Skip to content

Capture all repeated Cookie and Set-Cookie header values #5982

Description

@adinauer

Problem

The OkHttp, Ktor, and Apollo integrations capture only one Cookie or Set-Cookie header value when creating request and response contexts. Their current header accessors select a single value, so additional cookie fields are omitted from Sentry telemetry.

This is valid HTTP behavior. In particular, HTTP/2 allows clients to split the Cookie field into multiple header fields for compression. Responses also commonly contain multiple Set-Cookie fields.

This is follow-up completeness work from #5811 and supports #5666.

Check what other SDKs are doing before implementing.

Proposed solution

Make cookie extraction list-aware across OkHttp, Ktor, Apollo 3, and Apollo 4:

  • Combine repeated request Cookie fields with ; before applying the effective cookie policy.
  • Process each response Set-Cookie field independently because each field represents one cookie and its attributes.
  • Do not comma-join or comma-split Set-Cookie values. A valid Expires attribute contains a comma.
  • Add shared core helpers or integration-specific adapters that apply the effective cookie policy to every value.
  • Preserve valid Set-Cookie attributes and fail closed for malformed input.

Preserve the existing absent-Data-Collection compatibility behavior for each integration.

Acceptance criteria

  • OkHttp, Ktor, Apollo 3, and Apollo 4 capture all repeated cookie header values supported by their header APIs.
  • Multiple request Cookie fields are combined with ; and filtered as one cookie string.
  • Multiple response Set-Cookie fields are filtered independently without comma splitting or joining.
  • Built-in sensitive-cookie filtering and configured allow-list, deny-list, and off behavior apply to every cookie value.
  • Malformed cookie values never bypass filtering.
  • Integration tests cover at least two request Cookie fields and two response Set-Cookie fields where the underlying header API supports repeated values.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions