Skip to content

feat!: Replace the deprecated http.target span attribute - #23575

Open
msonnb wants to merge 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target
Open

feat!: Replace the deprecated http.target span attribute#23575
msonnb wants to merge 3 commits into
ms/http-attrs-renamesfrom
ms/http-attrs-target

Conversation

@msonnb

@msonnb msonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

Replaces the deprecated http.target span attribute with url.path and url.query.

Consumers that matched on http.target

Two ignoreSpans rules match spans that the SDK itself emits now match on url.path:

  • the low-quality transaction filter in @sentry/react-router
  • the tunnel-route filter in @sentry/tanstackstart-react

The readers in @sentry/nextjs still read http.target, but only after they read url.path. These readers also receive spans from an OpenTelemetry instrumentation that the user set up, and that instrumentation still emits the old attributes. Every other read-side fallback stays for the same reason.

no-unfiltered-url-attributes

This lint rule no longer guards http.target. The SDK no longer sets it, and its replacement url.path holds a pathname without a query, so there is nothing to filter.

part of #18895

@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 28.57 kB - -
@sentry/browser - with treeshaking flags 26.92 kB - -
@sentry/browser - with treeshaking flags tracing without tracing 26.82 kB - -
@sentry/browser (incl. Tracing) 48.5 kB +0.01% +3 B 🔺
@sentry/browser (incl. Tracing + Span Streaming) 48.52 kB -0.02% -8 B 🔽
@sentry/browser (incl. Tracing, Profiling) 51.42 kB -0.01% -3 B 🔽
@sentry/browser (incl. Tracing, Replay) 87.88 kB -0.02% -9 B 🔽
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 77.34 kB -0.02% -10 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas) 92.58 kB -0.01% -8 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback) 105.3 kB +0.01% +3 B 🔺
@sentry/browser (incl. Feedback) 45.81 kB - -
@sentry/browser (incl. sendFeedback) 33.36 kB - -
@sentry/browser (incl. FeedbackAsync) 38.47 kB - -
@sentry/browser (incl. Metrics) 29.52 kB - -
@sentry/browser (incl. Logs) 29.8 kB - -
@sentry/browser (incl. Metrics & Logs) 30.45 kB - -
@sentry/react 30.33 kB - -
@sentry/react (incl. Tracing) 50.7 kB -0.02% -7 B 🔽
@sentry/vue 35.64 kB - -
@sentry/vue (incl. Tracing) 50.72 kB -0.04% -18 B 🔽
@sentry/svelte 28.6 kB - -
CDN Bundle 30.32 kB - -
CDN Bundle (incl. Tracing) 49.02 kB -0.02% -7 B 🔽
CDN Bundle (incl. Logs, Metrics) 32.54 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 50.9 kB +0.02% +6 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) 72.91 kB - -
CDN Bundle (incl. Tracing, Replay) 86.47 kB +0.01% +5 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 88.33 kB -0.01% -2 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) 92.24 kB +0.02% +15 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 94.17 kB - -
CDN Bundle - uncompressed 89.94 kB - -
CDN Bundle (incl. Tracing) - uncompressed 146.59 kB -0.04% -55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed 96.23 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 152.28 kB -0.04% -55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 225.18 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 265.87 kB -0.03% -55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 271.54 kB -0.03% -55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 279.56 kB -0.02% -55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 285.23 kB -0.02% -55 B 🔽
@sentry/nextjs (client) 53.24 kB +0.03% +13 B 🔺
@sentry/sveltekit (client) 48.92 kB +0.01% +4 B 🔺
@sentry/core/server 65.03 kB -0.14% -85 B 🔽
@sentry/core/browser 52.25 kB -0.05% -21 B 🔽
@sentry/node 121.37 kB -0.16% -186 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection) 85.18 kB - -
@sentry/node - without tracing 87.41 kB -0.04% -27 B 🔽
@sentry/aws-serverless 95.6 kB -0.25% -230 B 🔽
@sentry/cloudflare (withSentry) - minified 199.29 kB +0.01% +13 B 🔺
@sentry/cloudflare (withSentry) 495.45 kB +0.01% +20 B 🔺

View base workflow run

@msonnb
msonnb force-pushed the ms/http-attrs-target branch from f6e86e3 to 2b3f570 Compare August 25, 2026 13:07
@msonnb
msonnb force-pushed the ms/http-attrs-target branch 2 times, most recently from ecc2aa5 to 4984f8c Compare August 25, 2026 14:01
@msonnb
msonnb force-pushed the ms/http-attrs-target branch from 4984f8c to 92af4c4 Compare August 25, 2026 14:39
@msonnb

msonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

bugbot run

@msonnb msonnb changed the title ref(core)!: Replace the deprecated http.target span attribute feat!: Replace the deprecated http.target span attribute Aug 25, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 92af4c4. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code owners August 25, 2026 14:44
@msonnb
msonnb requested review from chargome, isaacs and mydea and removed request for a team August 25, 2026 14:44
msonnb and others added 2 commits August 25, 2026 16:46
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.

`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.

The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.

Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.

`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.

`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.

Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.

`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.

The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.

Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.

`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.

`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.

Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnb force-pushed the ms/http-attrs-target branch from 92af4c4 to c0f52f9 Compare August 25, 2026 14:46
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.

`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.

Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.

`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnb force-pushed the ms/http-attrs-target branch from c0f52f9 to e71bd7a Compare August 25, 2026 14:52
@msonnb
msonnb requested a review from andreiborza August 25, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants