SShortSingh.
Back to feed

Dev adds Sentry tracing to Keycloak SPI after silent double JDBC query bug found in code review

0
·6 views

A developer working on a custom Keycloak SPI provider discovered that the LegacyUserStorageProvider was making two separate JDBC calls per username-attribute lookup instead of one, doubling database load without raising any errors or returning wrong results. The bug was caught only through manual code review, prompting the developer to add Sentry instrumentation to prevent similar issues from going undetected in the future. Query methods in LegacyUserRepository were updated to open child spans tied to Keycloak's active request tracing, and SQLExceptions are now captured as Sentry events rather than silently disappearing into server logs. The integration is fully opt-in, activating only when a SENTRY_DSN environment variable is set, ensuring the provider does not send data to any external service without explicit user consent. The instrumentation is designed to surface slow or intermittent legacy database issues — such as queries behaving poorly for specific data shapes — before they manifest as user-facing login complaints.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Senior Engineer Proposes Structured 'Skill Review' Framework for AI Agent Workflows

A senior software engineer and tech lead has outlined a five-dimension framework for reviewing AI agent skills before stress testing, arguing that current review practices are insufficient. The framework addresses a gap between stress tests, which check if a skill works when called, and skill reviews, which assess whether a skill is ready across all contexts its description implies. The proposed checklist covers routing signals, output contracts, methodology generalisability, and explicit failure behaviour, among other dimensions. The author credits Dan Shapiro's 'Five Levels' model and AI strategist Nate B. Jones as the conceptual foundations for the approach. The piece is part of an ongoing public learning log called 'The Level 5 Engineer,' documenting one practitioner's progression toward advanced AI-assisted software development.

0
ProgrammingHacker News ·

Hacker destroys Romania's entire land registry database in cyberattack

A hacker has wiped Romania's national land registry database in a significant cyberattack. The incident targeted the country's property records system, potentially affecting land ownership documentation across Romania. The attack raises serious concerns about the security of critical government infrastructure and digital public records. Romanian authorities are expected to investigate the breach and assess the extent of data loss and recovery options.

0
ProgrammingDEV Community ·

AWS S3 Deep Dive: Encryption, Bucket Policies, Access Control and CLI Explained

A detailed technical guide covering Amazon S3 has been published as part of an ongoing AWS learning series aimed at professionals transitioning into cloud and DevOps roles. The resource explores core S3 concepts including storage classes, versioning, object structure, and encryption methods such as SSE-S3, SSE-KMS, SSE-C, and client-side encryption. It also covers access control mechanisms including bucket policies, ACLs, and explicit deny rules, which are commonly tested in AWS certification exams and DevOps interviews. The guide explains foundational AWS concepts like JSON and YAML syntax, API calls, and infrastructure-as-code practices that underpin S3 configuration in real-world organizations. Practical sections include S3 CLI commands, Python integration via boto3, and hands-on tasks designed to reinforce certification and interview readiness.

0
ProgrammingDEV Community ·

One Developer's Practical Roadmap for Skill-Building in 2026

A software developer has outlined a personal learning roadmap for 2026, aimed at beginners and aspiring developers looking for structured guidance. The plan prioritizes programming fundamentals, depth in one language, and building real-world projects over chasing every new technology. It also covers version control, system design basics, clean code practices, and DevOps concepts like Docker and CI/CD. The developer additionally highlights using AI tools to accelerate learning, contributing to open source, and maintaining consistent habits such as reading technical blogs and building side projects. The core philosophy is that steady, focused progress on the right skills matters more than trying to learn everything at once.