Repository navigation
feat(scrubbing): implement PII scrubbing for stacktrace args - #1068
Merged
Merged
Conversation
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
2 times, most recently
from
May 26, 2026 12:01
a1fa0b9 to
ad495d6
Compare
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
from
May 28, 2026 11:33
ad495d6 to
e17e51e
Compare
solnic
changed the base branch from
fix/broaden-conn-scrubber
to
refa/consolidate-plug-scrubber-access
May 28, 2026 11:34
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
from
May 29, 2026 12:46
e17e51e to
c0c9dc8
Compare
solnic
force-pushed
the
refa/consolidate-plug-scrubber-access
branch
from
May 29, 2026 12:48
6d67fda to
d234d46
Compare
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
from
May 29, 2026 12:49
c0c9dc8 to
9f2ec07
Compare
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
2 times, most recently
from
June 1, 2026 09:38
5a2edb0 to
6778f84
Compare
solnic
force-pushed
the
refa/consolidate-plug-scrubber-access
branch
2 times, most recently
from
June 3, 2026 12:35
4b4dd34 to
e05c35a
Compare
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
3 times, most recently
from
June 3, 2026 13:38
03dd2d1 to
9240a03
Compare
solnic
commented
Jun 3, 2026
|
|
||
| Otherwise, we don't perform any scrubbing. To configure scrubbing, you can use the | ||
| `:scrubbing` option (see below). | ||
| `:scrubber` option (see below). |
Collaborator
Author
There was a problem hiding this comment.
Yes, that's the correct one 😄
solnic
force-pushed
the
refa/consolidate-plug-scrubber-access
branch
from
June 4, 2026 10:26
e05c35a to
6453968
Compare
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
from
June 4, 2026 10:26
9240a03 to
587cfb4
Compare
solnic
marked this pull request as ready for review
June 4, 2026 12:43
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 587cfb4. Configure here.
solnic
force-pushed
the
refa/consolidate-plug-scrubber-access
branch
from
June 5, 2026 08:34
6453968 to
211cdf8
Compare
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
2 times, most recently
from
June 5, 2026 12:04
32d8cf6 to
5c7697d
Compare
whatyouhide
approved these changes
Jun 6, 2026
solnic
force-pushed
the
refa/consolidate-plug-scrubber-access
branch
from
June 8, 2026 08:47
ffeec1c to
d7f79c1
Compare
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
from
June 8, 2026 08:49
5c7697d to
4ee788a
Compare
whatyouhide
approved these changes
Jun 8, 2026
Frame vars in event payloads are built by `inspect/1`-ing each arg, so a Plug.Conn or plain map passed to a function that raises leaks its contents into the event - authorization headers, cookies, password params, etc. `Sentry.Event` now scrubs each frame arg with `Sentry.Scrubber.scrub/1` before inspecting it, redacting `Plug.Conn` and map values (honoring any registered conn scrubber) while leaving everything else untouched. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This unifies dealing with exceptions and scrubbing. Previously it would special-case function clause errors from phoenix which was not sufficient. Now we scrub plug conn consistently when reporting exceptions.
Add a Phoenix integration endpoint that fabricates a plain FunctionClauseError (not a Phoenix.ActionClauseError) and assert that its captured stacktrace frame vars are scrubbed by Sentry.Event via StacktraceScrubber, independently of PlugCapture's ActionClauseError handling. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
solnic
force-pushed
the
fix/scrub-sensitive-data-from-stacktraces
branch
from
June 8, 2026 12:20
4ee788a to
73a3f74
Compare
changes in master surfaced this but it will be restored in the follow-up scrubb-broadening branch
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Sensitive data captured in a
FunctionClauseError/Phoenix.ActionClauseErrorcould leak into Sentry through stacktrace frame variables and the captured
exception's
:argsChanges
Sentry.Scrubber.StacktraceScrubber— a small, framework-agnostic helperthat scrubs args captured into error data. Each arg goes through
Sentry.Scrubber.scrub/1; callers that know the args' shape can pass a customcallback.
Sentry.Eventnow scrubs stacktrace frame vars (viascrub_args/1) beforeinspecting/truncating them.
Sentry.PlugCaptureroutesPhoenix.ActionClauseErrorscrubbing through thesame
Sentry.ScrubberasSentry.PlugContext(honoring the configured:body_scrubber/:header_scrubber/:cookie_scrubber/:url_scrubber), andmirrors the scrubbed conn's params onto the action's standalone params arg so both
are redacted consistently.
New reusable exception stacktrace scrubber
This is used under the hood to reduce duplication in
Sentry.EventandSentry.PlugCapture.