Privacy and Permissions¶
Privacy rules must take effect before data enters the RUM or Log queues. Both C# and Native C/C++ support redaction of URL Query, HTTP request headers, and response headers, and can handle business-sensitive fields through the generic Modifier.
Permission Configuration¶
The Windows SDK does not proactively apply for system permissions. The application must ensure that the process can access the configured reporting endpoint and cache directory; WebView2, window handles, and network components still follow the host application's own permission and security policies.
Default Behavior¶
| Data | .NET / C# | Native C/C++ |
|---|---|---|
| URL Query | Non-sensitive values are retained; default sensitive parameters are replaced with <redacted> |
Same |
| HTTP Header | Authentication-related headers are collected and redacted by default | Same |
| User and custom attributes | Can be redacted via DataModifier or LineDataModifier |
Same |
| Log content and attributes | Can be redacted via DataModifier or LineDataModifier |
Same |
| Trace Header | Only sent to targets allowed by ShouldTrace/should_trace |
Same |
Default sensitive Query names include token, access_token, refresh_token, client_secret, password, passwd, secret, api_key, apikey, auth, and authorization. Default sensitive Header names include Authorization, Cookie, Set-Cookie, Proxy-Authorization, X-Api-Key, X-Auth-Token, and X-Datakit-Token.
Unified Processing Order¶
RUM, Log, WebView, and Native Browser Bridge data use the same processing order before being written to the disk cache:
DataModifier: Processes existing Tags and Fields one by one; when it returnsnull, or the Native callback returns0, the original value is retained.LineDataModifier: Views the entire data line by Measurement and updates existing fields; new fields are ignored.- HTTP privacy rules: URL Query, request headers, and response headers are processed last, preventing custom Modifiers from bypassing the configured network redaction rules.
- Format and write to the cache.
Modifiers may run concurrently on multiple collection threads; avoid time-consuming operations in callbacks. Callback exceptions do not interrupt data collection, and the corresponding fields retain their original values.
Privacy Configuration¶
TrueWatchSdk.Init(new TrueWatchConfig
{
DatawayUrl = "https://openway.truewatch.com",
ClientToken = "<client-token>",
RumAppId = "<rum-app-id>",
DataModifier = (key, value) =>
{
return key switch
{
"user_email" => "<redacted>",
"phone" => "<redacted>",
_ => null
};
},
LineDataModifier = (measurement, data) =>
{
if (measurement == "error" && data.ContainsKey("error_message"))
{
return new Dictionary<string, object?>
{
["error_message"] = "<redacted-error>"
};
}
return null;
},
Privacy = new RumPrivacyConfig
{
CaptureHttpHeaders = true,
CaptureUrlQueryString = true,
RedactAllUrlQueryValues = false,
RedactedValue = "<redacted>",
RedactedHeaderNames = new[]
{
"Authorization",
"Cookie",
"Set-Cookie",
"X-Api-Key"
},
RedactedQueryParameterNames = new[]
{
"token",
"password",
"secret"
}
}
});
| Parameter | Default | Description |
|---|---|---|
CaptureHttpHeaders |
true |
Whether to record redacted request and response headers. |
CaptureUrlQueryString |
true |
Whether to keep the URL Query. When disabled, the entire Query is removed. |
RedactAllUrlQueryValues |
false |
Whether to hide all Query values. |
RedactedValue |
<redacted> |
Redaction replacement text. |
RedactedHeaderNames |
Authentication-related headers | Header name list, case-insensitive. |
RedactedQueryParameterNames |
Sensitive parameter name list | Query parameter name list, case-insensitive. |
Both DataModifier and LineDataModifier are optional configurations. If you only need default HTTP redaction, configure Privacy alone.
#include <cstring>
static int modify_data(
const char* key,
const truewatch_data_value*,
truewatch_data_value* replacement,
void*) {
if (std::strcmp(key, "user_email") != 0) {
return 0;
}
replacement->type = TRUEWATCH_DATA_VALUE_STRING;
replacement->value.string_value = "<redacted>";
return 1;
}
static void modify_line(
const char* measurement,
truewatch_data_item* data,
uint32_t data_count,
void*) {
if (std::strcmp(measurement, "error") != 0) {
return;
}
for (uint32_t index = 0; index < data_count; ++index) {
if (std::strcmp(data[index].key, "error_message") == 0) {
data[index].value.type = TRUEWATCH_DATA_VALUE_STRING;
data[index].value.value.string_value = "<redacted-error>";
}
}
}
truewatch_sdk_config sdk_config;
truewatch_sdk_config_init(&sdk_config);
sdk_config.dataway_url = "https://openway.truewatch.com";
sdk_config.client_token = "<client-token>";
sdk_config.rum_app_id = "<rum-app-id>";
truewatch_sdk_handle rum = truewatch_sdk_init(&sdk_config);
truewatch_data_modifier_config modifiers;
truewatch_data_modifier_config_init(&modifiers);
modifiers.data_modifier = modify_data;
modifiers.line_data_modifier = modify_line;
truewatch_configure_data_modifiers(rum, &modifiers);
const char* redacted_query_names[] = {
"token",
"password",
"secret"
};
const char* redacted_header_names[] = {
"Authorization",
"Cookie",
"Set-Cookie",
"X-Api-Key"
};
truewatch_rum_resource_collection_config privacy;
truewatch_rum_resource_collection_config_init(&privacy);
privacy.capture_http_headers = 1;
privacy.capture_url_query = 1;
privacy.redact_all_url_query_values = 0;
privacy.redacted_value = "<redacted>";
privacy.redacted_query_parameter_names = redacted_query_names;
privacy.redacted_query_parameter_name_count = 3;
privacy.redacted_header_names = redacted_header_names;
privacy.redacted_header_name_count = 4;
truewatch_rum_configure_resource_collection(rum, &privacy);
All Native configuration structures must first call the corresponding *_init(). HTTP privacy configuration copies the Header and Query name lists; Modifiers retain the function pointers and user_data, which must remain valid until reconfiguration or truewatch_sdk_shutdown(). Modifiers may run concurrently and must not call the same SDK Handle again.
Data Redaction¶
Disabling Network Data Collection¶
Target Filtering¶
Native Resources can filter collection targets via should_collect; in C#, apply equivalent filtering in business handlers or at manual Resource boundaries. Trace Headers must be restricted to trusted services through the target allowlist in Trace Configuration.
Users, Logs, and Custom Fields¶
- Do not write passwords, tokens, identity documents, payment information, or complete authentication headers.
- User IDs should use stable identifiers or hash values permitted by your business.
- Log content and attributes are not automatically interpreted for business-sensitive fields; redact them via Modifier or before calling
AddLog(). - Custom attributes cannot override SDK reserved fields; conflicting fields are ignored.
Session Replay Privacy¶
Experimental Capability
Session Replay is disabled by default and can be explicitly enabled for verification, but it remains an experimental capability. Before enabling it, you must confirm that the default policy and element-level overrides meet your business privacy requirements.
Session Replay's global privacy level, element-level overrides, and WebView2/Electron privacy boundaries are consolidated in Windows Session Replay Privacy Configuration and Privacy Overrides.