Skip to content

fix(appsec): API Security #648

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 3 commits into
base: main
Choose a base branch
from

Conversation

florentinl
Copy link
Contributor

@florentinl florentinl commented Aug 14, 2025

What does this PR do?

Enable API Security by default.

In case of an HTTP event:

  • Add the path to the url. (http.url_details.path is a backend tag that should not be set by the tracer. Currently, it always ends up having the value / overwritten from the http.url having no path)
  • Add the span.kind: server tag
  • Set the span resource {method} {route}. The same as for all instrumented frameworks.

Motivation

I am trying to make Appsec API security work with lambda inside the tracer. To do this, the backend must recognize that the service represented by the lambda has an endpoint.

Testing Guidelines

Updating existing tests

Additional Notes

Changing the resource name might break other parts of the lambda integration that I am not aware of. This is maybe a case where this should be changed in the backend.

Types of Changes

  • Bug fix
  • New feature
  • Breaking change
  • Misc (docs, refactoring, dependency upgrade, etc.)

Check all that apply

  • This PR's description is comprehensive
  • This PR contains breaking changes that are documented in the description
  • This PR introduces new APIs or parameters that are documented and unlikely to change in the foreseeable future
  • This PR impacts documentation, and it has been updated (or a ticket has been logged)
  • This PR's changes are covered by the automated tests
  • This PR collects user input/sensitive content into Datadog
  • This PR passes the integration tests (ask a Datadog member to run the tests)

@florentinl florentinl force-pushed the florentinl/APPSEC-58661/add-path-to-url branch 3 times, most recently from 30ce6b3 to 2c126e8 Compare August 18, 2025 08:16
@florentinl florentinl changed the title fix(http): append path to the url fix(appsec): provide URL to API Security Aug 18, 2025
@florentinl florentinl marked this pull request as ready for review August 18, 2025 14:41
@florentinl florentinl requested review from a team as code owners August 18, 2025 14:41
@DataDog DataDog deleted a comment from dd-devflow-routing-codex bot Aug 18, 2025
@DataDog DataDog deleted a comment from dd-devflow-routing-codex bot Aug 18, 2025
@florentinl florentinl force-pushed the florentinl/APPSEC-58661/add-path-to-url branch from 2c126e8 to 6fa020a Compare August 18, 2025 15:03
@florentinl florentinl marked this pull request as draft August 22, 2025 07:38
@florentinl florentinl force-pushed the florentinl/APPSEC-58661/add-path-to-url branch from 6fa020a to c6dd22d Compare August 22, 2025 07:55
@florentinl florentinl changed the title fix(appsec): provide URL to API Security fix(appsec): API Security Aug 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant