feat(web-tanstack): Sentry instrumentation via @sentry/node + @sentry/react + R38 PII test

Adds initSentryServerNode + initSentryClientReact to core-shared
(Vite/non-Next variants of the existing init helpers — same R31/R32/R33
posture, R34/R35/R37 replay defaults). Extends no-sentry.ts to mock
@sentry/node + @sentry/react. Wires the web-tanstack server/client
instrumentation entry hooks and adds the R38 PII test.

Spec deviation: web-tanstack has no vite.config.ts yet (placeholder app
per its package.json). The @sentry/vite-plugin dep is added but unused
until the TanStack Start build is wired in a later plan. A minimal
src/vite-env.d.ts shims ImportMetaEnv for the client entry until the
full Vite types land.

@sentry/node and @sentry/react are added to core-shared as optional
peerDependencies so feature packages don't transitively pull them in;
they're also devDependencies of core-shared for typecheck/test runs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-07 20:25:14 +02:00
parent d348cb9179
commit e1b6ecf578
13 changed files with 548 additions and 0 deletions

View File

@@ -18,3 +18,5 @@ export {
bindSentryInstrumentation,
type BindSentryOpts,
} from "./di/bind-sentry-instrumentation";
export { initSentryServerNode } from "./sentry/init-server-node";
export { initSentryClientReact } from "./sentry/init-client-react";

View File

@@ -0,0 +1,67 @@
// packages/core-shared/src/instrumentation/sentry/init-client-react.test.ts
import { describe, it, expect, vi, beforeEach } from "vitest";
const { replayIntegration } = vi.hoisted(() => {
const replayIntegration = vi.fn((opts: unknown) => ({ name: "Replay", _opts: opts }));
return { replayIntegration };
});
vi.mock("@sentry/react", () => ({
init: vi.fn(),
replayIntegration,
}));
import * as SentryReact from "@sentry/react";
import { initSentryClientReact } from "@/instrumentation/sentry/init-client-react";
describe("initSentryClientReact", () => {
beforeEach(() => {
vi.clearAllMocks();
});
it("calls SentryReact.init with sendDefaultPii: false (R31)", () => {
initSentryClientReact({ dsn: "https://x@y/1", app: "web-tanstack" });
const call = (SentryReact.init as ReturnType<typeof vi.fn>).mock.calls[0]![0] as Record<
string,
unknown
>;
expect(call["sendDefaultPii"]).toBe(false);
});
it("attaches replay integration with mask flags (R34, R35)", () => {
initSentryClientReact({ dsn: "https://x@y/1", app: "web-tanstack" });
expect(replayIntegration).toHaveBeenCalledTimes(1);
const replayOpts = (replayIntegration as ReturnType<typeof vi.fn>).mock.calls[0]![0] as Record<
string,
unknown
>;
expect(replayOpts["maskAllText"]).toBe(true);
expect(replayOpts["maskAllInputs"]).toBe(true);
expect(replayOpts["blockAllMedia"]).toBe(true);
});
it("defaults replay sample rates per R37", () => {
initSentryClientReact({ dsn: "https://x@y/1", app: "web-tanstack" });
const call = (SentryReact.init as ReturnType<typeof vi.fn>).mock.calls[0]![0] as Record<
string,
unknown
>;
expect(call["replaysSessionSampleRate"]).toBe(0.0);
expect(call["replaysOnErrorSampleRate"]).toBe(1.0);
});
it("attaches beforeSend + beforeSendTransaction scrubbers", () => {
initSentryClientReact({ dsn: "https://x@y/1", app: "web-tanstack" });
const call = (SentryReact.init as ReturnType<typeof vi.fn>).mock.calls[0]![0] as Record<
string,
unknown
>;
expect(typeof call["beforeSend"]).toBe("function");
expect(typeof call["beforeSendTransaction"]).toBe("function");
});
it("is a no-op when dsn is missing", () => {
initSentryClientReact({ dsn: "", app: "web-tanstack" });
expect(SentryReact.init).not.toHaveBeenCalled();
});
});

View File

@@ -0,0 +1,48 @@
// packages/core-shared/src/instrumentation/sentry/init-client-react.ts
import * as SentryReact from "@sentry/react";
import { beforeSend, beforeSendTransaction } from "./scrub";
import type { InitClientOpts } from "./init-client";
/**
* Client-side init for non-Next.js (Vite/React) runtimes (TanStack Start).
* Mirrors init-client.ts but uses @sentry/react directly. R31, R32, R33,
* R34, R35, R37 still apply.
*/
export function initSentryClientReact(opts: InitClientOpts): void {
if (!opts.dsn) return;
const isProd = process.env["NODE_ENV"] === "production";
const tracesSampleRate =
process.env["SENTRY_TRACES_SAMPLE_RATE"] !== undefined
? Number(process.env["SENTRY_TRACES_SAMPLE_RATE"])
: isProd
? 0.1
: 1.0;
const environment =
process.env["SENTRY_ENVIRONMENT"] ?? process.env["NODE_ENV"] ?? "development";
const release = opts.release ?? "unknown";
type InitOpts = Parameters<typeof SentryReact.init>[0];
SentryReact.init({
dsn: opts.dsn,
environment,
release,
tracesSampleRate,
sendDefaultPii: false, // R31
beforeSend: beforeSend as unknown as NonNullable<InitOpts>["beforeSend"], // R32
beforeSendTransaction:
beforeSendTransaction as unknown as NonNullable<InitOpts>["beforeSendTransaction"], // R33
replaysSessionSampleRate: 0.0, // R37
replaysOnErrorSampleRate: 1.0, // R37
integrations: [
// R34, R35 — mandatory mask flags; allowlist starts empty
SentryReact.replayIntegration({
maskAllText: true,
maskAllInputs: true,
blockAllMedia: true,
}),
],
initialScope: { tags: { app: opts.app } },
});
}

View File

@@ -0,0 +1,51 @@
// packages/core-shared/src/instrumentation/sentry/init-server-node.test.ts
import { describe, it, expect, vi, beforeEach } from "vitest";
vi.mock("@sentry/node", () => ({
init: vi.fn(),
}));
import * as SentryNode from "@sentry/node";
import { initSentryServerNode } from "@/instrumentation/sentry/init-server-node";
describe("initSentryServerNode", () => {
beforeEach(() => {
vi.clearAllMocks();
});
it("calls SentryNode.init with sendDefaultPii: false (R31)", () => {
initSentryServerNode({ dsn: "https://x@y/1", app: "web-tanstack" });
const call = (SentryNode.init as ReturnType<typeof vi.fn>).mock.calls[0]![0] as Record<
string,
unknown
>;
expect(call["sendDefaultPii"]).toBe(false);
});
it("attaches beforeSend + beforeSendTransaction scrubbers", () => {
initSentryServerNode({ dsn: "https://x@y/1", app: "web-tanstack" });
const call = (SentryNode.init as ReturnType<typeof vi.fn>).mock.calls[0]![0] as Record<
string,
unknown
>;
expect(typeof call["beforeSend"]).toBe("function");
expect(typeof call["beforeSendTransaction"]).toBe("function");
});
it("tags events with the app name", () => {
initSentryServerNode({ dsn: "https://x@y/1", app: "web-tanstack" });
const call = (SentryNode.init as ReturnType<typeof vi.fn>).mock.calls[0]![0] as Record<
string,
unknown
>;
const initialScope = call["initialScope"] as { tags?: Record<string, string> };
expect(initialScope?.tags?.["app"]).toBe("web-tanstack");
});
it("is a no-op when dsn is missing", () => {
initSentryServerNode({ dsn: "", app: "web-tanstack" });
expect(SentryNode.init).not.toHaveBeenCalled();
initSentryServerNode({ dsn: undefined as unknown as string, app: "web-tanstack" });
expect(SentryNode.init).not.toHaveBeenCalled();
});
});

View File

@@ -0,0 +1,40 @@
// packages/core-shared/src/instrumentation/sentry/init-server-node.ts
import * as SentryNode from "@sentry/node";
import { beforeSend, beforeSendTransaction } from "./scrub";
import type { InitServerOpts } from "./init-server";
/**
* Server-side init for non-Next.js runtimes (TanStack Start). Mirrors
* init-server.ts but uses @sentry/node directly. R31, R32, R33 still apply.
*/
export function initSentryServerNode(opts: InitServerOpts): void {
if (!opts.dsn) return;
const isProd = process.env["NODE_ENV"] === "production";
const tracesSampleRate =
process.env["SENTRY_TRACES_SAMPLE_RATE"] !== undefined
? Number(process.env["SENTRY_TRACES_SAMPLE_RATE"])
: isProd
? 0.1
: 1.0;
const environment =
process.env["SENTRY_ENVIRONMENT"] ??
process.env["VERCEL_ENV"] ??
process.env["NODE_ENV"] ??
"development";
const release = opts.release ?? process.env["VITE_GIT_COMMIT_SHA"] ?? "unknown";
type InitOpts = Parameters<typeof SentryNode.init>[0];
SentryNode.init({
dsn: opts.dsn,
environment,
release,
tracesSampleRate,
sendDefaultPii: false, // R31
beforeSend: beforeSend as unknown as NonNullable<InitOpts>["beforeSend"], // R32
beforeSendTransaction:
beforeSendTransaction as unknown as NonNullable<InitOpts>["beforeSendTransaction"], // R33
initialScope: { tags: { app: opts.app } },
});
}