Skip to content

Conversation

@loewenheim
Copy link
Contributor

This adds versions of all the existing cookie rules for fields of the form http.request.header.cookie.<key>. This means that such cookies will be correctly scrubbed if an SDK sends them in span data or attributes.

Both span v1 and span v2 tests are added/expanded to verify the new behavior. In 65293ad you can see that some, but not all the sensitive cookies would've been picked up by another default rule already.

Implements INGEST-667.

@loewenheim loewenheim requested a review from a team as a code owner December 9, 2025 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants