Skip to content

[appsec] Stripe business logic events#7138

Merged
simon-id merged 45 commits intomasterfrom
stripe_business_events
Feb 17, 2026
Merged

[appsec] Stripe business logic events#7138
simon-id merged 45 commits intomasterfrom
stripe_business_events

Conversation

@simon-id
Copy link
Copy Markdown
Member

@simon-id simon-id commented Dec 18, 2025

What does this PR do?

This PR adds instrumentation for the Stripe SDK, and sends payloads from a couple of methods to the AppSec WAF, that will in turn convert them into span tags for the backend to receive.

Motivation

These tags will be used by the WAF to detect endpoints that handle payments in the Endpoint Catalog, and will be useful for fraud detection and general security observability.

ST: DataDog/system-tests#6219

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Dec 18, 2025

Overall package size

Self size: 4.62 MB
Deduped: 5.46 MB
No deduping: 5.46 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | import-in-the-middle | 2.0.6 | 81.92 kB | 813.08 kB | | dc-polyfill | 0.1.10 | 26.73 kB | 26.73 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@simon-id simon-id self-assigned this Dec 18, 2025
@datadog-official
Copy link
Copy Markdown

datadog-official bot commented Dec 18, 2025

✅ Tests

🎉 All green!

❄️ No new flaky tests detected
🧪 All tests passed

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 0a6d94c | Docs | Datadog PR Page | Was this helpful? Give us feedback!

@codecov
Copy link
Copy Markdown

codecov bot commented Dec 18, 2025

Codecov Report

❌ Patch coverage is 98.43750% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 80.19%. Comparing base (8edb07d) to head (0a6d94c).
⚠️ Report is 2 commits behind head on master.

Files with missing lines Patch % Lines
packages/datadog-instrumentations/src/stripe.js 97.61% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #7138      +/-   ##
==========================================
+ Coverage   80.15%   80.19%   +0.04%     
==========================================
  Files         730      731       +1     
  Lines       31217    31281      +64     
==========================================
+ Hits        25023    25087      +64     
  Misses       6194     6194              
Flag Coverage Δ
aiguard-macos 38.99% <0.00%> (-0.11%) ⬇️
aiguard-ubuntu 39.12% <0.00%> (-0.11%) ⬇️
aiguard-windows 38.85% <0.00%> (-0.11%) ⬇️
apm-capabilities-tracing-macos 48.69% <0.00%> (-0.06%) ⬇️
apm-capabilities-tracing-ubuntu 48.73% <0.00%> (-0.05%) ⬇️
apm-capabilities-tracing-windows 48.42% <0.00%> (-0.01%) ⬇️
apm-integrations-child-process 38.56% <0.00%> (-0.11%) ⬇️
apm-integrations-couchbase-18 37.47% <0.00%> (+0.04%) ⬆️
apm-integrations-couchbase-eol 37.81% <0.00%> (-0.11%) ⬇️
apm-integrations-oracledb 38.00% <0.00%> (-0.10%) ⬇️
appsec-express 55.33% <27.27%> (-0.12%) ⬇️
appsec-fastify 51.95% <27.27%> (-0.11%) ⬇️
appsec-graphql 52.30% <27.27%> (-0.12%) ⬇️
appsec-kafka 44.57% <0.00%> (-0.09%) ⬇️
appsec-ldapjs 44.33% <0.00%> (-0.09%) ⬇️
appsec-lodash 44.01% <0.00%> (-0.09%) ⬇️
appsec-macos 58.39% <27.27%> (-0.12%) ⬇️
appsec-mongodb-core 49.25% <0.00%> (-0.09%) ⬇️
appsec-mongoose 49.94% <0.00%> (-0.08%) ⬇️
appsec-mysql 51.30% <27.27%> (-0.11%) ⬇️
appsec-node-serialize 43.52% <0.00%> (-0.09%) ⬇️
appsec-passport 48.05% <27.27%> (-0.13%) ⬇️
appsec-postgres 51.03% <27.27%> (-0.11%) ⬇️
appsec-sourcing 42.86% <0.00%> (-0.09%) ⬇️
appsec-template 43.69% <0.00%> (-0.09%) ⬇️
appsec-ubuntu 58.47% <27.27%> (-0.12%) ⬇️
appsec-windows 58.24% <27.27%> (-0.12%) ⬇️
instrumentations-instrumentation-bluebird 32.27% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-body-parser 40.79% <0.00%> (-0.10%) ⬇️
instrumentations-instrumentation-child_process 37.87% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-cookie-parser 34.49% <0.00%> (-0.10%) ⬇️
instrumentations-instrumentation-express 34.83% <0.00%> (-0.10%) ⬇️
instrumentations-instrumentation-express-mongo-sanitize 34.63% <0.00%> (-0.10%) ⬇️
instrumentations-instrumentation-express-session 40.41% <0.00%> (-0.10%) ⬇️
instrumentations-instrumentation-fs 31.87% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-generic-pool 30.18% <0.00%> (-0.01%) ⬇️
instrumentations-instrumentation-http 39.59% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-knex 32.27% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-mongoose 33.62% <0.00%> (-0.10%) ⬇️
instrumentations-instrumentation-multer 40.53% <0.00%> (-0.10%) ⬇️
instrumentations-instrumentation-mysql2 38.37% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-passport 44.34% <13.63%> (-0.15%) ⬇️
instrumentations-instrumentation-passport-http 43.99% <13.63%> (-0.15%) ⬇️
instrumentations-instrumentation-passport-local 44.55% <13.63%> (-0.15%) ⬇️
instrumentations-instrumentation-pg 37.78% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-promise 32.19% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-promise-js 32.20% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-q 32.24% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-url 32.16% <0.00%> (-0.11%) ⬇️
instrumentations-instrumentation-when 32.21% <0.00%> (-0.11%) ⬇️
llmobs-ai 41.40% <0.00%> (-0.10%) ⬇️
llmobs-anthropic 40.60% <0.00%> (-0.10%) ⬇️
llmobs-bedrock 39.49% <0.00%> (-0.09%) ⬇️
llmobs-google-genai 40.10% <0.00%> (-0.10%) ⬇️
llmobs-langchain 39.64% <0.00%> (-0.08%) ⬇️
llmobs-openai 44.44% <0.00%> (-0.10%) ⬇️
llmobs-vertex-ai 40.38% <0.00%> (-0.03%) ⬇️
platform-core 29.71% <ø> (ø)
platform-esbuild 32.89% <ø> (ø)
platform-instrumentations-misc 40.53% <ø> (ø)
platform-shimmer 36.14% <ø> (ø)
platform-unit-guardrails 31.27% <ø> (ø)
plugins-azure-event-hubs 24.02% <ø> (ø)
plugins-azure-service-bus 23.42% <ø> (ø)
plugins-bullmq 43.70% <0.00%> (-0.11%) ⬇️
plugins-cassandra 38.04% <0.00%> (-0.10%) ⬇️
plugins-cookie 25.08% <ø> (ø)
plugins-cookie-parser 24.87% <ø> (ø)
plugins-crypto 24.72% <ø> (ø)
plugins-dd-trace-api 38.42% <0.00%> (-0.11%) ⬇️
plugins-express-mongo-sanitize 25.04% <ø> (ø)
plugins-express-session 24.83% <ø> (ø)
plugins-fastify 42.52% <0.00%> (-0.10%) ⬇️
plugins-fetch 38.57% <0.00%> (-0.10%) ⬇️
plugins-fs 38.67% <0.00%> (-0.11%) ⬇️
plugins-generic-pool 24.06% <ø> (ø)
plugins-google-cloud-pubsub 45.72% <0.00%> (-0.15%) ⬇️
plugins-grpc 41.25% <0.00%> (-0.10%) ⬇️
plugins-handlebars 25.08% <ø> (ø)
plugins-hapi 40.43% <0.00%> (-0.11%) ⬇️
plugins-hono 40.69% <0.00%> (-0.10%) ⬇️
plugins-ioredis 38.47% <0.00%> (-0.11%) ⬇️
plugins-knex 24.80% <ø> (ø)
plugins-ldapjs 22.61% <ø> (ø)
plugins-light-my-request 24.48% <ø> (ø)
plugins-limitd-client 32.56% <0.00%> (+0.04%) ⬆️
plugins-lodash 24.13% <ø> (ø)
plugins-mariadb 39.58% <0.00%> (-0.11%) ⬇️
plugins-memcached 38.20% <0.00%> (-0.11%) ⬇️
plugins-microgateway-core 39.52% <0.00%> (-0.03%) ⬇️
plugins-moleculer 40.81% <0.00%> (-0.10%) ⬇️
plugins-mongodb 39.45% <0.00%> (-0.10%) ⬇️
plugins-mongodb-core 39.08% <0.00%> (-0.11%) ⬇️
plugins-mongoose 39.13% <0.00%> (-0.10%) ⬇️
plugins-multer 24.83% <ø> (ø)
plugins-mysql 39.22% <0.00%> (-0.11%) ⬇️
plugins-mysql2 39.32% <0.00%> (-0.11%) ⬇️
plugins-node-serialize 25.12% <ø> (ø)
plugins-opensearch 37.86% <0.00%> (-0.10%) ⬇️
plugins-passport-http 24.91% <ø> (ø)
plugins-postgres 35.73% <0.00%> (-0.09%) ⬇️
plugins-process 24.72% <ø> (ø)
plugins-pug 25.08% <ø> (ø)
plugins-redis 38.95% <0.00%> (+0.05%) ⬆️
plugins-router 43.29% <0.00%> (-0.10%) ⬇️
plugins-sequelize 23.66% <ø> (ø)
plugins-test-and-upstream-amqp10 38.39% <0.00%> (-0.26%) ⬇️
plugins-test-and-upstream-amqplib 43.89% <0.00%> (-0.11%) ⬇️
plugins-test-and-upstream-apollo 39.27% <0.00%> (-0.10%) ⬇️
plugins-test-and-upstream-avsc 38.81% <0.00%> (-0.11%) ⬇️
plugins-test-and-upstream-bunyan 33.87% <0.00%> (-0.11%) ⬇️
plugins-test-and-upstream-connect 41.11% <0.00%> (-0.11%) ⬇️
plugins-test-and-upstream-graphql 40.22% <0.00%> (-0.11%) ⬇️
plugins-test-and-upstream-koa 40.67% <0.00%> (-0.10%) ⬇️
plugins-test-and-upstream-protobufjs 39.04% <0.00%> (-0.11%) ⬇️
plugins-test-and-upstream-rhea 44.17% <0.00%> (-0.11%) ⬇️
plugins-undici 39.37% <0.00%> (-0.10%) ⬇️
plugins-url 24.72% <ø> (ø)
plugins-valkey 38.13% <0.00%> (-0.11%) ⬇️
plugins-vm 24.72% <ø> (ø)
plugins-winston 34.25% <0.00%> (-0.11%) ⬇️
plugins-ws 42.22% <0.00%> (-0.10%) ⬇️
profiling-macos 39.97% <0.00%> (-0.11%) ⬇️
profiling-ubuntu 40.10% <0.00%> (-0.11%) ⬇️
profiling-windows 41.33% <0.00%> (-0.10%) ⬇️
serverless-azure-functions-client 23.75% <ø> (ø)
serverless-azure-functions-eventhubs 23.75% <ø> (ø)
serverless-azure-functions-servicebus 23.75% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pr-commenter
Copy link
Copy Markdown

pr-commenter bot commented Dec 18, 2025

Benchmarks

Benchmark execution time: 2026-02-17 10:34:58

Comparing candidate commit 0a6d94c in PR branch stripe_business_events with baseline commit 8edb07d in branch master.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 229 metrics, 31 unstable metrics.

@simon-id simon-id marked this pull request as ready for review February 5, 2026 16:03
@simon-id simon-id requested review from a team as code owners February 5, 2026 16:03

addHook({
name: 'stripe',
versions: ['9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '>=20.0.0'],
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this long list (instead of >=9) used here only for testing purpose? To force the the execution in the versions 9, 10...?

I think that we shold add a comment explainig why, or else we can set this as >=9 and in externals.json add these version in stripe section. I think that it is the main purpose of having an array for versions in externals.json:

  "stripe": [
    {
      "name": "express",
      "versions": ["^4"]
    },
    {
      "name": "body-parser",
      "versions": ["1.20.1"]
    },
    {
      "name": "stripe",
      "versions": ['9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19']
    }
  ],

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes, it's to make sure we test all the majors, as it seems like stripe sdk loves majors. I don't think a comment is super useful here as this syntax is used in other instrumentations too. If you want a comment, please make a github suggestion, it's easy and handy!
And about externals.json I am not as sure as oyu this is why we have it. What's wrong with having it in the instrmentation anyway ?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What's wrong with having it in the instrumentation anyway ?

I am afraid that someone could see that and change it to <=9.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe we should just improve our install script to always run tests for all majors in a range

@CarlesDD
Copy link
Copy Markdown
Contributor

I found an edge case worth documenting.
When a client closes the connection before Stripe responds (e.g., client timeout < Stripe latency), the payment event is lost because the WAF context gets disposed when the connection closes.

client timeoutincomingHttpRequestEndwaf.disposeContext()Stripe responds laterwaf.run() fails silently (context disposed).

There's not much we can do here since the span is already closed at that point anyway. Even if waf.run() worked, the tags wouldn't go anywhere. This is an inherent limitation of tying the WAF context to the request lifecycle.

In the real world this is rare (requires client timeout < Stripe latency), and the existing warning [ASM] Calling run on a disposed context provides visibility when it happens.

@simon-id
Copy link
Copy Markdown
Member Author

@CarlesDD Good point but as you said it's a limitation of everything for appsec. I don't know if it's worth documenting this especially since i wouldn't know where to put this explanation. It's kind of obvious ? can't add tags when there is no span ?

@simon-id simon-id merged commit 179e273 into master Feb 17, 2026
792 checks passed
@simon-id simon-id deleted the stripe_business_events branch February 17, 2026 14:47
dd-octo-sts bot pushed a commit that referenced this pull request Feb 17, 2026
@dd-octo-sts dd-octo-sts bot mentioned this pull request Feb 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants