Skip to content

feat(core)!: Gate incoming HTTP body capture on dataCollection.httpBodies - #22834

Open
s1gr1d wants to merge 1 commit into
developfrom
sig/http-body-collection
Open

feat(core)!: Gate incoming HTTP body capture on dataCollection.httpBodies#22834
s1gr1d wants to merge 1 commit into
developfrom
sig/http-body-collection

Conversation

@s1gr1d

@s1gr1d s1gr1d commented Jul 29, 2026

Copy link
Copy Markdown
Member

Gates incoming request body capture on dataCollection.httpBodies.includes('incomingRequest')
across all server SDKs. An explicit maxRequestBodySize option still overrides the gate.

closes #21258

@s1gr1d
s1gr1d requested review from a team as code owners July 29, 2026 14:51
@s1gr1d
s1gr1d requested review from isaacs and mydea and removed request for a team July 29, 2026 14:51
@github-actions

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 29.82 kB - -
@sentry/browser - with treeshaking flags 28.02 kB - -
@sentry/browser (incl. Tracing) 47.1 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 47.1 kB - -
@sentry/browser (incl. Tracing, Profiling) 51.81 kB - -
@sentry/browser (incl. Tracing, Replay) 86.4 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 75.84 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 91.12 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 103.77 kB - -
@sentry/browser (incl. Feedback) 47.13 kB - -
@sentry/browser (incl. sendFeedback) 34.66 kB - -
@sentry/browser (incl. FeedbackAsync) 39.76 kB - -
@sentry/browser (incl. Metrics) 30.89 kB - -
@sentry/browser (incl. Logs) 31.12 kB - -
@sentry/browser (incl. Metrics & Logs) 31.8 kB - -
@sentry/react 31.6 kB - -
@sentry/react (incl. Tracing) 49.33 kB - -
@sentry/vue 34.74 kB - -
@sentry/vue (incl. Tracing) 49.05 kB - -
@sentry/svelte 29.85 kB - -
CDN Bundle 31.87 kB - -
CDN Bundle (incl. Tracing) 47.45 kB - -
CDN Bundle (incl. Logs, Metrics) 33.42 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 48.83 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 72.78 kB - -
CDN Bundle (incl. Tracing, Replay) 85.09 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 86.39 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 90.86 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 92.17 kB - -
CDN Bundle - uncompressed 95.04 kB - -
CDN Bundle (incl. Tracing) - uncompressed 142.25 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 99.75 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 146.23 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 224.51 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 261.51 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 265.48 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 275.22 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 279.17 kB - -
@sentry/nextjs (client) 51.92 kB - -
@sentry/sveltekit (client) 47.51 kB - -
@sentry/core/server 79.63 kB +0.04% +27 B 🔺
@sentry/core/browser 51.6 kB - -
@sentry/node 121.32 kB +0.03% +25 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection) 166 B - -
@sentry/node - without tracing 84.8 kB +0.03% +25 B 🔺
@sentry/aws-serverless 93.05 kB +0.03% +26 B 🔺
@sentry/cloudflare (withSentry) - minified 197.62 kB +0.04% +77 B 🔺
@sentry/cloudflare (withSentry) 485.82 kB +0.03% +132 B 🔺

View base workflow run

@isaacs isaacs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implementation looks great!

The test failures are pretty straightforward to fix, it looks like there are some that got missed that assert the old behavior. This patch should fix it, if I'm understanding the intent correctly: https://gist.github.com/isaacs/9897e925123d1ce714b4f20d2a589077

I notice that the Deno.serve() integration at packages/deno/src/integrations/deno-serve.ts doesn't send httpBodies at all, even if it is enabled. I think that means it's technically satisfying the spec, but it might be a nice addition to make it send them as well when enabled. That would require refactoring core's captureBodyFromWinterCGRequest method. That can be a subsequent feature addition though, even post-v11, since it's not technically a bug or spec violation, just a pre-existing inconsistency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[v11] Gate incoming HTTP body capture on dataCollection.httpBodies

2 participants