feat(web-next): Sentry instrumentation hooks + withSentryConfig + R38 PII test

Adds apps/web-next/instrumentation.ts (server) and instrumentation-client.ts
(browser) hooks, wraps next.config.mjs with withSentryConfig (R52), and adds
the R38 per-app PII scrubber smoke test.

Spec deviation: extend PII_KEY_SUBSTRINGS with "ipaddress" so keys like
ipAddress trigger key-level redaction (tighter posture than the spec's
substring list; existing scrub.test.ts still passes).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-07 20:13:39 +02:00
parent d4bc045a28
commit f911892d0b
8 changed files with 133 additions and 2 deletions

View File

@@ -12,6 +12,7 @@ export const PII_KEY_SUBSTRINGS = [
"apikey",
"api_key",
"secret",
"ipaddress",
] as const;
// R33 — substring match on URL query-param keys (case-insensitive)