Skip to content

feat(browser): opt-in HTTP failure errors, CSP and browser reports - #1152

Merged
Makisuo merged 3 commits into
feat/browser-sdk-breadcrumbsfrom
feat/browser-sdk-http-errors-csp
Sep 29, 2026
Merged

Makisuo merged 3 commits into
feat/browser-sdk-breadcrumbsfrom
feat/browser-sdk-http-errors-csp

Merge branch 'feat/browser-sdk-breadcrumbs' into feat/browser-sdk-htt…

cad4838
Select commit
Loading
Failed to load commit list.
Maple Review Bot / Maple / review succeeded Sep 29, 2026 in 5m 52s

Confidence 4/5 · No issues found

Confidence 4/5 · likely safe to merge
The delta since the last review is one stateful-regex fix with a test that fails without it, plus a type-only option already wired end to end.
quality 100/100 · no findings · tests covered · risk medium · 2/2 new units observable

Reviewed the two files changed since the last pass. matches now clears a stateful g/y regex's lastIndex before test, and ErrorFilterOptions.captureHttpStatus is declared as ReadonlyArray<HttpStatusRange> (type-only import) and already reaches HttpStatusExporter. No defect found in the delta.

  • matches resets lastIndex before test, so a g/y pattern cannot skip matches
  • ErrorFilterOptions.captureHttpStatus typed against HttpStatusRange, re-exported from the package root
What was checked
  • error-filters.test.ts:83 uses /chunk/gi three times, so it fails if the reset is removed
  • import type at error-filters.ts:4 keeps the http-status import type-only, no runtime cycle
  • captureHttpStatus flows config.ts:242 → tracing.ts:175 into HttpStatusExporter
Observability coverage: 2 of 2 changes observable
Change Kind Observable Evidence
HttpStatusExporter HTTP status error policy (error.type/error.message on listed statuses) in-process span exporter yes The exporter decides the span's own status and error attributes, which is the telemetry itself; covered by http-status.test.ts
ReportingObserver / securitypolicyviolation listener in deferred/reports.ts inbound browser event consumer yes Emits maple.browser.csp_violation and maple.browser.report OTLP log events via emitLog, matching the SDK's log-event convention (web vitals)

cad4838 · Updated on every push. Reply "won't fix" to dismiss a finding, or mention @maple to ask about one.