ameax / laravel-glitchtip
Error tracking for Laravel with GlitchTip (or any Sentry compatible server): privacy mode, release detection for git and Deployer, and context for users, tenants and Livewire
Requires
- php: ^8.1
- illuminate/contracts: ^10.0||^11.0||^12.0||^13.0
- sentry/sentry-laravel: ^4.0
- spatie/laravel-package-tools: ^1.16
Requires (Dev)
- larastan/larastan: ^2.9||^3.0
- laravel/pint: ^1.14
- livewire/livewire: ^3.0||^4.0
- orchestra/testbench: ^8.0||^9.0||^10.0||^11.0
- pestphp/pest: ^2.0||^3.0||^4.0
- pestphp/pest-plugin-laravel: ^2.0||^3.0||^4.0
- phpstan/extension-installer: ^1.3
Suggests
- livewire/livewire: Adds the involved Livewire components to error events (^3.0 or ^4.0)
- spatie/laravel-multitenancy: Adds the current tenant to error events
Provides
None
Conflicts
None
Replaces
None
README
Error tracking for Laravel with GlitchTip or any other Sentry compatible server.
The package builds on the official sentry/sentry-laravel SDK and adds:
- Privacy mode: one switch (
SENTRY_PRIVACY_MODE) decides whether personal data is sent - Release detection without configuration:
REVISIONfile written by Deployer or the checked out git commit - Context on every event: user id, locale, tenant (spatie/laravel-multitenancy) and the involved Livewire components
- Full client ip address as resolved by Laravel (trusted proxies) instead of
REMOTE_ADDR - Credential filter: passwords, tokens, the cookie header and other secrets are always replaced by
[Filtered] - A hook to add project specific context
Supports Laravel 10 to 13 and Livewire 3 and 4.
Installation
composer require ameax/laravel-glitchtip php artisan sentry:publish --dsn=https://<key>@<your-glitchtip-host>/<project-id>
Report exceptions to GlitchTip in bootstrap/app.php (Laravel 11+):
use Sentry\Laravel\Integration; ->withExceptions(function (Exceptions $exceptions) { Integration::handles($exceptions); })
On Laravel 10 add this to the register() method of app/Exceptions/Handler.php:
$this->reportable(function (Throwable $e) { \Sentry\Laravel\Integration::captureUnhandledException($e); });
Optionally add a log channel to config/logging.php:
'sentry' => [ 'driver' => 'sentry', ],
Configuration
| Variable | Default | Description |
|---|---|---|
SENTRY_LARAVEL_DSN |
DSN of the GlitchTip project | |
SENTRY_PRIVACY_MODE |
false |
Do not send personal data |
SENTRY_MAX_REQUEST_BODY_SIZE |
medium |
none, small, medium or always (ignored in privacy mode) |
SENTRY_RELEASE |
detected | Overrides the detected release |
SENTRY_DETECT_RELEASE |
true |
Detect the release from REVISION or .git |
SENTRY_ENVIRONMENT |
APP_ENV |
Environment of the events |
SENTRY_TRACES_SAMPLE_RATE |
Share of requests traced for performance monitoring, e.g. 0.01 |
Publish the package config with php artisan vendor:publish --tag=laravel-glitchtip-config if needed.
The package sets send_default_pii, max_request_body_size and the SQL binding options of the Sentry config
based on the privacy mode. Configure them via the variables above, not in config/sentry.php.
The enrichment and the credential filter run as Sentry before_send callback, i.e. after the SDK added
request and user data. A before_send callback configured in config/sentry.php is still called afterwards.
What is sent
| Data | Privacy mode off | Privacy mode on |
|---|---|---|
| Exception, stack trace, URL, route, server name, environment, release | ✅ | ✅ |
| User id, locale, tenant | ✅ | ✅ |
| Livewire component class and called methods | ✅ | ✅ |
| Full client ip address, cookies, headers, session id | ✅ | ❌ |
| User email and name | ✅ | ❌ |
| Request body, SQL bindings, Livewire component data | ✅ | ❌ |
| Passwords, tokens, secrets, cookie and authorization header, cookie values | ❌ | ❌ |
Note: GlitchTip truncates ip addresses unless "Scrub IP addresses" is disabled in the project settings.
Credential filter
Independent of the privacy mode, values of keys containing one of the sensitive_keys of the package config
(password, secret, token, api_key, authorization, cookie, csrf, signature, ...) are replaced by
[Filtered] in the request body, query string, url, headers and the Livewire context, including the Livewire
snapshots in the request body. Cookie values are always filtered.
Publish the config to adjust the list. Parameters of Livewire method calls are positional and therefore not filtered.
Release detection
When SENTRY_RELEASE is not set, the release is detected in this order:
REVISIONfile in the base path (written by Deployer into each release directory)- The checked out commit of
.git(deployments viagit pull)
Files are read directly, no shell command is executed.
Project specific context
use Ameax\Glitchtip\Glitchtip; use Sentry\Event; // e.g. in AppServiceProvider::boot() Glitchtip::enrichUsing(function (Event $event): void { $event->setTag('installation', config('app.name')); });
Exceptions thrown by an enricher are swallowed so that the event is still sent.
Testing
composer test
composer analyse
License
The MIT License (MIT). Please see License File for more information.