Repository navigation
fix: restore sanitized Sentry browser error delivery - #1611
jaywedgeworth22 wants to merge 11 commits into
Conversation
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
|
Consumer entry-point mismatch in Vitest arises because tests import the added or modified Sentry utilities directly from internal modules while Kody rule violation: Every exported schema or utility ships with tests and must typecheck |
|
Prose-spacing violation: the agent-written doc comment separates its two sentences with one literal ASCII space instead of the two required by the repository-wide prose spacing rule. Kody rule violation: Use two spaces between sentences in every human-facing string and agent-written paragraph |
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
|
Runtime type-validation gap at the SDK boundary: casting an arbitrary string to Kody rule violation: Keep type safety and test coverage for source changes |
|
Credential exposure occurs because the test commits a Sentry DSN containing a key-like username, project ID, and intake endpoint that the rule cannot exempt as synthetic. Inject a non-production DSN through Kody rule violation: Never hardcode secrets or tokens in web or Swift sources |
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
🤔 Insufficient Task ContextI found a task linked to this PR, but it only contains minimal information (title only, no description or acceptance criteria). To perform a meaningful business rules validation, I need more details. 🔍 What I need to validate:
💡 How to improve the task context:
|
Diagnosis
The 14-day Sentry audit found 32 error-category client discards, all network_error, and no accepted errors; spans/logs/check-ins were active. Production CSP omitted Sentry. This confirms a browser transport block consistent with the failures, but does not prove every discard had the same cause.
Changes
Diagnostic tradeoff
Strict privacy intentionally removes free-form exception messages and most stack filename/function labels. This reduces source-map resolution and grouping/detail for errors whose locations are not approved generated chunk identifiers. Error class, stack row order, line/column, trace/release metadata and approved operational counters remain. This is a tested bounded telemetry policy, not a claim of universal PII detection or historical exposure clearance.
Verification at 519c29c
Coordination / task notes
SDK/CSP/privacy scope is separate from reporter PRs #1610/#1612. This PR remains draft while separate rollout/reporter gates are held. Owner approved narrow Sentry CSP rollout, independent-review/CI substitution while Codex bot quota is exhausted, and evidence-based Kody responses. Owner also approved code/tests-only publication with these task notes: prepared AGENTS.md/effort-log edits are excluded because their upload is blocked. No private history or new credentials are included. Board reservation remains in progress until rollout is verified.
Current candidate df84a46
Integrated the separately merged sharp security patch. This candidate passes 110 scoped tests, typecheck and local build plus independent actual-SDK review. The final guard permits only error/transaction/span/log/metric/check-in/client-report envelopes; feedback, session summaries and unknown payload types are intentionally excluded. Check-in and client-report fields are projected; all 13 installed SDK discard reasons remain usable. Errors receive priority within the bounded aggregate budget and item failures preserve sanitized siblings. Private http.route values cannot bypass the route allowlist.
Current-head hosted CI/review is running; earlier-head verification above is historical. The de1 hostname suggestion remains explicitly unresolved pending authoritative supported-host evidence; network validation has not been broadened. No live privacy rollout or synthetic production error has occurred.
Feedback UI correction: Sentry feedback registration is disabled. Report a Problem uses the existing user-initiated mailto fallback with unchanged recipient/subject; the actual Nav handler is tested. No automatic email is sent. Check-in projection now reuses the scheduler's existing pure configuration helper to prevent cadence drift. These changes passed focused independent review and local build/typecheck; exact-head hosted CI/review must finish before landing.
Final batched collector alignment (2712522)
Profiling sample rate is zero and the installed BrowserSession integration is disabled, matching the explicit envelope policy. Profiling and crash-free session metrics are unavailable; normal approved errors and performance telemetry remain. Other default integrations are preserved. Synthetic report-button fixtures replace production origins, and missing CSP has an explicit test failure. Local scoped tests, typecheck/lint/build and narrow independent review passed; current-head hosted checks remain the final validation. No review configuration or sampling increase is introduced.