Skip to content

fix(starlette): Stop eagerly consuming request bodies for streamed spans - #6282

Merged
alexander-alderman-webb merged 22 commits into
masterfrom
webb/starlette/request-body-async
Jun 9, 2026
Merged

fix(starlette): Stop eagerly consuming request bodies for streamed spans#6282
alexander-alderman-webb merged 22 commits into
masterfrom
webb/starlette/request-body-async

Conversation

@alexander-alderman-webb

@alexander-alderman-webb alexander-alderman-webb commented May 18, 2026

Copy link
Copy Markdown
Contributor

Note: Depends on #6269

Description

Only attach cached request bodies to streamed spans to avoid relying on an eagerly consumed request body. Use the _json and _form attributes instead of json() and form() accessors to ensure that the request body is not consumed by the SDK.

Note: by using _json and _form directly we can no longer distinguish between raw data payloads and payloads that were not cached on the Request object. The attribute is therefore omitted if the request body is not cached, since the endpoint may not have accessed it.

The integration can still cause application hangs if middleware or handlers deprive the receive() callable instead of using Starlette accessors. Reliance on the overly ambitious request body access is only eliminated for streamed spans (and only persists for errors with the change).

  • Remove test_request_body_data_does_not_scrub_pii_span_streaming() since test_formdata_request_body() already asserts that fields in the request body are not scrubbed.
  • Remove test_request_body_data_annotated_value_top_level_span_streaming() because the attribute is no longer set if the request body is not JSON or FormData.

Issues

Reminders

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants