Skip to content

feat(integrations): Added Integrity policy - #6465

Open
GemLunaMarine wants to merge 7 commits into
getsentry:masterfrom
GemLunaMarine:master
Open

GemLunaMarine wants to merge 7 commits into
getsentry:masterfrom
GemLunaMarine:master

Conversation

@GemLunaMarine

Copy link
Copy Markdown

Browser-sent reports of type "integrity-violation" is not yet supported in Sentry Relay, and get rejected with "Invalid CSP". This Pull Request allows Relay to accept and send Integrity policy reports to Sentry backend. No Sentry backend changes are required, as it uses OurLog and is already formatted and correctly accepted into backend + frontend (except maybe like optimization or something).

Currently, testcases are not implemented (waiting to see if current direction is correct before creating tests). Current file lacking testcases is "/relay-event-normalization/src/normalize/integrity.rs".

Not sure if docs should have integration links (not just /integration/integrity/ but also for stuff like /integration/vercel/...). Should also probably update documentation to allow users to setup and use integrity reporting.
https://github.com/getsentry/sentry-docs/blob/master/docs/product/relay/operating-guidelines.mdx

Implementation to solve issue:
getsentry/sentry#124388

Legal Boilerplate

Look, I get it. The entity doing business as "Sentry" was incorporated in the State of Delaware in 2015 as Functional Software, Inc. and is gonna need some rights from me in order to utilize my contributions in this here PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Sentry can use, modify, copy, and redistribute my contributions, under Sentry's choice of terms.

@GemLunaMarine
GemLunaMarine requested a review from a team as a code owner October 2, 2026 13:45
@GemLunaMarine

Copy link
Copy Markdown
Author

@jjbayer @Dav1dde Here is the new implementation of the Integrity policy (following NEL format). Let me know if you need any changes, or if there are any issues with the pull request.

@loewenheim loewenheim left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the contribution! I have some nits and a bigger comment about attributes, but on the whole this looks very good. You're definitely on the right track.

Comment thread relay-server/src/endpoints/mod.rs Outdated
.route("/api/{project_id}/security/", security_report::route(config))
.route("/api/{project_id}/csp-report/", security_report::route(config))
.route("/api/{project_id}/nel/", nel::route(config))
.route("/api/{project_id}/integration/integrity/", integrations::integrity::route(config))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This belongs further down with the other integration routes.

use relay_protocol::{Annotated, Empty, FromValue, IntoValue, Object, Value};

/// Generated Integrity policy.
/// Can't name as "BodyRaw", like in nel.rs, due to name conflicts

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think this name is preferable anyway if we're going to pub use it.

/// Models the content of a Integrity report.
#[derive(Debug, Default, Clone, PartialEq, FromValue, IntoValue, Empty)]
pub struct IntegrityReportRaw {
/// The age of the report since it got collected and before it got sent.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
/// The age of the report since it got collected and before it got sent.
/// The time between collecting and sending the report.

Comment on lines +90 to +104
add_string_attribute!("sentry.origin", "auto.http.browser_report.integrity");
add_string_attribute!("browser.report.type", "integrity-violation");

// Handle URL and extract server address if available
if let Some(url_str) = raw_report.url.value() {
let url_domain = extract_server_address(url_str);
add_string_attribute!("url.domain", &url_domain);
}
add_attribute!("url.full", raw_report.url);

// Integrity-specific attributes
add_attribute!("integrity.document_url", body.document_url);
add_attribute!("integrity.blocked_url", body.blocked_url);
add_attribute!("integrity.destination", body.destination);
add_attribute!("integrity.report_only", body.report_only);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please use the attribute constants defined in use relay_conventions::attributes, e.g. SENTRY__ORIGIN instead of "sentry.origin". Those constants are generated from the sentry_conventions repo and make it easier for us to check that we aren't using something that isn't defined. We should change this in the nel module, too.

On a related note, you will need to define the new integrity attributes in sentry-conventions.

@GemTails

GemTails commented Oct 6, 2026 •

Copy link
Copy Markdown

@loewenheim

Copy link
Copy Markdown
Contributor

conventions is merged. What you need to do here now is:

  1. cd into relay-conventions/sentry-conventions
  2. git checkout main
  3. git pull
  4. verify that the commit with the new attributes is included (git log or git show)
  5. commit the updated submodule

Comment thread relay-server/src/endpoints/integrations/integrity.rs
@loewenheim

Copy link
Copy Markdown
Contributor

Also merge or rebase onto master, please.

@loewenheim

Copy link
Copy Markdown
Contributor

Remaining issues:

  • Add a changelog entry under unreleased/features
  • Run cargo fmt
  • Run cargo test --workspace --all-features followed by cargo insta review, review and accept the new snapshots

@loewenheim loewenheim changed the title Added Integrity policy (integrations) feat(integrations): Added Integrity policy Oct 9, 2026
Comment thread relay-ua/uap-core

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are you intentionally changing this submodule?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, apologies. I think i accidentally added that. Lemme remove it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants