Skip to content

fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel route - #24617

Merged
Lms24 merged 1 commit into
v10from
backport/v10-tanstackstart-tunnel-route-non-post
Sep 23, 2026
Merged

Lms24 merged 1 commit into
v10from
backport/v10-tanstackstart-tunnel-route-non-post

Conversation

@Lms24

@Lms24 Lms24 commented Sep 23, 2026

Copy link
Copy Markdown
Member

Backport of: #24615

@Lms24
Lms24 marked this pull request as ready for review September 23, 2026 07:51
@Lms24
Lms24 requested a review from a team as a code owner September 23, 2026 07:51
@Lms24
Lms24 requested review from mydea and s1gr1d and removed request for a team September 23, 2026 07:51
@Lms24 Lms24 self-assigned this Sep 23, 2026
@github-actions

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 28.23 kB added added
@sentry/browser - with treeshaking flags 26.66 kB added added
@sentry/browser (incl. Tracing) 47.12 kB added added
@sentry/browser (incl. Tracing + Span Streaming) 48.91 kB added added
@sentry/browser (incl. Tracing, Profiling) 51.89 kB added added
@sentry/browser (incl. Tracing, Replay) 86.4 kB added added
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 76.06 kB added added
@sentry/browser (incl. Tracing, Replay with Canvas) 91.13 kB added added
@sentry/browser (incl. Tracing, Replay, Feedback) 103.76 kB added added
@sentry/browser (incl. Feedback) 45.39 kB added added
@sentry/browser (incl. sendFeedback) 33.03 kB added added
@sentry/browser (incl. FeedbackAsync) 38.16 kB added added
@sentry/browser (incl. Metrics) 29.31 kB added added
@sentry/browser (incl. Logs) 29.54 kB added added
@sentry/browser (incl. Metrics & Logs) 30.23 kB added added
@sentry/react 30.02 kB added added
@sentry/react (incl. Tracing) 49.43 kB added added
@sentry/vue 33.66 kB added added
@sentry/vue (incl. Tracing) 49.13 kB added added
@sentry/svelte 28.25 kB added added
CDN Bundle 30.58 kB added added
CDN Bundle (incl. Tracing) 49.07 kB added added
CDN Bundle (incl. Logs, Metrics) 32.16 kB added added
CDN Bundle (incl. Tracing, Logs, Metrics) 50.39 kB added added
CDN Bundle (incl. Replay, Logs, Metrics) 71.5 kB added added
CDN Bundle (incl. Tracing, Replay) 86.67 kB added added
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 87.93 kB added added
CDN Bundle (incl. Tracing, Replay, Feedback) 92.48 kB added added
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 93.75 kB added added
CDN Bundle - uncompressed 90.96 kB added added
CDN Bundle (incl. Tracing) - uncompressed 147.96 kB added added
CDN Bundle (incl. Logs, Metrics) - uncompressed 95.67 kB added added
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 151.94 kB added added
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 220.63 kB added added
CDN Bundle (incl. Tracing, Replay) - uncompressed 267.39 kB added added
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 271.35 kB added added
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 281.09 kB added added
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 285.04 kB added added
@sentry/nextjs (client) 51.96 kB added added
@sentry/sveltekit (client) 47.57 kB added added
@sentry/core/server 81.14 kB added added
@sentry/core/browser 67.27 kB added added
@sentry/node-core 63.84 kB added added
@sentry/node 126.55 kB added added
@sentry/node (incl. diagnostics channel injection) 170.69 kB added added
@sentry/node/import (ESM hook with diagnostics-channel injection) 166 B added added
@sentry/node/light 51.95 kB added added
@sentry/node - without tracing 75.61 kB added added
@sentry/aws-serverless 84.79 kB added added
@sentry/cloudflare (withSentry) - minified 204.66 kB added added
@sentry/cloudflare (withSentry) 504.61 kB added added

@Lms24
Lms24 merged commit f01ca30 into v10 Sep 23, 2026
46 checks passed
@Lms24
Lms24 deleted the backport/v10-tanstackstart-tunnel-route-non-post branch September 23, 2026 08:39
brandhaug added a commit to brandhaug/b2b-saas-starter that referenced this pull request Sep 27, 2026
## pnpm-workspace.yaml (default)

## Dependency Updates

| Package | From | To | Type |
| --- | --- | --- | --- |
| `@sentry/cloudflare` | 10.75.0 | 11.0.0 | major |
| `@sentry/react` | 10.75.0 | 11.0.0 | major |

## Release Notes

<details>
<summary><b>@<!---->sentry/cloudflare</b> (10.75.0 → 11.0.0) — 4
releases</summary>

<details>
<summary><b>11.0.0</b></summary>

Version `11.0.0` marks a major release of the Sentry JavaScript SDKs
containing breaking changes.
The goal of this release is to be better compatible with OpenTelemetry,
make our integrations work across Node.js, Cloudflare, Bun and Deno
through run-time and build-time instrumentation, and make span streaming
and more permissive data collection the default.

### How To Upgrade

Please carefully read through the migration guide in the Sentry docs on
how to upgrade from version 10 to version 11. Make sure to select your
specific platform/framework in the top left corner:
https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/

A comprehensive migration guide outlining all changes can be found
within the Sentry JavaScript SDK Repository:
https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md

### Breaking Changes

#### All SDKs

- feat: Remove support for initialising via `--require`
([#22513](getsentry/sentry-javascript#22513))
- feat!: Rename deprecated `http.*` span attributes
([#23574](getsentry/sentry-javascript#23574))
- feat!: Rename deprecated `net.` span attributes
([#23301](getsentry/sentry-javascript#23301))
- feat!: Replace `skipOpenTelemetrySetup` with
`enableOpenTelemetrySetup`
([#23199](getsentry/sentry-javascript#23199))
- feat!: Replace the deprecated `http.target` span attribute
([#23575](getsentry/sentry-javascript#23575))
- feat!: Require Node `>=20.19.0` as minimum supported version
([#22558](getsentry/sentry-javascript#22558))
- feat!: Use `handler` span op for terminal request handlers
([#22871](getsentry/sentry-javascript#22871))
- feat!: Use `middleware` span op for web-server middleware
([#22852](getsentry/sentry-javascript#22852))
- feat(frameworks)!: Use `function` op for framework functions
([#23047](https://github.com/getse

…[full
notes](https://github.com/getsentry/sentry-javascript/releases/tag/11.0.0)

</details>

<details>
<summary><b>10.75.3</b></summary>

- fix(v10/tanstackstart-react): Reject non-POST requests to the managed
tunnel route
([#24617](getsentry/sentry-javascript#24617))

<details>
  <summary><strong>Internal Changes</strong></summary>

- chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3
([#24646](getsentry/sentry-javascript#24646))
- chore(v10/publish): Tag all packages as v10
([#24619](getsentry/sentry-javascript#24619))

</details>

## Bundle size 📦 

| Path | Size |
|
--------------------------------------------------------------------------
| ----------------- |
| @<!---->sentry/browser | 27.56 KB |
| @<!---->sentry/browser - with treeshaking flags | 26.04 KB |
| @<!---->sentry/browser (incl. Tracing) | 46.02 KB |
| @<!---->sentry/browser (incl. Tracing + Span Streaming) | 47.77 KB |
| @<!---->sentry/browser (incl. Tracing, Profiling) | 50.67 KB |
| @<!---->sentry/browser (incl. Tracing, Replay) | 84.38 KB |
| @<!---->sentry/browser (incl. Tracing, Replay) - with treeshaking
flags | 74.28 KB |
| @<!---->sentry/browser (incl. Tracing, Replay with Canvas) | 89 KB |
| @<!---->sentry/browser (incl. Tracing, Replay, Feedback) | 101.33 KB |
| @<!---->sentry/browser (incl. Feedback) | 44.33 KB |
| @<!---->sentry/browser (incl. sendFeedback) | 32.25 KB |
| @<!---->sentry/browser (incl. FeedbackAsync) | 37.27 KB |
| @<!---->sentry/browser (incl. Metrics) | 28.63 KB |
| @<!---->sentry/browser (incl. Logs) | 28.84 KB |
| @<!---->sentry/bro

…[full
notes](https://github.com/getsentry/sentry-javascript/releases/tag/10.75.3)

</details>

<p><i>…and 2 more release(s) not shown</i></p>

</details>

<details>
<summary><b>@<!---->sentry/react</b> (10.75.0 → 11.0.0) — 4
releases</summary>

<details>
<summary><b>11.0.0</b></summary>

Version `11.0.0` marks a major release of the Sentry JavaScript SDKs
containing breaking changes.
The goal of this release is to be better compatible with OpenTelemetry,
make our integrations work across Node.js, Cloudflare, Bun and Deno
through run-time and build-time instrumentation, and make span streaming
and more permissive data collection the default.

### How To Upgrade

Please carefully read through the migration guide in the Sentry docs on
how to upgrade from version 10 to version 11. Make sure to select your
specific platform/framework in the top left corner:
https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/

A comprehensive migration guide outlining all changes can be found
within the Sentry JavaScript SDK Repository:
https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md

### Breaking Changes

#### All SDKs

- feat: Remove support for initialising via `--require`
([#22513](getsentry/sentry-javascript#22513))
- feat!: Rename deprecated `http.*` span attributes
([#23574](getsentry/sentry-javascript#23574))
- feat!: Rename deprecated `net.` span attributes
([#23301](getsentry/sentry-javascript#23301))
- feat!: Replace `skipOpenTelemetrySetup` with
`enableOpenTelemetrySetup`
([#23199](getsentry/sentry-javascript#23199))
- feat!: Replace the deprecated `http.target` span attribute
([#23575](getsentry/sentry-javascript#23575))
- feat!: Require Node `>=20.19.0` as minimum supported version
([#22558](getsentry/sentry-javascript#22558))
- feat!: Use `handler` span op for terminal request handlers
([#22871](getsentry/sentry-javascript#22871))
- feat!: Use `middleware` span op for web-server middleware
([#22852](getsentry/sentry-javascript#22852))
- feat(frameworks)!: Use `function` op for framework functions
([#23047](https://github.com/getse

…[full
notes](https://github.com/getsentry/sentry-javascript/releases/tag/11.0.0)

</details>

<details>
<summary><b>10.75.3</b></summary>

- fix(v10/tanstackstart-react): Reject non-POST requests to the managed
tunnel route
([#24617](getsentry/sentry-javascript#24617))

<details>
  <summary><strong>Internal Changes</strong></summary>

- chore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3
([#24646](getsentry/sentry-javascript#24646))
- chore(v10/publish): Tag all packages as v10
([#24619](getsentry/sentry-javascript#24619))

</details>

## Bundle size 📦 

| Path | Size |
|
--------------------------------------------------------------------------
| ----------------- |
| @<!---->sentry/browser | 27.56 KB |
| @<!---->sentry/browser - with treeshaking flags | 26.04 KB |
| @<!---->sentry/browser (incl. Tracing) | 46.02 KB |
| @<!---->sentry/browser (incl. Tracing + Span Streaming) | 47.77 KB |
| @<!---->sentry/browser (incl. Tracing, Profiling) | 50.67 KB |
| @<!---->sentry/browser (incl. Tracing, Replay) | 84.38 KB |
| @<!---->sentry/browser (incl. Tracing, Replay) - with treeshaking
flags | 74.28 KB |
| @<!---->sentry/browser (incl. Tracing, Replay with Canvas) | 89 KB |
| @<!---->sentry/browser (incl. Tracing, Replay, Feedback) | 101.33 KB |
| @<!---->sentry/browser (incl. Feedback) | 44.33 KB |
| @<!---->sentry/browser (incl. sendFeedback) | 32.25 KB |
| @<!---->sentry/browser (incl. FeedbackAsync) | 37.27 KB |
| @<!---->sentry/browser (incl. Metrics) | 28.63 KB |
| @<!---->sentry/browser (incl. Logs) | 28.84 KB |
| @<!---->sentry/bro

…[full
notes](https://github.com/getsentry/sentry-javascript/releases/tag/10.75.3)

</details>

<p><i>…and 2 more release(s) not shown</i></p>

</details>

---
*This PR was auto-generated by
[catalog-update-action](https://github.com/brandhaug/catalog-update-action).*

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants