Skip to content

fix: stop sending sensitive data to Sentry and Cloud Logging - #120

Merged
olivermeyer merged 12 commits into
mainfrom
fix/VPTHP-126-stop-sending-sensitive-data
Sep 28, 2026
Merged

olivermeyer merged 12 commits into
mainfrom
fix/VPTHP-126-stop-sending-sensitive-data

Conversation

@olivermeyer

@olivermeyer olivermeyer commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Why?
foundry-core sends credentials and personal data to Sentry and to Cloud Logging (VPTHP-126). The leaks are frame locals, request bodies, Auth0 profile claims, signed-URL query strings, DEBUG records of all libraries, and trace headers to partner hosts. Every Foundry service uses this setup, and pviz waits for this fix before it turns on Sentry (VPTHP-124).

How?
Each leak gets a safe default in SentrySettings, logging_initialize or otel_initialize, and each fix commit has a BREAKING CHANGE: footer for the changelog. Two Sentry hooks remove query strings from HTTP breadcrumbs and transaction spans, and tests use a real sentry_sdk.init with a capturing transport, not mocks. foundry-core now requires sentry-sdk 2.68.0, so the ignored enable_logs setting goes, and capture_sentry_logs=True on the logging integrations is the only opt-in to Sentry Logs.

🤖 Generated with Claude Code

olivermeyer and others added 4 commits September 25, 2026 09:33
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BREAKING CHANGE: Sentry events no longer include frame local variables. Set
{PREFIX}SENTRY_INCLUDE_LOCAL_VARIABLES=true to restore them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add SentrySettings.max_request_body_size (default "never") and pass it
to sentry_sdk.init. The FastAPI integration sends JSON request bodies
even when send_default_pii is false.

BREAKING CHANGE: Sentry events no longer include request bodies. Set
{PREFIX}SENTRY_MAX_REQUEST_BODY_SIZE to small, medium or always to restore them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BREAKING CHANGE: set_sentry_user no longer sends email, name, nickname, given
name, family name, picture, org name or updated_at to Sentry.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 90.00000% with 4 lines in your changes missing coverage. Please review.
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
src/aignostics_foundry_core/sentry.py 86.20% 1 Missing and 3 partials ⚠️
Files with missing lines Coverage Δ
src/aignostics_foundry_core/boot.py 82.71% <100.00%> (+3.70%) ⬆️
src/aignostics_foundry_core/log.py 93.47% <100.00%> (+0.29%) ⬆️
src/aignostics_foundry_core/otel.py 100.00% <100.00%> (ø)
src/aignostics_foundry_core/sentry.py 93.38% <86.20%> (-2.36%) ⬇️

olivermeyer and others added 8 commits September 25, 2026 09:48
At traces_sample_rate=0.1, a FastAPI request can also record a sampled
transaction. Then `(event,) = sentry_capture.events` got two payloads
and the Step 3 tests failed about 10% of the time. Read the error event
with items("event"), and look for the secret in every payload.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BREAKING CHANGE: the OTLP log sink drops records below {PREFIX}LOG_LEVEL and
records that the boot() log_filter rejects.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
logging_initialize sets the stdlib loggers httpx, httpx2 and urllib3 to
WARNING. httpx logs each request URL at INFO, including the query string
of signed URLs. The root logger is at level 0, so these lines got to all
loguru sinks and to Sentry breadcrumbs.

Tests restore the stdlib logger levels, the root level and the
InterceptHandler after each logging_initialize call.

BREAKING CHANGE: logging_initialize sets the httpx, httpx2 and urllib3 loggers
to WARNING. INFO request lines no longer get to the log sinks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The httpx, httpx2 and stdlib integrations parse URLs with sanitize=False
and write http.query and http.fragment into span data. The SDK makes the
HTTP breadcrumb from this span data, so the query string of signed URLs
got to Sentry in breadcrumbs and in transaction spans.

sentry_initialize now passes a before_breadcrumb hook that removes
http.query, http.fragment and the query of data["url"] from HTTP
breadcrumbs, and a before_send_transaction hook that does the same for
the data of each span.

BREAKING CHANGE: Sentry HTTP breadcrumbs and transaction spans no longer carry
the query string or the fragment of the request URL.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add SentrySettings.trace_propagation_targets with the default [] and pass
it to sentry_sdk.init. The SDK default [".*"] adds sentry-trace and
baggage to every outbound request inside a transaction, also to partner
systems. The baggage header carries the release, the environment and the
public key of the DSN.

BREAKING CHANGE: Sentry no longer adds sentry-trace and baggage headers to
outbound requests. Set {PREFIX}SENTRY_TRACE_PROPAGATION_TARGETS to a JSON list of
host regexes to opt in.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SentrySettings.enable_logs now defaults to False. On sentry-sdk 2.67.1,
the old default sent every INFO+ record from the stdlib logging module
and from loguru to Sentry Logs. sentry-sdk 2.68.0 and later ignore
enable_logs; capture_sentry_logs=True on LoggingIntegration or
LoguruIntegration replaces it.

BREAKING CHANGE: {PREFIX}SENTRY_ENABLE_LOGS defaults to false. Log records no
longer go to Sentry Logs unless a service opts in.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sentry-sdk 2.68.0 moved Sentry Logs from the global enable_logs option
to capture_sentry_logs on LoggingIntegration and LoguruIntegration.
With this lower bound, foundry-core supports one Sentry Logs mechanism
only. The lock file moves from 2.67.1 to 2.70.0.

Unit tests pass with --resolution lowest-direct (sentry-sdk 2.68.0),
and the Sentry, log, OTel and boot integration tests pass on 2.68.0 and
on 2.70.0.

BREAKING CHANGE: foundry-core requires sentry-sdk 2.68.0 or later.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sentry-sdk 2.68.0 and later ignore the enable_logs option and write a
deprecation warning for it. foundry-core now requires 2.68.0, so the
setting has no effect. Remove SentrySettings.enable_logs and stop
passing it to sentry_sdk.init.

A service opts in to Sentry Logs with
LoggingIntegration(capture_sentry_logs=True) or
LoguruIntegration(capture_sentry_logs=True) in
boot(sentry_integrations=...). SentrySettings uses extra="ignore", so a
service that still sets {PREFIX}SENTRY_ENABLE_LOGS starts as before.

BREAKING CHANGE: SentrySettings has no enable_logs field, and
{PREFIX}SENTRY_ENABLE_LOGS has no effect. Pass
LoggingIntegration(capture_sentry_logs=True) or
LoguruIntegration(capture_sentry_logs=True) to send log records to
Sentry Logs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@olivermeyer
olivermeyer marked this pull request as ready for review September 25, 2026 08:42
@olivermeyer
olivermeyer requested a review from a team as a code owner September 25, 2026 08:42
@olivermeyer
olivermeyer merged commit 0062879 into main Sep 28, 2026
14 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants