Skip to content

[nodejs] feat(nodejs): add /security/thread_context_sharing weblog endpoint - #7848

Draft
CarlesDD wants to merge 13 commits into
mainfrom
ccapell/APPSEC-70386/nodejs-thread-context-sharing-endpoint
Draft

CarlesDD wants to merge 13 commits into
mainfrom
ccapell/APPSEC-70386/nodejs-thread-context-sharing-endpoint

Conversation

@CarlesDD

Copy link
Copy Markdown
Contributor

Motivation

Node.js has no /security/thread_context_sharing endpoint yet, so Test_ThreadContextSharing (THREAD_CONTEXT_SHARING scenario) cannot run for Node.js.

Changes

  • Implement GET /security/thread_context_sharing in:
    • express/app.js (shared by express4, uds-express4, express5)
    • fastify/app.js
    • express4-typescript/app.ts
    • nextjs (new App Router route src/app/security/thread_context_sharing/route.js)
  • nextjs.Dockerfile: copy the new src/app/security route so no base image rebuild is needed.
  • The handler writes path with fs.writeFileSync. Async fs would open the file on a libuv worker thread, which does not carry the request's thread context that system-probe reads. It returns the active span's 128-bit trace ID and span ID as decimal strings, and returns 400 when path is missing.
  • manifests/nodejs.yml: keep Test_ThreadContextSharing as missing_feature, updating the reason to thread context sharing not enabled for appsec yet. The endpoint now exists, but dd-trace-js only publishes the thread context when DD_TRACE_OTEL_CTX_ENABLED=true, and this scenario only sets DD_APPSEC_ENABLED=true.

Activation is intentionally left for a follow-up. It also needs a Node.js weblog with AsyncContextFrame active (Node.js 24+): all Node.js weblogs currently run Node.js 18–22, and express5, the only one scheduled for this scenario, runs node:18-alpine.

Workflow

  1. ⚠️ Create your PR as draft ⚠️
  2. Work on you PR until the CI passes
  3. Mark it as ready for review
    • Tests, manifest, weblog are modified -> you'll need a review from system-tests-reviewers: ask to one of youre co-worker familiar with the tested feature.
    • Framework is modified, or non obvious usage of it -> get a review from system-tests-core (slack)

🚀 Once your PR is reviewed and the CI green, you can merge it!

🛟 #apm-shared-testing 🛟

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

CODEOWNERS have been resolved as:

utils/build/docker/nodejs/nextjs/src/app/security/thread_context_sharing/route.js  @DataDog/system-tests-reviewers
manifests/agent.yml                                                     @DataDog/system-tests-reviewers
manifests/nodejs.yml                                                    @DataDog/system-tests-reviewers
mirror_images.lock.yaml                                                 @DataDog/system-tests-core
mirror_images.yaml                                                      @DataDog/system-tests-core
utils/build/docker/base-images.lock.json                                @DataDog/system-tests-reviewers
utils/build/docker/nodejs/express/app.js                                @DataDog/system-tests-reviewers
utils/build/docker/nodejs/express4-typescript/app.ts                    @DataDog/system-tests-reviewers
utils/build/docker/nodejs/fastify.Dockerfile                            @DataDog/system-tests-reviewers
utils/build/docker/nodejs/fastify/app.js                                @DataDog/system-tests-reviewers
utils/build/docker/nodejs/nextjs.Dockerfile                             @DataDog/system-tests-reviewers
utils/build/docker/nodejs/weblog_metadata.yml                           @DataDog/system-tests-reviewers

@CarlesDD CarlesDD changed the title feat(nodejs): add /security/thread_context_sharing weblog endpoint [nodejs] feat(nodejs): add /security/thread_context_sharing weblog endpoint Sep 29, 2026
@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Pipelines  Tests

✨ Unblock PR with BitsAI

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 267 Pipeline jobs failed

Testing the test | all-jobs-are-green — 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

Testing the test | System Tests (cpp_httpd, prod) / End-to-end #1 / httpd 1 — 🔄 Retry may pass, looks flaky

View more details · View in GitHub Actions

Testing the test | System Tests (golang, dev) / End-to-end #1 / gin 1 — 🔄 Retry may pass, looks flaky

View more details · View in GitHub Actions

View all 267 failed jobs.

ℹ️ Info

No other issues found (see more)

🧪 All tests passed
❄️ No new flaky tests detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: c73a29a | Docs | View more details | Give us feedback!

@CarlesDD
CarlesDD force-pushed the ccapell/APPSEC-70386/nodejs-thread-context-sharing-endpoint branch from 803f358 to a672525 Compare October 1, 2026 07:19
@CarlesDD
CarlesDD force-pushed the ccapell/APPSEC-70386/nodejs-thread-context-sharing-endpoint branch from 2a1dd35 to 7ecdfaf Compare October 1, 2026 13:33

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant