Skip to content

Upgrade Sentry with ID-only attribution and limited data collection - #66

Merged
andreogle merged 1 commit into
mainfrom
andre/sentry-11-privacy
Oct 2, 2026
Merged

andreogle merged 1 commit into
mainfrom
andre/sentry-11-privacy

Conversation

@andreogle

Copy link
Copy Markdown
Owner

Upgrades @sentry/react and @sentry/node to 11.0.0 together, superseding #61 and #62. Sentry 11 broadens automatic data collection by default, so both SDKs now use explicit restrictive settings while keeping user ID attribution.

  • Attach only the signed-in user's ID in browser, SSR and Phoenix errors. Browser identity follows initial load, successful visits and history navigation, clears on logout, and survives partial reloads. SSR identity is passed per error to avoid sharing users between pooled requests.
  • Disable automatic user/IP, cookie, header, body, query-parameter, database payload, AI input/output, queue argument, GraphQL document/variable and stack-variable collection in both JavaScript SDKs. Tracing and replay remain unconfigured.
  • Restrict Phoenix user context to IDs and request context to method/URL, stripping query strings, fragments, URL credentials, headers, cookies, bodies and network metadata.
  • Document the collection policy and verify outgoing browser payloads omit email/query tokens while retaining the user ID and error. Error messages, stacks and breadcrumbs remain available for diagnosis.

Validation: mix precommit passed (224 Elixir checks and 4 frontend tests, including lint and TypeScript checks); mix assets.build passed; the built SSR bundle rendered the login form and captured separate ID-only errors for two users and an anonymous request using an in-memory transport.

Migration reference: Sentry 10 to 11 data collection changes.

@andreogle
andreogle merged commit 7f769d2 into main Oct 2, 2026
5 checks passed
@andreogle
andreogle deleted the andre/sentry-11-privacy branch October 2, 2026 00:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant