feat(quart): Add span streaming support to Quart integration#6502
feat(quart): Add span streaming support to Quart integration#6502ericapisani wants to merge 17 commits into
Conversation
Move http.query and client.address attribute collection inside the should_send_default_pii() check so sensitive values are not captured by default. Fixes PY-2514 Fixes #6499
Add span streaming support for the Quart integration when the trace_lifecycle stream experiment is enabled. Sets HTTP request attributes (method, headers, URL, query, client IP) on the segment span and uses the correct source constant from sentry_sdk.traces for span-first mode. Depends on #6501 being merged first. Fixes PY-2352 Fixes #6050
Codecov Results 📊✅ 89523 passed | ⏭️ 6013 skipped | Total: 95536 | Pass Rate: 93.71% | Execution Time: 311m 35s 📊 Comparison with Base Branch
All tests are passing successfully. ✅ Patch coverage is 91.84%. Project has 2393 uncovered lines. Files with missing lines (1)
Coverage diff@@ Coverage Diff @@
## main #PR +/-##
==========================================
+ Coverage 89.80% 89.81% +0.01%
==========================================
Files 192 192 —
Lines 23460 23495 +35
Branches 8062 8084 +22
==========================================
+ Hits 21069 21102 +33
- Misses 2391 2393 +2
- Partials 1328 1332 +4Generated by Codecov Action |
There was a problem hiding this comment.
We'll need a streaming counterpart for this piece of code, something like:
client = sentry_sdk.get_client()
if has_span_streaming_enabled(client.options):
span = get_current_span()
if span is not None:
span._segment._update_active_thread()| ) | ||
| segment.set_attribute( | ||
| "user.ip_address", request_websocket.access_route[0] | ||
| ) |
There was a problem hiding this comment.
We should also set user.id if we have it (essentially port _add_user_to_event).
It's one of the attributes that should be set on all spans, not just the segment, so it should be set on the scope.
Maybe extract the code that fetches the user id from _add_user_to_event to a helper func, get rid of _add_user_to_event and set the user id in the event processor directly, and in the streaming path set it on the current scope?
def _fetch_user_id() -> None:
if quart_auth is None:
return
user = quart_auth.current_user
if user is None:
return
try:
return quart_auth.current_user._auth_id
except Exception:
return Noneand then here
user_id = _fetch_user_id()
if user_id is not None:
sentry_sdk.get_current_scope().set_attribute("user.id", user_id)and in the event processor
user_id = _fetch_user_id()
if user_id is not None:
user_info = event.setdefault("user", {})
user_info["id"] = user_idThere was a problem hiding this comment.
Please also add a test for this if there is none or add to an existing one.
There was a problem hiding this comment.
Sounds good. Regarding needing to set the user.id on the scope - would that mean that we also need to make an adjustment for the user.ip_address as well? I noticed it also appears in that list that you had linked 👀
There was a problem hiding this comment.
That's a really good point that made me realize we had a bug in the attribute setting code, fix here. Yup we should absolutely also be setting ip_address.
I need to amend my previous comment though: we should port setting the user but not the way I wrote. There's an existing mechanism for it (set_user) that we should use -- it sets the user data on the scope and then this code materializes it on the span eventually. The only thing to be mindful of is that set_user accepts a dict where the keys are different from the final attribute names (see the linked code), so it's e.g. name instead of user.name etc.
There was a problem hiding this comment.
Another thing to note: set_user will completely overwrite whatever was there previously (it doesn't merge the dicts), so we need to collect all the fields we have and update once.
| SENTRY_PYTHON_TEST_POSTGRES_USER: postgres | ||
| SENTRY_PYTHON_TEST_POSTGRES_PASSWORD: sentry | ||
| SENTRY_PYTHON_TEST_MYSQL_USER: root | ||
| SENTRY_PYTHON_TEST_MYSQL_PASSWORD: sentry |
There was a problem hiding this comment.
Missing MySQL host env variable
Medium Severity
The DB CI job sets SENTRY_PYTHON_TEST_POSTGRES_HOST to postgres for Python 3.6/3.7 container runs but does not set SENTRY_PYTHON_TEST_MYSQL_HOST the same way for the new MySQL service. tests/integrations/aiomysql reads that variable and defaults to localhost, which is unreachable from the job container network.
Reviewed by Cursor Bugbot for commit dde12e6. Configure here.
| SENTRY_PYTHON_TEST_POSTGRES_USER: postgres | ||
| SENTRY_PYTHON_TEST_POSTGRES_PASSWORD: sentry | ||
| SENTRY_PYTHON_TEST_MYSQL_USER: root | ||
| SENTRY_PYTHON_TEST_MYSQL_PASSWORD: sentry |
There was a problem hiding this comment.
Missing MySQL host container env
Medium Severity
The new MySQL CI env sets SENTRY_PYTHON_TEST_MYSQL_USER and password but not SENTRY_PYTHON_TEST_MYSQL_HOST. For Python 3.6/3.7 jobs that run inside a service-linked container, tests/integrations/aiomysql defaults to localhost, unlike Postgres and Redis which use the mysql service hostname in that layout.
Reviewed by Cursor Bugbot for commit e5eb0b3. Configure here.
…ython into py-2352-migrate-quart
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
There are 4 total unresolved issues (including 2 from previous reviews).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 717731d. Configure here.
| segment = spans[1] | ||
| if send_default_pii and user_id is not None: | ||
| assert segment["attributes"]["user.id"] == user_id | ||
| print("SEGMENT ATTRS", segment["attributes"]) |
There was a problem hiding this comment.
Debug print left in test
Low Severity
A print("SEGMENT ATTRS", ...) call remains in test_span_streaming_quart_auth_user_id, which will emit noisy output whenever that test runs under PII with a logged-in user.
Reviewed by Cursor Bugbot for commit 717731d. Configure here.
| user_properties["id"] = current_user_id | ||
|
|
||
| if user_properties: | ||
| sentry_sdk.get_current_scope().set_user(user_properties) |
There was a problem hiding this comment.
set_user drops existing scope user
Medium Severity
The span-streaming path calls set_user with only newly built user_properties (IP and Quart auth id) on the current scope, so any user fields already on the isolation scope are replaced instead of merged before one update.
Reviewed by Cursor Bugbot for commit 717731d. Configure here.


Add span streaming support for the Quart integration when the
trace_lifecycle stream experiment is enabled. Sets HTTP request
attributes (method, headers, URL, query, client IP) on the segment
span and uses the correct source constant from sentry_sdk.traces
for span-first mode.
Depends on #6501
being merged first.
Fixes PY-2352
Fixes #6050