Skip to content

feat(node)!: Always report the encoded body size on HTTP spans - #23576

Open
msonnb wants to merge 2 commits into
ms/http-attrs-targetfrom
ms/http-attrs-body-sizes
Open

feat(node)!: Always report the encoded body size on HTTP spans#23576
msonnb wants to merge 2 commits into
ms/http-attrs-targetfrom
ms/http-attrs-body-sizes

Conversation

@msonnb

@msonnb msonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member

What

Always set http.(request|response).body.size instead of .size and .decoded_size in HTTP server spans. Browser resource spans are untouched and still report the latter, where the Resource Timing API measures it directly.

Why

The content-length header always reports the encoded body size, and we only set the .decoded_size attribute when content-encoding was identity, i.e. there was no encoding and the "decoded" size would equal the encoded size. I'd argue that "decoded" or "uncompressed" has no real meaning and thus value in this case and that we should just always set http.request.body.size.

part of #18895

@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 28.57 kB - -
@sentry/browser - with treeshaking flags 26.92 kB - -
@sentry/browser - with treeshaking flags tracing without tracing 26.82 kB - -
@sentry/browser (incl. Tracing) 48.5 kB +0.01% +3 B 🔺
@sentry/browser (incl. Tracing + Span Streaming) 48.52 kB -0.02% -8 B 🔽
@sentry/browser (incl. Tracing, Profiling) 51.42 kB -0.01% -3 B 🔽
@sentry/browser (incl. Tracing, Replay) 87.88 kB -0.02% -9 B 🔽
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 77.34 kB -0.02% -10 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas) 92.58 kB -0.01% -8 B 🔽
@sentry/browser (incl. Tracing, Replay, Feedback) 105.3 kB +0.01% +3 B 🔺
@sentry/browser (incl. Feedback) 45.81 kB - -
@sentry/browser (incl. sendFeedback) 33.36 kB - -
@sentry/browser (incl. FeedbackAsync) 38.47 kB - -
@sentry/browser (incl. Metrics) 29.52 kB - -
@sentry/browser (incl. Logs) 29.8 kB - -
@sentry/browser (incl. Metrics & Logs) 30.45 kB - -
@sentry/react 30.33 kB - -
@sentry/react (incl. Tracing) 50.7 kB -0.02% -7 B 🔽
@sentry/vue 35.64 kB - -
@sentry/vue (incl. Tracing) 50.72 kB -0.04% -18 B 🔽
@sentry/svelte 28.6 kB - -
CDN Bundle 30.32 kB - -
CDN Bundle (incl. Tracing) 49.02 kB -0.02% -7 B 🔽
CDN Bundle (incl. Logs, Metrics) 32.54 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 50.9 kB +0.02% +6 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) 72.91 kB - -
CDN Bundle (incl. Tracing, Replay) 86.47 kB +0.01% +5 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 88.33 kB -0.01% -2 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) 92.24 kB +0.02% +15 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 94.17 kB - -
CDN Bundle - uncompressed 89.94 kB - -
CDN Bundle (incl. Tracing) - uncompressed 146.59 kB -0.04% -55 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed 96.23 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 152.28 kB -0.04% -55 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 225.18 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 265.87 kB -0.03% -55 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 271.54 kB -0.03% -55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 279.56 kB -0.02% -55 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 285.23 kB -0.02% -55 B 🔽
@sentry/nextjs (client) 53.24 kB +0.03% +13 B 🔺
@sentry/sveltekit (client) 48.92 kB +0.01% +4 B 🔺
@sentry/core/server 64.97 kB -0.22% -140 B 🔽
@sentry/core/browser 52.29 kB +0.05% +26 B 🔺
@sentry/node 121.27 kB -0.24% -291 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection) 85.18 kB - -
@sentry/node - without tracing 87.33 kB -0.12% -99 B 🔽
@sentry/aws-serverless 95.46 kB -0.4% -374 B 🔽
@sentry/cloudflare (withSentry) - minified 199.29 kB +0.01% +13 B 🔺
@sentry/cloudflare (withSentry) 495.45 kB +0.01% +20 B 🔺

View base workflow run

@msonnb
msonnb force-pushed the ms/http-attrs-body-sizes branch from 5b4383f to d4a417c Compare August 25, 2026 13:07
@msonnb msonnb changed the title ref(core)!: Replace deprecated HTTP body size and status text attributes ref(node)!: Always report the encoded body size on HTTP spans Aug 25, 2026
@msonnb msonnb changed the title ref(node)!: Always report the encoded body size on HTTP spans feat(node)!: Always report the encoded body size on HTTP spans Aug 25, 2026
@msonnb
msonnb force-pushed the ms/http-attrs-body-sizes branch from d4a417c to 4a220fd Compare August 25, 2026 13:48
@msonnb
msonnb force-pushed the ms/http-attrs-body-sizes branch from 4a220fd to 376d102 Compare August 25, 2026 14:01
@msonnb
msonnb force-pushed the ms/http-attrs-body-sizes branch from 376d102 to 100e344 Compare August 25, 2026 14:38
@msonnb

msonnb commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 100e344. Configure here.

@msonnb
msonnb marked this pull request as ready for review August 25, 2026 14:44
@msonnb
msonnb requested review from a team as code owners August 25, 2026 14:44
@msonnb
msonnb requested review from JPeer264 and isaacs and removed request for a team August 25, 2026 14:44
@msonnb
msonnb force-pushed the ms/http-attrs-body-sizes branch from 100e344 to 684378f Compare August 25, 2026 14:46
msonnb and others added 2 commits August 25, 2026 16:50
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Stacked on the `http.*` renames.

`http.target` carried the pathname *and* the query, while `url.path` is the
pathname only. The core server span set neither `url.query` nor `url.fragment`,
so dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.

Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise have
silently stopped matching. The Next.js readers keep `http.target` as a fallback
behind a `url.path` primary, since they also see spans from a user's own
OpenTelemetry instrumentation. All other read-side fallbacks are untouched for
the same reason.

`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Part of the v11 migration. Stacked on the `http.target` PR. The attribute
renames landed in the first PR of the stack; this one is the behavior change
behind them.

Node HTTP spans read the `content-length` header and then reported it as either
the encoded or the decoded body size, branching on whether a `content-encoding`
header was present. Neither attribute was set on every span, so a query against
either one only ever saw part of a user's traffic.

`content-length` is the encoded size whether or not a content encoding is
applied, so it now always maps to `http.request.body.size` /
`http.response.body.size`.

The decoded size cannot be derived from `content-length`, so Node HTTP spans no
longer set `http.request.body.decoded_size` or
`http.response.body.decoded_size`. Browser resource spans still report the
latter, where the Resource Timing API measures it directly.

Deriving the decoded size from `content-length` when no encoding is applied was
considered and rejected: it would populate the attribute only where it
duplicates the encoded size, and leave it empty exactly where it carries
information, which makes any query over it a biased sample. Measuring the
decompressed stream would be the real fix and is out of scope here.

The three copies of the `content-length` parsing are now one
`getContentLengthFromHeaders` util in `@sentry/core`, whose docblock holds the
encoded-size rule so it is not restated at each call site.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@msonnb
msonnb force-pushed the ms/http-attrs-body-sizes branch from 684378f to 2e7b1a9 Compare August 25, 2026 14:52
@msonnb
msonnb requested a review from andreiborza August 25, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants