Skip to content

fix(starlette): Don't overwrite user set during request in AuthenticationMiddleware - #6760

Merged
ericapisani merged 1 commit into
masterfrom
py-2596-do-not-overwrite-user-starlette
Jul 7, 2026
Merged

fix(starlette): Don't overwrite user set during request in AuthenticationMiddleware#6760
ericapisani merged 1 commit into
masterfrom
py-2596-do-not-overwrite-user-starlette

Conversation

@ericapisani

Copy link
Copy Markdown
Member

The AuthenticationMiddleware patch added the request-derived user after
calling the wrapped handler, silently overwriting any user set by the
application during the request (e.g. via sentry_sdk.set_user). Add
the user before invoking the handler so app-set user data takes
precedence.

Fixes PY-2596
Fixes #6756

…tionMiddleware

The AuthenticationMiddleware patch added the request-derived user after
calling the wrapped handler, silently overwriting any user set by the
application during the request (e.g. via `sentry_sdk.set_user`). Add
the user before invoking the handler so app-set user data takes
precedence.

Fixes PY-2596
Fixes #6756
@linear-code

linear-code Bot commented Jul 6, 2026

Copy link
Copy Markdown
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊

90045 passed | ⏭️ 6302 skipped | Total: 96347 | Pass Rate: 93.46% | Execution Time: 311m 12s

📊 Comparison with Base Branch

Metric Change
Total Tests 📈 +11
Passed Tests 📈 +11
Failed Tests
Skipped Tests

All tests are passing successfully.

✅ Patch coverage is 100.00%. Project has 2437 uncovered lines.
✅ Project coverage is 89.77%. Comparing base (base) to head (head).

Coverage diff
@@            Coverage Diff             @@
##          main       #PR       +/-##
==========================================
+ Coverage    89.76%    89.77%    +0.01%
==========================================
  Files          192       192         —
  Lines        23823     23823         —
  Branches      8226      8226         —
==========================================
+ Hits         21384     21386        +2
- Misses        2439      2437        -2
- Partials      1351      1348        -3

Generated by Codecov Action

@ericapisani
ericapisani marked this pull request as ready for review July 6, 2026 14:58
@ericapisani
ericapisani requested a review from a team as a code owner July 6, 2026 14:58
Comment thread sentry_sdk/integrations/starlette.py
@ericapisani
ericapisani merged commit e2dd162 into master Jul 7, 2026
271 of 274 checks passed
@ericapisani
ericapisani deleted the py-2596-do-not-overwrite-user-starlette branch July 7, 2026 11:58
mgaligniana pushed a commit to mgaligniana/sentry-python that referenced this pull request Aug 9, 2026
…tionMiddleware (getsentry#6760)

The AuthenticationMiddleware patch added the request-derived user after
calling the wrapped handler, silently overwriting any user set by the
application during the request (e.g. via `sentry_sdk.set_user`). Add
the user before invoking the handler so app-set user data takes
precedence.

Fixes PY-2596
Fixes getsentry#6756
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants