Problem
When dataCollection.databaseQueryData disables raw SQL collection, database spans lose their SQL description entirely. Keeping the raw statement is not safe because inline literals and other query values can contain sensitive data and create high-cardinality span descriptions.
We should provide useful, low-cardinality descriptions without retaining query values, for example:
SELECT users
UPDATE orders
INSERT products
This is follow-up work from #5801 and supports #5666.
Proposed solution
Add a SQL summarizer that extracts only a safe operation and target from a statement. Use the summary for JDBC and Android SQLite span descriptions when raw database query data is disabled. Preserve the full statement only when the effective Data Collection policy allows it.
Consider adapting OpenTelemetry Java's Apache-2.0 SQL query analyzer instead of depending on its incubating API. If code is adapted, include the required source attribution and update THIRD_PARTY_NOTICES.md.
The summarizer must fail closed: malformed or unsupported SQL must never fall back to the raw statement.
Acceptance criteria
- JDBC and Android SQLite spans use low-cardinality summaries when raw query collection is disabled.
- Summaries do not contain inline literals, bound values, comments, or other query values.
- Parsing covers common operations such as
SELECT, INSERT, UPDATE, and DELETE.
- Malformed and unsupported SQL produces a generic description or no description, never the raw statement.
- Tests cover inline literals, placeholders, mixed literal-and-bound queries, malformed SQL, and representative dialect-specific syntax.
- Any adapted third-party code includes complete license attribution.
Problem
When
dataCollection.databaseQueryDatadisables raw SQL collection, database spans lose their SQL description entirely. Keeping the raw statement is not safe because inline literals and other query values can contain sensitive data and create high-cardinality span descriptions.We should provide useful, low-cardinality descriptions without retaining query values, for example:
SELECT usersUPDATE ordersINSERT productsThis is follow-up work from #5801 and supports #5666.
Proposed solution
Add a SQL summarizer that extracts only a safe operation and target from a statement. Use the summary for JDBC and Android SQLite span descriptions when raw database query data is disabled. Preserve the full statement only when the effective Data Collection policy allows it.
Consider adapting OpenTelemetry Java's Apache-2.0 SQL query analyzer instead of depending on its incubating API. If code is adapted, include the required source attribution and update
THIRD_PARTY_NOTICES.md.The summarizer must fail closed: malformed or unsupported SQL must never fall back to the raw statement.
Acceptance criteria
SELECT,INSERT,UPDATE, andDELETE.