Skip to content

fix(spring): Handle user provider failures - #6240

Merged
adinauer merged 5 commits into
fix/callback-error-handlingfrom
fix/callback-error-handling-spring-user-provider
Oct 9, 2026
Merged

adinauer merged 5 commits into
fix/callback-error-handlingfrom
fix/callback-error-handling-spring-user-provider

Conversation

@adinauer

@adinauer adinauer commented Oct 9, 2026

Copy link
Copy Markdown
Member

📜 Description

Handle exceptions from SentryUserProvider implementations across the Spring, Spring Jakarta, and Spring 7 integrations. Later providers and the request continue running, but any provider failure causes the accumulated identity to be discarded and an empty user to be set.

💡 Motivation and Context

A custom user provider currently can interrupt request processing. Retaining identity from providers that ran before or after a failure could also attach incomplete or unintended PII. Failing closed shadows inherited scope users while preserving request availability.

💚 How did you test it?

  • ./gradlew spotlessApply apiDump
  • ./gradlew :sentry-spring:test :sentry-spring-jakarta:test :sentry-spring-7:test

📝 Checklist

  • I added GH Issue ID & Linear ID
  • I added tests to verify the changes.
  • No new PII added or SDK only sends newly added PII if sendDefaultPII is enabled.
  • I updated the docs if needed.
  • I updated the wizard if needed.
  • Review from the native team if needed.
  • No breaking change or entry added to the changelog.
  • No breaking change for hybrid SDKs or communicated to hybrid SDKs.
  • Public API changes reviewed by another Mobile SDK team member or implemented according to the develop docs spec.

🔮 Next steps

None.

adinauer and others added 2 commits October 9, 2026 06:26
Keep requests running when a Spring user provider throws. Continue invoking later providers, but discard all provider-derived identity and install an empty user so inherited identity cannot leak into the event.

Co-Authored-By: Claude <noreply@anthropic.com>
@sentry

sentry Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

📲 Install Builds

Android

🔗 App Name App ID Version Configuration
SDK Size io.sentry.tests.size 8.59.0 (1) release

⚙️ sentry-android Build Distribution Settings

}
}
scopes.setUser(user);
scopes.setUser(providerFailed ? new User() : user);

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

overriding with an empty user seems safer in terms of PII leak risk compared to taking last good state or ignoring failing providers and using the others as it might be a data stripping provider that failed

@lbloder lbloder left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

small suggestion regarding log, otherwise LGTM

scopes
.getOptions()
.getLogger()
.log(SentryLevel.ERROR, "The SentryUserProvider callback threw an exception.", e);

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(l) should we log the name of the provider that failed? (provider.getClass().getName())?

adinauer and others added 2 commits October 9, 2026 16:35
Identify which SentryUserProvider failed when multiple providers are configured, making callback failures actionable across all Spring variants.

Refs GH-6240
Co-Authored-By: Claude <noreply@anthropic.com>
@adinauer
adinauer marked this pull request as ready for review October 9, 2026 14:38
@adinauer
adinauer merged commit 84e8b86 into fix/callback-error-handling Oct 9, 2026
51 of 53 checks passed
@adinauer
adinauer deleted the fix/callback-error-handling-spring-user-provider branch October 9, 2026 14:38
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor
Fails
🚫 Please consider adding a changelog entry for the next release.

Instructions and example for changelog

Please add an entry to CHANGELOG.md to the "Unreleased" section. Make sure the entry includes this PR's number.

Example:

## Unreleased

### Fixes

- Handle user provider failures ([#6240](https://github.com/getsentry/sentry-java/pull/6240))

If none of the above apply, you can opt out of this check by adding #skip-changelog to the PR description or adding a skip-changelog label.

Generated by 🚫 dangerJS against 5c639a8

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants