Skip to content

fix(core): Filter more cookie names for PII#20485

Merged
mydea merged 2 commits intodevelopfrom
fn/cookie-name-filters
Apr 24, 2026
Merged

fix(core): Filter more cookie names for PII#20485
mydea merged 2 commits intodevelopfrom
fn/cookie-name-filters

Conversation

@mydea
Copy link
Copy Markdown
Member

@mydea mydea commented Apr 24, 2026

Raised by claude security review, this PR extends the list of cookie names we filter for PII reasons, covering more ground. This is always best effort so no guarantees, but this should extend the list of things we cover significantly.

@mydea mydea requested review from isaacs, logaretm and nicohrubec April 24, 2026 08:34
@mydea mydea self-assigned this Apr 24, 2026
Comment thread packages/core/src/utils/request.ts Outdated
Comment thread packages/core/src/utils/request.ts Outdated
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 24, 2026

size-limit report 📦

⚠️ Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

Path Size % Change Change
@sentry/browser 25.98 kB - -
@sentry/browser - with treeshaking flags 24.46 kB - -
@sentry/browser (incl. Tracing) 43.91 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 45.54 kB - -
@sentry/browser (incl. Tracing, Profiling) 48.87 kB - -
@sentry/browser (incl. Tracing, Replay) 83.11 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 72.59 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 87.79 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 100.05 kB - -
@sentry/browser (incl. Feedback) 42.78 kB - -
@sentry/browser (incl. sendFeedback) 30.65 kB - -
@sentry/browser (incl. FeedbackAsync) 35.64 kB - -
@sentry/browser (incl. Metrics) 27.27 kB - -
@sentry/browser (incl. Logs) 27.4 kB - -
@sentry/browser (incl. Metrics & Logs) 28.09 kB - -
@sentry/react 27.73 kB - -
@sentry/react (incl. Tracing) 46.14 kB - -
@sentry/vue 30.83 kB - -
@sentry/vue (incl. Tracing) 45.72 kB - -
@sentry/svelte 26 kB - -
CDN Bundle 28.66 kB - -
CDN Bundle (incl. Tracing) 46.13 kB - -
CDN Bundle (incl. Logs, Metrics) 30.04 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 47.17 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 69.02 kB - -
CDN Bundle (incl. Tracing, Replay) 83.19 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 84.22 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 88.68 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 89.76 kB - -
CDN Bundle - uncompressed 83.94 kB - -
CDN Bundle (incl. Tracing) - uncompressed 137.84 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 88.08 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 141.26 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 211.66 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 255.29 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 258.68 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 268.2 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 271.59 kB - -
@sentry/nextjs (client) 48.66 kB - -
@sentry/sveltekit (client) 44.34 kB - -
@sentry/node-core 58.52 kB +0.28% +160 B 🔺
@sentry/node 175.84 kB +0.1% +167 B 🔺
@sentry/node - without tracing 98.32 kB +0.02% +12 B 🔺
@sentry/aws-serverless 115.52 kB +0.16% +177 B 🔺

View base workflow run

@mydea mydea merged commit dbf1af1 into develop Apr 24, 2026
495 of 497 checks passed
@mydea mydea deleted the fn/cookie-name-filters branch April 24, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants