Part of #5420. Phase 0 — hardening pre-work, no new public API.
Introduce the spec's canonical sensitive-terms denylist and a shared internal key-value filtering utility that all collection points will use.
- Canonical denylist (case-insensitive substring match):
auth, token, secret, password, passwd, pwd, key, jwt, bearer, sso, saml, csrf, xsrf, credentials, session, sid, identity.
- Additional cookie-name-only terms (see JS
SENSITIVE_COOKIE_NAME_SNIPPETS): sessid, remember, oidc, pkce, nonce, __secure-, __host-, etc.
- Filtering semantics per the spec: key names are always preserved; matching values are replaced with
[Filtered]; supports off / denyList (built-in list + extra terms) / allowList (listed keys keep real values, built-in denylist still applies).
- Seed from existing primitives:
PiiExtensions.RedactedText (src/Sentry/Internal/PiiExtensions.cs), RedactedHeaders (src/Sentry/Internal/RedactedHeaders.cs).
- Internal-only in this phase; exhaustive unit tests.
JS reference: packages/core/src/utils/data-collection/filterKeyValueData.ts and filtering-snippets.ts (getsentry/sentry-javascript#20989).
Part of #5420. Phase 0 — hardening pre-work, no new public API.
Introduce the spec's canonical sensitive-terms denylist and a shared internal key-value filtering utility that all collection points will use.
auth,token,secret,password,passwd,pwd,key,jwt,bearer,sso,saml,csrf,xsrf,credentials,session,sid,identity.SENSITIVE_COOKIE_NAME_SNIPPETS):sessid,remember,oidc,pkce,nonce,__secure-,__host-, etc.[Filtered]; supportsoff/denyList(built-in list + extra terms) /allowList(listed keys keep real values, built-in denylist still applies).PiiExtensions.RedactedText(src/Sentry/Internal/PiiExtensions.cs),RedactedHeaders(src/Sentry/Internal/RedactedHeaders.cs).JS reference:
packages/core/src/utils/data-collection/filterKeyValueData.tsandfiltering-snippets.ts(getsentry/sentry-javascript#20989).