Skip to content

fix(sveltekit): Skip trace meta tags when prerendering - #24777

Open
andasan wants to merge 1 commit into
getsentry:developfrom
andasan:fix/sveltekit-prerender-meta-tags
Open

andasan wants to merge 1 commit into
getsentry:developfrom
andasan:fix/sveltekit-prerender-meta-tags

Conversation

@andasan

@andasan andasan commented Sep 28, 2026 •

Copy link
Copy Markdown

Repro: https://github.com/andasan/sentry-sveltekit-prerender-repro

When a page is prerendered, sentryHandle injects the sentry-trace and baggage meta tags at
build time, so every visitor continues the same build-time trace and the sampling decision is
frozen in the HTML. This skips the meta tags while SvelteKit builds the app. The fetch proxy
script, error capture and spans are unchanged.

The SDK can't use building from $app/environment (it's loaded from node_modules at runtime), and
matching event.url.origin against prerender.origin breaks when people set that to their real
domain. SvelteKit prerenders in a worker_thread that gets a copy of process.env, so:

  • sentrySvelteKit() sets _SENTRY_SVELTEKIT_BUILDING during vite build
  • sentryHandle also checks SVELTEKIT_FORK, which Kit sets on that worker itself (2.x and 3.0.0-next),
    so apps without our Vite plugin are covered too

Question: SVELTEKIT_FORK isn't a documented Kit API. Would you rather keep only our own flag (which
means the fix needs the Vite plugin), or keep both?

Tested with unit tests for both env vars plus the plugin, and an e2e test in sveltekit-2-static that
checks a prerendered page has no meta tags while an SSR page still does.

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes #15267


Note

Medium Risk
Changes when trace propagation meta tags are injected in sentryHandle, but scope is limited to build/prerender via env detection; runtime SSR tracing behavior is preserved.

Overview
Fixes prerendered SvelteKit HTML shipping a single build-time sentry-trace / baggage meta pair to every visitor by skipping those tags while the app is built or prerendered.

addSentryCodeToPage now omits trace meta tags when isSvelteKitBuilding() sees _SENTRY_SVELTEKIT_BUILDING (new sentry-sveltekit-build-flag Vite plugin during vite build) or SvelteKit’s SVELTEKIT_FORK in the prerender worker. SSR at request time is unchanged—meta tags still inject on live responses. Fetch proxy script behavior during build is unchanged.

Coverage: unit tests for both env signals and the Vite plugin, plus an e2e route with prerender = true asserting no meta tags vs the SSR home page.

Reviewed by Cursor Bugbot for commit 1c5ffdb. Bugbot is set up for automated code reviews on this repo. Configure here.

Prerendered pages had the `sentry-trace` and `baggage` meta tags baked in at
build time, so every visitor continued the same trace with a frozen sampling
decision.

SvelteKit prerenders in a worker that inherits `process.env`, so
`sentrySvelteKit()` now sets `_SENTRY_SVELTEKIT_BUILDING` during `vite build`
and `sentryHandle` skips the meta tags when it (or Kit's own `SVELTEKIT_FORK`)
is set. The fetch proxy script and error capture are unchanged.

Closes getsentry#15267
@andasan
andasan requested a review from a team as a code owner September 28, 2026 01:28
@andasan
andasan requested review from chargome and nicohrubec and removed request for a team September 28, 2026 01:28
}

/**
* We only need to inject the fetch proxy script for SvelteKit versions < 2.16.0.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The check for the undocumented SVELTEKIT_FORK environment variable can incorrectly return true in production on some platforms (e.g., Netlify), silently disabling trace meta tag injection for SSR pages.
Severity: MEDIUM

Suggested Fix

Avoid relying on the undocumented SVELTEKIT_FORK environment variable as it can be present in production environments. Instead, find a more reliable, documented way to detect prerendering that isn't ambiguous with production environments. Alternatively, add more context checks, such as verifying if the code is running in a worker_thread, to ensure it's truly a prerendering worker and not a production server.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: packages/sveltekit/src/server-common/handle.ts#L106

Potential issue: The function `isSvelteKitBuilding` checks for the
`_SENTRY_SVELTEKIT_BUILDING` or `SVELTEKIT_FORK` environment variables to determine if
it's a build-time prerendering phase. However, the undocumented `SVELTEKIT_FORK`
variable can also be present in production runtime environments on certain hosting
platforms like Netlify. When this occurs during a standard server-side render (SSR)
request in production, `isSvelteKitBuilding` will incorrectly return `true`. This
prevents the injection of Sentry trace meta tags into the HTML, which silently breaks
distributed tracing functionality for all dynamically rendered pages on affected
platforms.

Did we get this right? 👍 / 👎 to inform future reviews.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[SvelteKit] Avoid injecting <meta> tags when prerendering page

1 participant