mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
fix(api): stop sending personal data to Sentry (#12912)
This commit is contained in:
@@ -0,0 +1 @@
|
|||||||
|
Sentry error events no longer include user identity, IP addresses, cookies, headers or request bodies, which could contain personal data or provider credentials
|
||||||
@@ -30,6 +30,21 @@ def test_initialize_sentry_uses_configured_dsn():
|
|||||||
assert mock_init.call_args.kwargs["before_send"] is sentry_settings.before_send
|
assert mock_init.call_args.kwargs["before_send"] is sentry_settings.before_send
|
||||||
|
|
||||||
|
|
||||||
|
def test_initialize_sentry_sends_no_personal_data():
|
||||||
|
with (
|
||||||
|
patch.object(
|
||||||
|
sentry_settings.env,
|
||||||
|
"str",
|
||||||
|
return_value="https://fake-public-key@sentry.example.invalid/1",
|
||||||
|
),
|
||||||
|
patch.object(sentry_settings.sentry_sdk, "init") as mock_init,
|
||||||
|
):
|
||||||
|
sentry_settings.initialize_sentry()
|
||||||
|
|
||||||
|
assert mock_init.call_args.kwargs["send_default_pii"] is False
|
||||||
|
assert mock_init.call_args.kwargs["max_request_body_size"] == "never"
|
||||||
|
|
||||||
|
|
||||||
def _make_log_record(msg, level=logging.ERROR, name="test", args=None):
|
def _make_log_record(msg, level=logging.ERROR, name="test", args=None):
|
||||||
"""Build a real LogRecord so getMessage() works like in production."""
|
"""Build a real LogRecord so getMessage() works like in production."""
|
||||||
record = logging.LogRecord(
|
record = logging.LogRecord(
|
||||||
|
|||||||
@@ -193,10 +193,10 @@ def initialize_sentry():
|
|||||||
|
|
||||||
sentry_sdk.init(
|
sentry_sdk.init(
|
||||||
dsn=sentry_dsn,
|
dsn=sentry_dsn,
|
||||||
# Add data like request headers and IP for users,
|
|
||||||
# see https://docs.sentry.io/platforms/python/data-management/data-collected/ for more info
|
|
||||||
before_send=before_send,
|
before_send=before_send,
|
||||||
send_default_pii=True,
|
# No user identity, IPs, cookies, headers or request bodies: bodies carry emails and provider details.
|
||||||
|
send_default_pii=False,
|
||||||
|
max_request_body_size="never",
|
||||||
traces_sample_rate=env.float("DJANGO_SENTRY_TRACES_SAMPLE_RATE", default=0.02),
|
traces_sample_rate=env.float("DJANGO_SENTRY_TRACES_SAMPLE_RATE", default=0.02),
|
||||||
_experiments={
|
_experiments={
|
||||||
# Set continuous_profiling_auto_start to True
|
# Set continuous_profiling_auto_start to True
|
||||||
|
|||||||
Reference in New Issue
Block a user