fix(cli): Guard baggage header against non-ASCII characters - #1398
Closed
sentry[bot] wants to merge 1 commit into
Closed
sentry[bot] wants to merge 1 commit into
sentry[bot] wants to merge 1 commit into
Conversation
Contributor
There was a problem hiding this comment.
Closing this one. The evidence points at the Authorization header, not baggage, and current main already fixes the real cause.
- Baggage can't contain non-ASCII here.
getTraceData()buildsbaggagewithdynamicSamplingContextToSentryBaggageHeader→objectToBaggageHeader, and that runsencodeURIComponenton every key and value (@sentry/core10.63.0,utils/baggage.js). A release containingıwould be sent as%C4%B1. Also, the affected release in these events is0.44.1, which is plain ASCII. The new tests mockgetTraceDatato return raw non-ASCII, which the SDK never produces. - The failure matches
Authorization: Bearer <token>. All 42 CLI-3A8 events aresourcemap uploadon 0.44.1. There are two variants: U+0131 at index 32, and U+2022 (•) at index 7. Index 7 is the first character afterBearer, and•is a masked or pasted token character. Abaggagevalue can't have that byte at index 7, because it always starts with a fixed ASCIIsentry-…key. - Already fixed on
main. getsentry/cli#1638 (merged 2026-09-28, after 0.44.1) addednormalizeAuthToken/formatAuthHeaderinpackages/cli/src/lib/auth-header.ts. They reject non-ASCII and whitespace in tokens withMalformedAuthTokenErrorbefore theHeaders.setcall, so this path no longer throws the undiciTypeError.
Dropping baggage here would only hide a header that's already valid. If CLI-3A8 comes back on a release that includes #1638, that would be new evidence worth a fresh look.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR addresses CLI-3A8, where the Sentry CLI would crash with a
TypeErrorfrom Node.jsundiciwhen attempting to set an HTTPbaggageheader containing non-ASCII characters.Root Cause:
prepareHeaders()inpackages/cli/src/lib/sentry-client.tswas passing thetraceData.baggagevalue directly toheaders.set(). If the Sentry SDK'sgetTraceData()produced a baggage string (e.g., from a release name) containing characters with code points greater than 255 (like Turkish 'ı' U+0131),undici'sByteStringconversion would fail.Solution:
NON_HTTP_HEADER_CHAR_REregex insentry-client.tsto detect non-ASCII characters in the baggage header value.prepareHeaders()to checktraceData.baggageagainst this regex. If non-ASCII characters are present, the baggage header is now gracefully omitted, preventing theTypeError.test/lib/sentry-client.baggage.mocked.test.ts, to cover cases with both valid ASCII and invalid non-ASCII baggage values, ensuring the guard functions as expected.This ensures the CLI remains stable even when dealing with non-ASCII release names, while still forwarding distributed tracing information when possible.
Fixes CLI-3A8
@sentry <feedback>: Autofix iterates on these changes@sentry stop iterating: Autofix stops iterating on this runThis PR was automatically generated by Sentry. You can adjust this setting at any time.