From 214531caa2ecc07b3b8bd291a27ce20da1fd4036 Mon Sep 17 00:00:00 2001 From: Alexey Karimov Date: Tue, 29 Sep 2026 15:13:52 +0500 Subject: [PATCH 1/3] docs(android): use Bugsee.getDefaultNetworkSanitizer() in network filters MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 🤖 Generated with [Claude Code](https://claude.com/claude-code) Change-Id: I3733f9b5bd42d405f5b0a0da3a3fc7765886ed60 --- docs/sdk/android/network.mdx | 2 +- docs/sdk/android/privacy/network.mdx | 32 +++++++++++++++++++++++----- 2 files changed, 28 insertions(+), 6 deletions(-) diff --git a/docs/sdk/android/network.mdx b/docs/sdk/android/network.mdx index dacc713..9e2e35f 100644 --- a/docs/sdk/android/network.mdx +++ b/docs/sdk/android/network.mdx @@ -160,7 +160,7 @@ Notes on the filter shape: - Event types are `NetworkEvent` / `LogEvent` in `com.bugsee.library.contracts`. - Mutators (`setUrl`, `setMethod`, `setBody`, headers, etc.) and `getBodyAbsenceReason()` are available. - The filter applies uniformly to events coming from every network extension — OkHttp, Ktor 2, Ktor 3, and Cronet all feed the same pipeline. -- Installing a filter turns off the built-in redaction of credentials (`Authorization`, cookies, `password` and `token` fields); your filter must redact them, or call `NetworkDataSanitizer.sanitize(event)` to keep the built-in redaction. See [Privacy → Network traffic](/sdk/android/privacy/network#a-filter-replaces-the-built-in-redaction). +- Installing a filter turns off the built-in redaction of credentials (`Authorization`, cookies, `password` and `token` fields); your filter must redact them, or call `Bugsee.getDefaultNetworkSanitizer().sanitize(event)` to keep the built-in redaction (on SDK 7.0.3 through 7.2.0, the static `NetworkDataSanitizer.sanitize(event)`). See [Privacy → Network traffic](/sdk/android/privacy/network#a-filter-replaces-the-built-in-redaction). See also the [Logs page](/sdk/android/logs) for the matching `setLogEventFilter(...)` API. diff --git a/docs/sdk/android/privacy/network.mdx b/docs/sdk/android/privacy/network.mdx index 2723db7..6f6d687 100644 --- a/docs/sdk/android/privacy/network.mdx +++ b/docs/sdk/android/privacy/network.mdx @@ -117,16 +117,15 @@ only adds or renames a field records `Authorization` headers, cookies and unless you disabled `CaptureNetworkUseDefaultSanitizer`. ::: -To keep the built-in redaction and add your own, call -`NetworkDataSanitizer.sanitize(event)` (package -`com.bugsee.library.shared.security.privacy`) at the start of your filter: +To keep the built-in redaction and add your own, call the SDK's default +sanitizer, `Bugsee.getDefaultNetworkSanitizer()`, at the start of your filter: ```java Bugsee.setNetworkEventFilter((event, callback) -> { - NetworkDataSanitizer.sanitize(event); // built-in redaction + Bugsee.getDefaultNetworkSanitizer().sanitize(event); // built-in redaction // ...your own redaction... callback.run(event); }); @@ -137,7 +136,7 @@ Bugsee.setNetworkEventFilter((event, callback) -> { ```kotlin Bugsee.setNetworkEventFilter { event, callback -> - NetworkDataSanitizer.sanitize(event) // built-in redaction + Bugsee.getDefaultNetworkSanitizer().sanitize(event) // built-in redaction // ...your own redaction... callback.run(event) } @@ -146,6 +145,29 @@ Bugsee.setNetworkEventFilter { event, callback -> +`getDefaultNetworkSanitizer()` always returns the same stateless +`NetworkDataSanitizer` (package `com.bugsee.library.contracts.exchange`). It +works before `Bugsee.launch()`, so it is safe in a +[manifest-declared filter](#declaring-the-filter-in-the-manifest), and it is +cheap to call for every event. Besides `sanitize(event)`, which covers the URL, +headers, body and error messages, it has `sanitizeUrl(event)` and +`sanitizeErrorMessage(event)`, which redact only the URL or only the error +messages. + +:::note +`Bugsee.getDefaultNetworkSanitizer()` is new in the next SDK release after +7.2.0. On SDK 7.0.3 through 7.2.0, call the static +`NetworkDataSanitizer.sanitize(event)` (package +`com.bugsee.library.shared.security.privacy`) instead; earlier versions have no +public sanitizer. That class still works in later releases but is deprecated. + +If your code wildcard-imports both `com.bugsee.library.contracts.exchange.*` and +`com.bugsee.library.shared.security.privacy.*`, the new interface and the old +class share the name `NetworkDataSanitizer`, and the compiler reports it as +ambiguous after the upgrade. Import the one you mean by its full name, or switch +to `Bugsee.getDefaultNetworkSanitizer()`, which needs no import. +::: + Capture from OkHttp 3/4, Ktor 2/3, and Cronet is wired automatically by the Bugsee Gradle plugin through the matching [extension modules](/sdk/android/extensibility/bugsee-extensions) — no manual interceptor From ff552e24d6bb533780288acccf245b0d4665e395 Mon Sep 17 00:00:00 2001 From: Alexey Karimov Date: Tue, 29 Sep 2026 18:06:39 +0500 Subject: [PATCH 2/3] docs(android): getDefaultNetworkSanitizer() ships in SDK 7.3.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 🤖 Generated with [Claude Code](https://claude.com/claude-code) Change-Id: Ib87f46cf18396d08b544b8c281a8fbc751f43f55 --- docs/sdk/android/privacy/network.mdx | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/docs/sdk/android/privacy/network.mdx b/docs/sdk/android/privacy/network.mdx index 6f6d687..6c61b70 100644 --- a/docs/sdk/android/privacy/network.mdx +++ b/docs/sdk/android/privacy/network.mdx @@ -155,9 +155,8 @@ headers, body and error messages, it has `sanitizeUrl(event)` and messages. :::note -`Bugsee.getDefaultNetworkSanitizer()` is new in the next SDK release after -7.2.0. On SDK 7.0.3 through 7.2.0, call the static -`NetworkDataSanitizer.sanitize(event)` (package +`Bugsee.getDefaultNetworkSanitizer()` is new in SDK 7.3.0. On SDK 7.0.3 through 7.2.0, call the +static `NetworkDataSanitizer.sanitize(event)` (package `com.bugsee.library.shared.security.privacy`) instead; earlier versions have no public sanitizer. That class still works in later releases but is deprecated. From d546a32d95306a5c801700b3f7803d11cc4af24b Mon Sep 17 00:00:00 2001 From: Alexey Karimov Date: Tue, 29 Sep 2026 18:17:59 +0500 Subject: [PATCH 3/3] docs(android): keep only what changes for the customer in the sanitizer note MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 🤖 Generated with [Claude Code](https://claude.com/claude-code) Change-Id: I692184ef0ddc5620192e7ef5684089de3dac226b --- docs/sdk/android/privacy/network.mdx | 26 ++++++++++++-------------- 1 file changed, 12 insertions(+), 14 deletions(-) diff --git a/docs/sdk/android/privacy/network.mdx b/docs/sdk/android/privacy/network.mdx index 6c61b70..f275c04 100644 --- a/docs/sdk/android/privacy/network.mdx +++ b/docs/sdk/android/privacy/network.mdx @@ -145,26 +145,24 @@ Bugsee.setNetworkEventFilter { event, callback -> -`getDefaultNetworkSanitizer()` always returns the same stateless -`NetworkDataSanitizer` (package `com.bugsee.library.contracts.exchange`). It -works before `Bugsee.launch()`, so it is safe in a -[manifest-declared filter](#declaring-the-filter-in-the-manifest), and it is -cheap to call for every event. Besides `sanitize(event)`, which covers the URL, -headers, body and error messages, it has `sanitizeUrl(event)` and +`getDefaultNetworkSanitizer()` works before `Bugsee.launch()`, so you can use +it in a [manifest-declared filter](#declaring-the-filter-in-the-manifest), and +you can call it for every event. Besides `sanitize(event)`, which redacts the +URL, headers, body and error messages, it has `sanitizeUrl(event)` and `sanitizeErrorMessage(event)`, which redact only the URL or only the error messages. :::note -`Bugsee.getDefaultNetworkSanitizer()` is new in SDK 7.3.0. On SDK 7.0.3 through 7.2.0, call the -static `NetworkDataSanitizer.sanitize(event)` (package -`com.bugsee.library.shared.security.privacy`) instead; earlier versions have no -public sanitizer. That class still works in later releases but is deprecated. +`Bugsee.getDefaultNetworkSanitizer()` is new in SDK 7.3.0. On SDK 7.0.3 +through 7.2.0, call the static `NetworkDataSanitizer.sanitize(event)` (package +`com.bugsee.library.shared.security.privacy`) instead; that class is deprecated +from 7.3.0 but still works. Earlier versions have no public sanitizer. If your code wildcard-imports both `com.bugsee.library.contracts.exchange.*` and -`com.bugsee.library.shared.security.privacy.*`, the new interface and the old -class share the name `NetworkDataSanitizer`, and the compiler reports it as -ambiguous after the upgrade. Import the one you mean by its full name, or switch -to `Bugsee.getDefaultNetworkSanitizer()`, which needs no import. +`com.bugsee.library.shared.security.privacy.*`, the compiler reports +`NetworkDataSanitizer` as ambiguous after the upgrade. Import the one you mean by +its full name, or use `Bugsee.getDefaultNetworkSanitizer()`, which needs no +import. ::: Capture from OkHttp 3/4, Ktor 2/3, and Cronet is wired automatically by the