feat(browser): opt-in HTTP failure errors, CSP and browser reports - #1152
Conversation
- errors.captureHttpStatus lists the fetch/XHR response statuses that make a span an error, e.g. [[500, 599], 429]. Default none: a response status alone is not an error, a network failure always is. A matching span gets Error, error.type = the status (HTTP semconv) and error.message "METHOD url-without-query -> status", so issues group per endpoint with ids redacted by the fingerprint. Applied in the same export-time status policy as the XHR fix, so both instrumentations follow one rule. - Content Security Policy violations become maple.browser.csp_violation WARN log events (directive, blocked URI, disposition, source location), on by default; reporting.browserReports adds deprecation and intervention reports as maple.browser.report. Logs, not errors, so they never open an issue. Uses a buffered ReportingObserver, which also delivers reports from before the SDK loaded, and falls back to the securitypolicyviolation event. Each kind is sent once per page, up to 50. - Reports live in the deferred chunk. First-party eager budget 17 -> 17.5 kB for the status ranges in the exporter.
|
Warning Review limit reachedNext included review available in 58 minutes. View limit detailsLimit details: You’ve used all 4 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (14)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Maple reviewConfidence 5/5 · safe to merge Adds an opt-in
What was checked
Observability coverage: 2 of 2 changes observable
|
Maple reviewConfidence 5/5 · safe to merge Adds opt-in
What was checked
|
Maple reviewConfidence 4/5 · likely safe to merge Reviewed the two files changed since the last pass.
What was checked
Observability coverage: 2 of 2 changes observable
|
Part 6 of the browser SDK stack. Based on #1151.
What changes
errors.captureHttpStatus(default none)[[500, 599], 429].Error,error.type= the status (HTTP semconv) anderror.message=METHOD url-without-query -> status.error_events_mvfalls back toerror.type/error.messagefor spans with no exception event, so issues group per endpoint, with ids in the path redacted by the message signature.CSP and browser reports (
reporting.cspdefault true,reporting.browserReportsdefault false)maple.browser.csp_violationWARN log events (effective directive, blocked URI, disposition,url.full, and the source location ascode.file.path/code.line.number/code.column.number).maple.browser.reportevents.ReportingObserveralso delivers reports from before the SDK loaded; thesecuritypolicyviolationevent is the fallback where the observer is missing. Report bodies are parsed into a named shape at the boundary.Reports live in the deferred chunk. First-party eager budget 17 → 17.5 kB for the status ranges in the exporter.
Testing
ReportingObserver(meta CSP + blocked image), the DOM-event fallback, once-per-kind dedupe, and turning it off.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.