Skip to content

fix: keep backend error text out of API responses - #786

Merged
catinspace-au merged 1 commit into
mainfrom
fix/no-backend-error-text
Oct 10, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/no-backend-error-text

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

ClickHouse's error text can carry statement fragments, user names and password hashes (ALTER USER ... IDENTIFIED WITH sha256_hash BY '...'). Routes across the API handed it straight back to the caller, and data_analyst, data_viewer and org_viewer reach plenty of them through the console. Kafka, the deploy repo and the IdP leaked the same way.

  • A route reporting a backend failure now answers a fixed message naming what failed, and logs the backend's text. One helper in api/errors.py (backend_failure, hide_backend_text) does it everywhere, the CH RBAC reconcile from fix: contain store paths and make regexes linear #782 included.
  • The central 503 for an exhausted ClickHouse or deploy repo no longer repeats scalo's ServiceUnavailable message, which ends with the backend's last error verbatim.
  • Background tasks log every failure. A reader sees the task's own message only for the sampler's and synthetic data's refusals; anything else reads "The task failed".
  • Errors that are sometimes the engine's words and sometimes the backend's (CloudServiceError, JsonPromotionError) keep the engine's: those are raised with no cause, and the backend ones are raised from the backend error.
  • Kafka topic failures record "broker unreachable" or "the broker refused it", which also cleans the dead-letter refusal and the schema status topic drift.
  • Schema status names the stage that failed. The cause is in the engine log, and the dfe schema apply CLI still prints it from there.
  • Refusals about the caller's own input keep their text: view options and cursors, catalogue and schema build errors, Kafka contract errors, JSON path validation, HdxSanitizeError.
  • Left alone on purpose: POST /queries/raw (admin only, the text is ClickHouse's answer to the caller's own SQL) and the OIDC provider test, verify-login and sync routes (admin only, they exist to diagnose the IdP connection).

tests/unit/test_api/test_no_backend_error_text.py makes each backend fail with a sentinel carrying IDENTIFIED and a fake hash, then checks the response has none of it and the engine log has it.

Done when no route under src/dfe_engine/api/ sends a backend's error text to its caller.

ClickHouse's error text can carry statement fragments, user names and password hashes, and routes across the API handed it straight back to the caller, viewers included. Kafka, the deploy repo and the IdP leaked the same way.

- A route reporting a backend failure answers a fixed message naming what failed, and the backend's text goes to the engine log. One helper in api/errors.py does it, and the CH RBAC reconcile now uses it too.
- The 503 for an exhausted ClickHouse or deploy repo no longer repeats scalo's message, which ends with the backend's last error verbatim.
- Background tasks log every failure. Readers see a task's own message only for the sampler's and synthetic data's refusals; anything else reads "The task failed".
- Covered: view execution, cost leaderboard, discovery, tenant id discovery, TTL and defaults reconcile, default drift, ClickHouse Cloud, source plan, deploy and dry run, source signals, app metrics, app reconcile, bulk source actions, HyperDX source sync, JSON path reads, the sampler scope check, the Kafka topic routes, schema status and the OIDC callback.
- Schema status names the stage that failed; the cause is in the engine log, which the CLI prints too.
- Refusals the engine writes about the caller's own input keep their text: cursor and option validation, catalogue and schema build errors, Kafka contract errors, JSON path validation.
@catinspace-au
catinspace-au merged commit 2d11e06 into main Oct 10, 2026
20 checks passed
@catinspace-au
catinspace-au deleted the fix/no-backend-error-text branch October 10, 2026 07:42
@github-actions

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant