Skip to content

fix(custom-headers): reject non-ASCII characters in header values (CLI-31G) - #1660

Open
sentry[bot] wants to merge 2 commits into
mainfrom
seer/fix/cli-31g-header-validation
Open

sentry[bot] wants to merge 2 commits into
mainfrom
seer/fix/cli-31g-header-validation

Conversation

@sentry

@sentry sentry Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

This PR adds validation for custom HTTP header values to prevent TypeError: Cannot convert argument to a ByteString when non-Latin-1 characters (like emojis or other Unicode symbols), carriage returns, line feeds, or null characters are present.

Previously, custom header values were not checked for ByteString compliance before being passed to undici's Headers.set(). This could lead to a runtime TypeError crash if a user configured a custom header with an invalid character.

The assertValidHeaderValue function is introduced in src/lib/custom-headers.ts to perform this validation. It is called by both parseCustomHeaders (for SENTRY_CUSTOM_HEADERS env var and stored defaults) and setCustomHeadersOverride (for createSentrySDK({ headers })). Invalid values now result in a ConfigError being thrown early, providing a clearer error message to the user and preventing the underlying HTTP client crash.

Note: This issue (CLI-31G) was also caused by unvalidated authentication tokens containing non-ASCII characters. That specific problem is addressed by commit 980fa503 (#1638), which is already on main and will be released in 0.46.0 (or backported to a 0.45.x patch).

An existing e2e test (test/e2e/auth.test.ts) that previously relied on the TypeError crash for credential redaction testing has been updated to expect the new ConfigError behavior.

Fixes CLI-31G

@sentry <feedback>: Autofix iterates on these changes
@sentry stop iterating: Autofix stops iterating on this run

This PR was automatically generated by Sentry. You can adjust this setting at any time.

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cli Ready Ready Preview Oct 7, 2026 11:09am UTC
1 Skipped Deployment
Project Deployment Actions Updated
sentry-local Skipped Skipped Oct 7, 2026 11:09am UTC

Request Review

This branch was successfully deployed

1 active and 1 inactive deployments
Preview – cli — e3a78b7a Deployed Oct 7, 2026 by vercel[bot]
Preview – sentry-local — e3a78b7a Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk: medium PR risk score: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants