. httpx logs each request URL at INFO, including the query string of signed URLs. The root logger is at level 0, so these lines got to all loguru sinks and to Sentry breadcrumbs. Tests restore the stdlib logger levels, the root level and the InterceptHandler after each logging_initialize call. BREAKING CHANGE: logging_initialize sets the httpx, httpx2 and urllib3 loggers to WARNING. INFO request lines no longer get to the log sinks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The httpx, httpx2 and stdlib integrations parse URLs with sanitize=False and write http.query and http.fragment into span data. The SDK makes the HTTP breadcrumb from this span data, so the query string of signed URLs got to Sentry in breadcrumbs and in transaction spans. sentry_initialize now passes a before_breadcrumb hook that removes http.query, http.fragment and the query of data["url"] from HTTP breadcrumbs, and a before_send_transaction hook that does the same for the data of each span. BREAKING CHANGE: Sentry HTTP breadcrumbs and transaction spans no longer carry the query string or the fragment of the request URL. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add SentrySettings.trace_propagation_targets with the default [] and pass
it to sentry_sdk.init. The SDK default [".*"] adds sentry-trace and
baggage to every outbound request inside a transaction, also to partner
systems. The baggage header carries the release, the environment and the
public key of the DSN.
BREAKING CHANGE: Sentry no longer adds sentry-trace and baggage headers to
outbound requests. Set {PREFIX}SENTRY_TRACE_PROPAGATION_TARGETS to a JSON list of
host regexes to opt in.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SentrySettings.enable_logs now defaults to False. On sentry-sdk 2.67.1,
the old default sent every INFO+ record from the stdlib logging module
and from loguru to Sentry Logs. sentry-sdk 2.68.0 and later ignore
enable_logs; capture_sentry_logs=True on LoggingIntegration or
LoguruIntegration replaces it.
BREAKING CHANGE: {PREFIX}SENTRY_ENABLE_LOGS defaults to false. Log records no
longer go to Sentry Logs unless a service opts in.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sentry-sdk 2.68.0 moved Sentry Logs from the global enable_logs option to capture_sentry_logs on LoggingIntegration and LoguruIntegration. With this lower bound, foundry-core supports one Sentry Logs mechanism only. The lock file moves from 2.67.1 to 2.70.0. Unit tests pass with --resolution lowest-direct (sentry-sdk 2.68.0), and the Sentry, log, OTel and boot integration tests pass on 2.68.0 and on 2.70.0. BREAKING CHANGE: foundry-core requires sentry-sdk 2.68.0 or later. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sentry-sdk 2.68.0 and later ignore the enable_logs option and write a
deprecation warning for it. foundry-core now requires 2.68.0, so the
setting has no effect. Remove SentrySettings.enable_logs and stop
passing it to sentry_sdk.init.
A service opts in to Sentry Logs with
LoggingIntegration(capture_sentry_logs=True) or
LoguruIntegration(capture_sentry_logs=True) in
boot(sentry_integrations=...). SentrySettings uses extra="ignore", so a
service that still sets {PREFIX}SENTRY_ENABLE_LOGS starts as before.
BREAKING CHANGE: SentrySettings has no enable_logs field, and
{PREFIX}SENTRY_ENABLE_LOGS has no effect. Pass
LoggingIntegration(capture_sentry_logs=True) or
LoguruIntegration(capture_sentry_logs=True) to send log records to
Sentry Logs.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
olivermeyer
marked this pull request as ready for review
September 25, 2026 08:42
arne-aignx
approved these changes
Sep 25, 2026
aig-hannes
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Why?
foundry-core sends credentials and personal data to Sentry and to Cloud Logging (VPTHP-126). The leaks are frame locals, request bodies, Auth0 profile claims, signed-URL query strings, DEBUG records of all libraries, and trace headers to partner hosts. Every Foundry service uses this setup, and pviz waits for this fix before it turns on Sentry (VPTHP-124).
How?
Each leak gets a safe default in
SentrySettings,logging_initializeorotel_initialize, and each fix commit has aBREAKING CHANGE:footer for the changelog. Two Sentry hooks remove query strings from HTTP breadcrumbs and transaction spans, and tests use a realsentry_sdk.initwith a capturing transport, not mocks. foundry-core now requires sentry-sdk 2.68.0, so the ignoredenable_logssetting goes, andcapture_sentry_logs=Trueon the logging integrations is the only opt-in to Sentry Logs.🤖 Generated with Claude Code