Conversation
Prerendered pages had the `sentry-trace` and `baggage` meta tags baked in at build time, so every visitor continued the same trace with a frozen sampling decision. SvelteKit prerenders in a worker that inherits `process.env`, so `sentrySvelteKit()` now sets `_SENTRY_SVELTEKIT_BUILDING` during `vite build` and `sentryHandle` skips the meta tags when it (or Kit's own `SVELTEKIT_FORK`) is set. The fetch proxy script and error capture are unchanged. Closes getsentry#15267
andasan
requested review from
chargome and
nicohrubec
and removed request for
a team
September 28, 2026 01:28
| } | ||
|
|
||
| /** | ||
| * We only need to inject the fetch proxy script for SvelteKit versions < 2.16.0. |
Contributor
There was a problem hiding this comment.
Bug: The check for the undocumented SVELTEKIT_FORK environment variable can incorrectly return true in production on some platforms (e.g., Netlify), silently disabling trace meta tag injection for SSR pages.
Severity: MEDIUM
Suggested Fix
Avoid relying on the undocumented SVELTEKIT_FORK environment variable as it can be present in production environments. Instead, find a more reliable, documented way to detect prerendering that isn't ambiguous with production environments. Alternatively, add more context checks, such as verifying if the code is running in a worker_thread, to ensure it's truly a prerendering worker and not a production server.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/sveltekit/src/server-common/handle.ts#L106
Potential issue: The function `isSvelteKitBuilding` checks for the
`_SENTRY_SVELTEKIT_BUILDING` or `SVELTEKIT_FORK` environment variables to determine if
it's a build-time prerendering phase. However, the undocumented `SVELTEKIT_FORK`
variable can also be present in production runtime environments on certain hosting
platforms like Netlify. When this occurs during a standard server-side render (SSR)
request in production, `isSvelteKitBuilding` will incorrectly return `true`. This
prevents the injection of Sentry trace meta tags into the HTML, which silently breaks
distributed tracing functionality for all dynamically rendered pages on affected
platforms.
Did we get this right? 👍 / 👎 to inform future reviews.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Repro: https://github.com/andasan/sentry-sveltekit-prerender-repro
When a page is prerendered,
sentryHandleinjects thesentry-traceandbaggagemeta tags atbuild time, so every visitor continues the same build-time trace and the sampling decision is
frozen in the HTML. This skips the meta tags while SvelteKit builds the app. The fetch proxy
script, error capture and spans are unchanged.
The SDK can't use
buildingfrom$app/environment(it's loaded from node_modules at runtime), andmatching
event.url.originagainstprerender.originbreaks when people set that to their realdomain. SvelteKit prerenders in a
worker_threadthat gets a copy ofprocess.env, so:sentrySvelteKit()sets_SENTRY_SVELTEKIT_BUILDINGduringvite buildsentryHandlealso checksSVELTEKIT_FORK, which Kit sets on that worker itself (2.x and 3.0.0-next),so apps without our Vite plugin are covered too
Question:
SVELTEKIT_FORKisn't a documented Kit API. Would you rather keep only our own flag (whichmeans the fix needs the Vite plugin), or keep both?
Tested with unit tests for both env vars plus the plugin, and an e2e test in
sveltekit-2-staticthatchecks a prerendered page has no meta tags while an SSR page still does.
yarn lint) & (yarn test).Closes #15267
Note
Medium Risk
Changes when trace propagation meta tags are injected in
sentryHandle, but scope is limited to build/prerender via env detection; runtime SSR tracing behavior is preserved.Overview
Fixes prerendered SvelteKit HTML shipping a single build-time
sentry-trace/baggagemeta pair to every visitor by skipping those tags while the app is built or prerendered.addSentryCodeToPagenow omits trace meta tags whenisSvelteKitBuilding()sees_SENTRY_SVELTEKIT_BUILDING(newsentry-sveltekit-build-flagVite plugin duringvite build) or SvelteKit’sSVELTEKIT_FORKin the prerender worker. SSR at request time is unchanged—meta tags still inject on live responses. Fetch proxy script behavior during build is unchanged.Coverage: unit tests for both env signals and the Vite plugin, plus an e2e route with
prerender = trueasserting no meta tags vs the SSR home page.Reviewed by Cursor Bugbot for commit 1c5ffdb. Bugbot is set up for automated code reviews on this repo. Configure here.