Skip to content

DataCollection phase 0: sensitive-terms denylist and key-value filtering utility #5421

Description

@jamescrosswell

Part of #5420. Phase 0 — hardening pre-work, no new public API.

Introduce the spec's canonical sensitive-terms denylist and a shared internal key-value filtering utility that all collection points will use.

  • Canonical denylist (case-insensitive substring match): auth, token, secret, password, passwd, pwd, key, jwt, bearer, sso, saml, csrf, xsrf, credentials, session, sid, identity.
  • Additional cookie-name-only terms (see JS SENSITIVE_COOKIE_NAME_SNIPPETS): sessid, remember, oidc, pkce, nonce, __secure-, __host-, etc.
  • Filtering semantics per the spec: key names are always preserved; matching values are replaced with [Filtered]; supports off / denyList (built-in list + extra terms) / allowList (listed keys keep real values, built-in denylist still applies).
  • Seed from existing primitives: PiiExtensions.RedactedText (src/Sentry/Internal/PiiExtensions.cs), RedactedHeaders (src/Sentry/Internal/RedactedHeaders.cs).
  • Internal-only in this phase; exhaustive unit tests.

JS reference: packages/core/src/utils/data-collection/filterKeyValueData.ts and filtering-snippets.ts (getsentry/sentry-javascript#20989).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    FeatureNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions