Skip to content

ref: Add sanitizeSqlQueryWithSummary helper and DB bugbot rule - #24244

Merged
s1gr1d merged 3 commits into
developfrom
sig/db-bugbot-and-helper
Sep 9, 2026
Merged

ref: Add sanitizeSqlQueryWithSummary helper and DB bugbot rule#24244
s1gr1d merged 3 commits into
developfrom
sig/db-bugbot-and-helper

Conversation

@s1gr1d

@s1gr1d s1gr1d commented Sep 9, 2026

Copy link
Copy Markdown
Member

Follow-up for #24089

@s1gr1d
s1gr1d requested review from a team as code owners September 9, 2026 12:44
@s1gr1d
s1gr1d requested review from mydea and nicohrubec and removed request for a team September 9, 2026 12:44
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 28.81 kB +0.04% +11 B 🔺
@sentry/browser - with treeshaking flags 27.12 kB +0.04% +10 B 🔺
@sentry/browser - with treeshaking flags tracing without tracing 27.01 kB +0.03% +7 B 🔺
@sentry/browser (incl. Tracing) 49.27 kB +0.12% +57 B 🔺
@sentry/browser (incl. Tracing + Span Streaming) 49.28 kB +0.12% +57 B 🔺
@sentry/browser (incl. Tracing, Profiling) 52.21 kB +0.17% +84 B 🔺
@sentry/browser (incl. Tracing, Replay) 88.81 kB +0.05% +44 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 77.99 kB +0.05% +33 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas) 93.49 kB +0.06% +51 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback) 106.44 kB +0.07% +67 B 🔺
@sentry/browser (incl. Feedback) 46.3 kB +0.02% +5 B 🔺
@sentry/browser (incl. sendFeedback) 33.87 kB +0.02% +6 B 🔺
@sentry/browser (incl. FeedbackAsync) 38.99 kB +0.04% +13 B 🔺
@sentry/browser (incl. Metrics) 29.84 kB +0.08% +23 B 🔺
@sentry/browser (incl. Logs) 30.1 kB +0.06% +18 B 🔺
@sentry/browser (incl. Metrics & Logs) 30.78 kB +0.11% +31 B 🔺
@sentry/react 30.57 kB +0.05% +14 B 🔺
@sentry/react (incl. Tracing) 51.64 kB +0.16% +78 B 🔺
@sentry/vue 36.07 kB +0.05% +17 B 🔺
@sentry/vue (incl. Tracing) 51.56 kB +0.16% +82 B 🔺
@sentry/svelte 28.85 kB +0.06% +15 B 🔺
CDN Bundle 30.56 kB +0.05% +15 B 🔺
CDN Bundle (incl. Tracing) 49.81 kB +0.15% +73 B 🔺
CDN Bundle (incl. Logs, Metrics) 32.83 kB +0.03% +9 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) 51.77 kB +0.14% +71 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) 73.48 kB -0.01% -4 B 🔽
CDN Bundle (incl. Tracing, Replay) 87.35 kB +0.08% +63 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 89.26 kB +0.1% +82 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) 93.28 kB +0.07% +59 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 95.27 kB +0.07% +65 B 🔺
CDN Bundle - uncompressed 90.47 kB +0.01% +8 B 🔺
CDN Bundle (incl. Tracing) - uncompressed 148.36 kB +0.13% +189 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed 97.04 kB +0.01% +8 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 154.32 kB +0.13% +189 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 226.3 kB +0.01% +8 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed 267.95 kB +0.08% +189 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 273.9 kB +0.07% +189 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 281.65 kB +0.07% +189 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 287.59 kB +0.07% +189 B 🔺
@sentry/nextjs (client) 54.09 kB +0.16% +84 B 🔺
@sentry/sveltekit (client) 49.73 kB +0.15% +71 B 🔺
@sentry/core/server 36.99 kB - -
@sentry/core/browser 13.55 kB - -
@sentry/node 127.95 kB +0.13% +158 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection) 81.61 kB - -
@sentry/node - without tracing 88.73 kB +0.03% +22 B 🔺
@sentry/node - without channel injection 107.17 kB +0.13% +136 B 🔺
@sentry/aws-serverless 97.12 kB +0.03% +28 B 🔺
@sentry/cloudflare (withSentry) - minified 202.05 kB +0.04% +74 B 🔺
@sentry/cloudflare (withSentry) 502.91 kB +0.05% +232 B 🔺

View base workflow run

Comment thread .cursor/BUGBOT.md Outdated
- `consoleSandbox(() => { console.warn(...) })` for intentional user-facing warnings (e.g. init-time misconfiguration messages). The `consoleSandbox` wrapper prevents the SDK's own console instrumentation from intercepting the call. Bare `console.*` calls outside very early init paths (e.g. before the logger is available) should be flagged.
- Flag `url.full`, `url.query`, `http.target` or `request.query_string` being set from a URL that isn't filtered. Wrap the value in `filterCollectedUrl()` (or `filterCollectedUrlQuery()` for a bare query string), passing the `client` if one is in scope, so `dataCollection.urlQueryParams` applies. Values that can't contain a query (a bare pathname, a queue URL) are fine. The `sdk/no-unfiltered-url-attributes` lint rule catches direct attribute writes, so look for what it can't: URLs passed through a helper or variable first, deprecated aliases set next to a filtered attribute, and URLs on breadcrumbs or events instead of spans.
- Flag span names built from a raw URL. Names follow `METHOD scheme://host/path` and must never contain a query string, so they need `stripUrlQueryAndFragment()`, not `filterCollectedUrl()`.
- Flag a SQL statement reaching telemetry unsanitized: `db.query.text`, `db.query.summary`, DB span names and breadcrumbs carrying a statement all have to come from `sanitizeSqlQuery()` / `sanitizeSqlQueryWithSummary()` (`@sentry/server-utils`). Inline literals are user data, and OTel only allows collecting query text once they are replaced with `?` — deliberately not gated on `dataCollection.databaseQueryData`, which does not cover query text. Sanitize each statement before it is joined into a batch, pass the `'mysql'` dialect for mysql/mysql2/MariaDB (there `"…"` quotes a value, not an identifier), and prefer `sanitizeSqlQueryWithSummary()`, which omits both attributes for an empty statement instead of reporting `'Unknown SQL Query'`. The sinks that get missed are the breadcrumb next to an already-sanitized span and the span name used when span streaming is off. Redis command text is not SQL and has its own redaction path.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The sinks that get missed are the breadcrumb next to an already-sanitized span

sorry what does this mean? 😅 As-in: breadcrumbs contain unsanitized query text?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I used a write-for-agent skill but I agree this is too much "claudism" and not readable anymore for us 😅 I think this means that the breadcrumbs don't need the summary, just the query text. I'm gonna rewrite that

@s1gr1d
s1gr1d added this pull request to stack #24251 September 9, 2026 13:33
@s1gr1d
s1gr1d merged commit 824ebf3 into develop Sep 9, 2026
595 of 602 checks passed
@s1gr1d
s1gr1d deleted the sig/db-bugbot-and-helper branch September 9, 2026 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants