Files
supabase/pnpm-workspace.yaml
ad181489b1 feat(studio): adopt @sentry/tanstackstart-react server instrumentation on the TanStack build (#47724)
Stacked on #47666 (base `alaister/tanstack-sentry-init`; retarget to
`master` when that merges). **Supersedes #47721** (the manual
`@sentry/node` wrapper). Client stays on #47666's `@sentry/react` setup.

Adopts the official `@sentry/tanstackstart-react` SDK **on the server
only**, after a spike (#47723) evaluating the full unified client+server
SDK. The spike found the SDK's **browser**
`tanstackRouterBrowserTracingIntegration` is a broken no-op stub at
10.59.0/10.64.0 — so the client stays on `@sentry/react` (whose
equivalent integration is a real, working implementation, already
shipped in #47666). The **server** exports, however, are a clear upgrade
and slot in cleanly.

### What this adds (server-side, TanStack build only)
- **`instrument.server.mjs`** — `Sentry.init` from
`@sentry/tanstackstart-react`, mirroring `sentry.server.config.ts` +
`release: VERCEL_GIT_COMMIT_SHA`.
- **`start.ts`** — `sentryGlobalRequestMiddleware` +
`sentryGlobalFunctionMiddleware` at the front of the existing
`createStart(...)` middleware. **This is the win**: it captures request-
and server-function errors *including the ones swallowed into 500s* —
the exact class the manual wrapper (and the Next server SDK) miss.
- **`api/server.js` / `scripts/serve.js`** — gated
(`STUDIO_FRAMEWORK==='tanstack'`) instrument init +
`wrapFetchWithSentry` on the handler.
- **`vite.config.ts`** — `sentryTanstackStart({ …,
autoInstrumentMiddleware: false })` as the last plugin: source-map
upload + release injection (skips gracefully without an auth token).
Middleware is wired explicitly rather than via the plugin's
string-rewrite.

### Guarantees
- **Client untouched** — the `@sentry/nextjs`→`@sentry/react` alias and
#47666's client init are unchanged.
- **Next untouched** — `instrumentation.ts` / `sentry.server.config.ts`
etc. stay as-is; all new code is TanStack-gated.
- **No server SDK in the client bundle** — verified after build: no
`@sentry/node` / server middleware / `wrapFetchWithSentry` in
`dist/client/assets` (`start.ts`'s server import is tree-shaken out).

### Verified
TanStack build exit 0 (past `assertNoChunkCycles`), post-build server
boot served `/api/get-utc-time → 200`, `tsc --noEmit` clean,
prettier/eslint clean. Node smoke: no-DSN init is a clean no-op; wrapped
handler returns 200.

### To test (deploy with a server DSN)
Throw a server error from an `/api/*` route (or a `/_serverFn/*`) —
including one that gets turned into a 500 without rethrowing — and
confirm a server event in Sentry with `release` = the deploy SHA.
Compared to #47721, the swallowed-500 case should now be captured via
the middleware.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added Sentry integration for the Studio app’s TanStack Start runtime,
including request and server-function instrumentation.
* Wrapped server request handling to capture errors reliably, with
tracing enabled.
* Updated build tooling to conditionally upload source maps when
credentials are present.

* **Bug Fixes**
* Improved resilience by safely falling back to a no-op Sentry setup if
instrumentation cannot be loaded.
* Ensured existing request protection remains enabled while adding
observability middleware.

* **Chores / Config**
* Added `SKIP_ASSET_UPLOAD` to the build environment list to control
cache/build behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-07-10 16:52:07 +08:00

111 lines
2.8 KiB
YAML

packages:
- apps/*
- packages/*
- blocks/*
- e2e/*
blockExoticSubdeps: true
catalog:
'@monaco-editor/react': ^4.7.0
'@sentry/nextjs': ^10.59.0
'@sentry/tanstackstart-react': ^10.59.0
'@supabase/auth-js': 2.110.1
'@supabase/postgrest-js': 2.110.1
'@supabase/realtime-js': 2.110.1
'@supabase/ssr': 0.10.2
'@supabase/supabase-js': 2.110.1
'@tanstack/react-router': ^1.169.2
'@tanstack/react-start': ^1.167.65
'@tanstack/react-table': ^8.21.3
'@types/node': ^22.0.0
'@types/react': ^19.2.14
'@types/react-dom': ^19.2.3
# TypeScript 7 has no programmatic API until 7.1, so `typescript` stays aliased
# to the 6.0-API compat package for tools that import it (typescript-eslint,
# Next.js build typechecking), while `@typescript/native` provides the native
# TS 7 `tsc` binary used by typecheck scripts.
# https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/
'@typescript/native': npm:typescript@~7.0.2
'@vitejs/plugin-react': ^6.0.1
'@vitest/coverage-v8': ^4.1.4
'@vitest/ui': ^4.1.4
lodash: ^4.18.1
lodash-es: ^4.18.1
monaco-editor: 0.52.2
next: 16.2.6
next-themes: ^0.4.6
postcss: ^8.5.10
radix-ui: ^1.4.3
react: ^19.2.6
react-dom: ^19.2.6
recharts: ^2.15.4
tailwindcss: ^4.2.4
tsx: ^4.22.0
typescript: ~6.0.2
valtio: ^1.12.0
vite: ^8.0.16
vite-tsconfig-paths: ^6.1.1
vitest: ^4.1.4
zod: 3.25.76
ignoredBuiltDependencies:
- '@parcel/watcher'
- '@sentry/cli'
- contentlayer2
- core-js
- es5-ext
- esbuild
- libpg-query
- msw
- protobufjs
- sharp
minimumReleaseAge: 4320
minimumReleaseAgeExclude:
- '@ai-sdk/*'
- '@supabase/*'
- '@supabase-labs/*'
- typescript
- '@typescript/*'
# First-party, published from supabase-community/mdast-jsx.
- mdast-jsx
# The following are excluded to fix vulnerablities.
- react-use
onlyBuiltDependencies:
- node-pty
- supabase
overrides:
'@ardatan/relay-compiler>immutable': ^3.8.3
'monaco-editor': 'catalog:'
'@mapbox/node-pre-gyp>tar': ^7.5.11
'@sentry/webpack-plugin>uuid': ^11.1.1
'@usercentrics/cmp-browser-sdk>uuid': ^11.1.1
braintrust>esbuild: ^0.28.1
braintrust>uuid: ^11.1.1
cacache>tar: ^7.5.11
dompurify: ^3.3.2
express-rate-limit>ip-address: ^10.1.1
# Pin h3 v1 to a single version so the Nuxt registry example (vue-blocks)
# doesn't end up with two copies (1.15.10 + 1.15.11) and hit nominal
# H3Event type mismatches. v2 (h3@2) is intentionally left untouched.
'h3@1': 1.15.11
lodash: 'catalog:'
lodash-es: 'catalog:'
mdx-bundler>uuid: ^11.1.1
node-gyp>tar: ^7.5.11
nodemailer: ^7.0.11
postcss: 'catalog:'
qs: ^6.15.2
refractor>prismjs: ^1.30.0
supabase>tar: ^7.5.11
tmp: ^0.2.7
vite>esbuild: ^0.28.1
webpack: ^5.104.1
patchedDependencies:
react-data-grid: patches/react-data-grid.patch