TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-tools · module folder · Try on Runboat
Module version
1.0.0
Category
Extra Tools
Folder size
9.27 MB
License
AGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-tools
Last tracking update
2026-10-08 19:23:09
Authors
Odoo Community Association (OCA), Ledoent
Maintainers
Odoo Community Association (OCA), Ledoent
Committers
Don Kendall, OCA-git-bot, oca-ci
Odoo dependencies
odoo/odoo:
- web
Python dependencies
None
System dependencies
None
Required by
None
Description
Capture uncaught JS errors and unhandled promise rejections in the Odoo web
client to Sentry, with optional Performance Monitoring (BrowserTracing),
Session Replay, Browser CPU Profiling, and Console-log capture tiers
behind explicit opt-in toggles.

The Sentry browser SDK ships **vendored inside the module** — no external
CDN call, air-gapped friendly out of the box.

**Standalone:** works on its own. Reads DSN / release / environment from
the `sentry_*` options in `odoo.conf`. Captures browser-side errors only.

**Better together with `sentry`:** install alongside the server-side
[`sentry`](../sentry) module to cluster client and server errors for the
same user / release / environment into one Sentry issue. Both modules
share the same `sentry_*` config options by convention — fill them in
once and client + server events land in the same Sentry project.

Each tier above Tier 0 is **off by default** and surfaces an in-form
warning about its perf cost when enabled. Sample rates are sliders so
admins can dial behaviour without a server restart. Individual users can
opt out of session replay via their own preferences page.

Code Analysis info_outline

Views touched (3)
XML IDNameModelTypeStatus
res_config_settings_view_form res.config.settings.view.form.inherit.sentry_client res.config.settings form Inherits base.res_config_settings_view_form
view_users_form_admin_inherit res.users.form.inherit.sentry_client res.users form Inherits base.view_users_form
view_users_form_preferences_inherit res.users.preferences.form.inherit.sentry_client res.users form Inherits base.view_users_form_simple_modif
HTTP endpoints (1)
Route(s)HandlerAuthTypeMethodsFlags
/sentry_client/config.json SentryClientController.config public http GET csrf off sudo
Models touched (2)

New fields (15)
  • sentry_client_browser_dsn Char
    config_parameter='sentry_client.browser_dsn' help="Public Sentry DSN for the browser project. Leave blank to reuse the `sentry_dsn` option from odoo.conf. Sentry recommends a separate project per platform (Python vs. JavaScript-Browser); set this to that project's DSN. Browser DSNs are public by design and safe to expose to end users." string='Browser DSN'
  • sentry_client_cdn_base Char
    config_parameter='sentry_client.cdn_base' default='/sentry_client/static/lib/sentry' help='Where the Sentry browser SDK bundle is loaded from. Defaults to the bundle vendored inside this module so no external network call is needed. Override to point at a mirror or back at the public CDN at https://browser.sentry-cdn.com.' string='Sentry SDK source URL'
  • sentry_client_cdn_version Char
    config_parameter='sentry_client.cdn_version' default='10.53.1' string='Sentry SDK version'
  • sentry_client_enabled Boolean
    config_parameter='sentry_client.enabled' help='When enabled and a DSN is configured (either above or via the `sentry_dsn` option in odoo.conf), the Sentry browser SDK is loaded into the Odoo web client and captures uncaught JS errors and unhandled promise rejections.' string='Enable browser error reporting'
  • sentry_client_environment Char
    config_parameter='sentry_client.environment' help="Tags every browser event with this environment (e.g. 'production-web', 'staging-web'). Leave blank to inherit from the `sentry_*` options in odoo.conf." string='Environment tag'
  • sentry_client_release Char
    config_parameter='sentry_client.release' help='Tags every browser event with this release identifier (e.g. the asset-bundle hash or a deploy SHA). Leave blank to inherit from the `sentry_*` options in odoo.conf.' string='Release tag'
  • sentry_client_tier1_traces_sample_rate Float
    config_parameter='sentry_client.tier1_traces_sample_rate' default=0.0 help='Fraction of requests to record performance traces for. 0.0 = none, 1.0 = all. Recommended in production: 0.05 or below.' string='Traces sample rate'
  • sentry_client_tier1_tracing_enabled Boolean
    config_parameter='sentry_client.tier1_tracing_enabled' string='Enable performance monitoring (Tier 1)'
  • sentry_client_tier2_error_sample_rate Float
    config_parameter='sentry_client.tier2_error_sample_rate' default=1.0 help='Fraction of sessions that hit an error to record. 1.0 means every errored session is captured for replay.' string='On-error session sample rate'
  • sentry_client_tier2_replay_enabled Boolean
    config_parameter='sentry_client.tier2_replay_enabled' string='Enable session replay (Tier 2)'
  • sentry_client_tier2_session_sample_rate Float
    config_parameter='sentry_client.tier2_session_sample_rate' default=0.0 help='Fraction of HEALTHY user sessions to record. Keep at 0.0 unless you have a specific UX debugging need.' string='Healthy-session sample rate'
  • sentry_client_tier3_feedback_enabled Boolean
    config_parameter='sentry_client.tier3_feedback_enabled' string='Enable user feedback widget'
  • sentry_client_tier3_logs_enabled Boolean
    config_parameter='sentry_client.tier3_logs_enabled' string='Capture console logs'
  • sentry_client_tier3_profiles_sample_rate Float
    config_parameter='sentry_client.tier3_profiles_sample_rate' default=0.0 help='Fraction of traced transactions for which to also capture a browser CPU profile. 0.0 = none, 1.0 = all. Recommended in production: 0.05 or below.' string='Profiles sample rate'
  • sentry_client_tier3_profiling_enabled Boolean
    config_parameter='sentry_client.tier3_profiling_enabled' help='Captures JS Self-Profiling samples for traced transactions. Requires the page to be served with a `Document-Policy: js-profiling` HTTP header — without it the integration registers but never collects samples. See CONFIGURE.' string='Enable browser CPU profiling'
Public methods (0)

No public methods.

New fields (1)
  • sentry_client_replay_optout Boolean
    help='Sentry session replay records DOM changes, console activity, and network requests for any session that hits an error. Enable this to keep that recording off for your own sessions, regardless of the database-wide Tier 2 toggle. Server-wide error capture (Tier 0) is unaffected.' string='Disable Sentry session replay'
Public methods (2)
  • SELF_READABLE_FIELDS(self)
    @property
  • SELF_WRITEABLE_FIELDS(self)
    @property