Skip to content

💥 [RUM-17990] scrub the app path from payloads - #241

Draft
bcaudan wants to merge 4 commits into
bcaudan/scl-path-scrubberfrom
bcaudan/scl-scrubber-wiring
Draft

bcaudan wants to merge 4 commits into
bcaudan/scl-path-scrubberfrom
bcaudan/scl-scrubber-wiring

Conversation

@bcaudan

@bcaudan bcaudan commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Motivation

Payloads still carry installation-specific app paths (file:///Users/alice/…/app.asar/dist/main.js, main-process stacks under the install folder): source maps can't resolve them and they leak the user's home directory. This PR wires the PathScrubber from the previous PR into every place payloads are written, so the app path becomes / everywhere.

Breaking change: view.url, resource.url, error stacks, replay href and profile resources change from absolute file:// or install paths to root-relative values (/main-window.html, /main.js). Queries and monitors on the old values break, and Error Tracking issues regroup once.

Changes

  • init() builds one PathScrubber and passes it explicitly down to the three exit points: StandardBatchProducer (RUM, telemetry, logs, spans), ProfileBatchProducer (event and trace) and Segment.flush (replay). Scrubbing happens after beforeSendRum, so existing customer rewrites keep working.
  • Batch rotation and the replay raw_segment_size are computed on the scrubbed text.
  • The e2e and integration intake now fails any scenario whose payloads contain an absolute SDK path (app path, userData, crashDumps), so every app setup and platform of the compatibility matrix validates the scrubbing. A positive control checks that main-process frames are root-relative.
  • docs/ARCHITECTURE.md describes payload scrubbing; docs/TESTING.md describes the intake check.

Test instructions

  1. Run the playground with source maps uploaded (layer A tooling), trigger a main-process error and a file:// renderer error
  2. In Datadog, check both stacks resolve to the original files, and that view URLs read /… instead of file:///Users/…
  3. Open the session replay: it still plays, and its href is root-relative

Checklist

  • Tested locally (playground)
  • Added unit tests for this change.
  • Added e2e/integration tests for this change.
  • Updated related documentation.
  • Agentic code review findings addressed or explicitly dismissed.

Replay hrefs and stylesheet URLs become root-relative, so they match uploaded source maps and no longer carry the install path.
Stacks and URLs in RUM, telemetry, logs, spans and profiles become root-relative, so they match uploaded source maps.
Describes where payloads are scrubbed and adds the e2e positive control proving it runs.
Runs on every e2e, integration and compatibility scenario, so each app setup and platform validates the scrubbing.
@bcaudan
bcaudan added this pull request to stack #242 October 7, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant