Skip to content

fix(sentry): scrub percent-encoded Matrix IDs and opaque base64url tokens from URLs#531

Merged
7w1 merged 2 commits intoSableClient:devfrom
Just-Insane:fix/sentry-scrub-opaque-matrix-ids
Mar 25, 2026
Merged

fix(sentry): scrub percent-encoded Matrix IDs and opaque base64url tokens from URLs#531
7w1 merged 2 commits intoSableClient:devfrom
Just-Insane:fix/sentry-scrub-opaque-matrix-ids

Conversation

@Just-Insane
Copy link
Copy Markdown
Contributor

Description

Extends scrubMatrixUrl with two additional patterns that were leaking through the existing scrubber.

1. Opaque Matrix IDs with percent-encoded colon (%3A)

Device IDs, filter tokens, and other Matrix IDs that lack a sigil prefix but follow the localpart%3Aserver pattern were not matched by the existing sigil-based patterns. For example:

/Gj3Wy2D8gAi8jTIyR%3Asable.moe  →  /[MATRIX_ID]

2. Long opaque base64url path segments

Access tokens, Curve25519 keys, MSC3575 session tokens, and push endpoints appear as 30+ character base64url strings in URL path segments. These were passing through unscrubbed. For example:

/vI02CuiDNpaYEhUIVLbqE8vdKqm2ZwqIR5Y6NwNY_Rg/  →  /[REDACTED]/

The new pattern runs last so the earlier sigil-based patterns already handle known Matrix IDs first.

Fixes #

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update

Checklist:

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • My changes generate no new warnings

AI disclosure:

  • Partially AI assisted
  • Fully AI generated

Two regex patterns added to scrubMatrixUrl in sentryScrubbers.ts. The first matches path segments containing a bare localpart%3Aserver form (no sigil) and replaces with [MATRIX_ID]. The second matches any path segment of 30 or more base64url characters and replaces with [REDACTED], covering access tokens, crypto keys, and opaque session identifiers. Both are appended after the existing patterns so known sigil-prefixed IDs are handled first.

@Just-Insane Just-Insane requested review from 7w1 and hazre as code owners March 25, 2026 02:53
@dozro
Copy link
Copy Markdown
Contributor

dozro commented Mar 25, 2026

hey it seems like you're missing a changeset. Can you please add a changeset, as described here https://github.com/SableClient/Sable/blob/dev/CONTRIBUTING.md#documenting-a-change

Thank you :3

@Just-Insane
Copy link
Copy Markdown
Contributor Author

hey it seems like you're missing a changeset. Can you please add a changeset, as described here dev/CONTRIBUTING.md#documenting-a-change

Thank you :3

Yup, working on it.

@Just-Insane Just-Insane marked this pull request as draft March 25, 2026 03:09
@Just-Insane Just-Insane force-pushed the fix/sentry-scrub-opaque-matrix-ids branch from 00c9655 to 6409005 Compare March 25, 2026 03:32
@Just-Insane Just-Insane marked this pull request as ready for review March 25, 2026 03:52
Copy link
Copy Markdown
Contributor

@dozro dozro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changes in the code lgtm

@7w1 7w1 added this pull request to the merge queue Mar 25, 2026
Merged via the queue into SableClient:dev with commit 7b76e27 Mar 25, 2026
9 checks passed
@Just-Insane Just-Insane deleted the fix/sentry-scrub-opaque-matrix-ids branch March 27, 2026 16:31
github-merge-queue bot pushed a commit that referenced this pull request Mar 28, 2026
> [!IMPORTANT]
> Merging this PR will create a new release.

## Features

* Add ability to click on usernames in member and state events to view
user info ([#536](#536) by
@thundertheidiot)
* Add black theme ([#437](#437)
by @Elec3137)
* added a limited compatibility with `pk;member` commands
([#550](#550) by @dozro)
* Add /location sharing command, and a /sharemylocation command.
([#509](#509) by @nushea)
* added option to use shorthands to send a message with a Persona, for
example `✨:test` ([#550](#550)
by @dozro)
* Add quick reply keybinds by using <kbd>ctrl</kbd>+<kbd>up</kbd> /
<kbd>ctrl</kbd>+<kbd>down</kbd> you can now cycle through the message
you are replying to with keybinds
([#524](#524) by @CodeF53)
* Adds a `/html` command to send HTML messages
([#560](#560) by @Vespe-r)
* Add room abbreviations with hover tooltips: moderators define
term/definition pairs in room settings; matching terms are highlighted
in messages. ([#514](#514) by
@Just-Insane)
* Add support for timestamps, playlists and youtube music links for the
youtube embeds ([#534](#534) by
@thundertheidiot)
* Add settings sync across devices via Matrix account data, with JSON
export/import ([#515](#515) by
@Just-Insane)

## Fixes

* Add detailed error messages to forwarding failures.
([#532](#532) by @7w1)
* Cap unread badge numbers at `1k+`, and something extra :)
([#484](#484) by @hazre)
* Fix scroll-to-bottom after room navigation, timeline pagination
reliability, and URL preview deduplication.
([#529](#529) by @Just-Insane)
* Fixes the most recent pmp message in encrypted rooms not consistently
rendering the pmp and not grouping with previous pmps.
([#526](#526) by @7w1)
* fixed sending sticker and attachments while having a persona selected
([#525](#525) by @dozro)
* Fix push notifications missing sender/room avatar and showing stale
display names when using event_id_only push format.
([#551](#551) by @Just-Insane)
* Sanitize formatted reply previews before rendering to prevent unsafe
HTML from being parsed in reply snippets.
([#569](#569) by @Just-Insane)
* Fix broken link to Sliding Sync known issues — now points to
#39 instead of the old repository.
([#519](#519) by @Just-Insane)
* Fix service worker authenticated media requests returning 401 errors
after SW restart or when session data is missing/stale.
([#516](#516) by @Just-Insane)
* rephrased the command describtion for `/usepmp` and made `/usepmp
reset` actually reset the room association of the pmp
([#550](#550) by @dozro)
* Fix confusing ui with `Client Side Embeds in Encrypted Rooms` setting
([#535](#535) by
@thundertheidiot)
* fix forwarding metadata by removing the `null` value
([#540](#540) by @dozro)
* fix forwarding issue for users on synapse homeservers, by removing the
relation ([#558](#558) by
@dozro)
* fixed the syntax issues regarding `/addpmp` and `usepmp` (note that
the syntax for `/usepmp` has changed)
([#550](#550) by @dozro)
* fix the display of jumbo emojis on messages sent with a persona
([#530](#530) by @dozro)
* Fix sidebar notification badge positioning so unread and unverified
counts align consistently.
([#484](#484) by @hazre)
* Use the browser's native compact number formatting for room and member
counts. ([#484](#484) by
@hazre)
* fix(sentry): scrub percent-encoded Matrix IDs and opaque base64url
tokens from Sentry URLs
([#531](#531) by @Just-Insane)

## Notes

* new/changed bios will now also be saved in the format MSC4440 expects
([#559](#559) by @dozro)
* moved the setting for filtering pronouns by language from experimental
to the appearance setting
([#521](#521) by @dozro)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants