fix(python): do not render local variables in tracebacks - #264
Merged
Merged
Conversation
Typer's pretty tracebacks print every frame's locals by default. Request helpers keep credentials in locals, so an unhandled exception could echo them to stderr. Turn show_locals off on the root app. Adds a subprocess test that forces a transport failure and asserts a sentinel credential never reaches stdout or stderr.
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Typer renders every frame's local variables in its pretty tracebacks by default.
This sets
pretty_exceptions_show_locals=Falseon the rootrafterapp so an unhandled exception prints the stack and the error, without frame locals (which can include credentials).Node is not affected.
Test
python/tests/test_traceback_no_locals.pyrunsrafter usagein a subprocess with a sentinelRAFTER_API_KEYand an unreachable proxy, so the command fails with an unhandled transport error.It asserts the sentinel appears in neither stdout nor stderr.
mainbefore the change, passes after.