Repository navigation
fix: keep backend error text out of API responses - #786
Merged
Merged
Conversation
ClickHouse's error text can carry statement fragments, user names and password hashes, and routes across the API handed it straight back to the caller, viewers included. Kafka, the deploy repo and the IdP leaked the same way. - A route reporting a backend failure answers a fixed message naming what failed, and the backend's text goes to the engine log. One helper in api/errors.py does it, and the CH RBAC reconcile now uses it too. - The 503 for an exhausted ClickHouse or deploy repo no longer repeats scalo's message, which ends with the backend's last error verbatim. - Background tasks log every failure. Readers see a task's own message only for the sampler's and synthetic data's refusals; anything else reads "The task failed". - Covered: view execution, cost leaderboard, discovery, tenant id discovery, TTL and defaults reconcile, default drift, ClickHouse Cloud, source plan, deploy and dry run, source signals, app metrics, app reconcile, bulk source actions, HyperDX source sync, JSON path reads, the sampler scope check, the Kafka topic routes, schema status and the OIDC callback. - Schema status names the stage that failed; the cause is in the engine log, which the CLI prints too. - Refusals the engine writes about the caller's own input keep their text: cursor and option validation, catalogue and schema build errors, Kafka contract errors, JSON path validation.
|
Released in v1.22.18 -- https://github.com/hyperi-io/dfe-engine/releases/tag/v1.22.18 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ClickHouse's error text can carry statement fragments, user names and password hashes (
ALTER USER ... IDENTIFIED WITH sha256_hash BY '...'). Routes across the API handed it straight back to the caller, anddata_analyst,data_viewerandorg_viewerreach plenty of them through the console. Kafka, the deploy repo and the IdP leaked the same way.api/errors.py(backend_failure,hide_backend_text) does it everywhere, the CH RBAC reconcile from fix: contain store paths and make regexes linear #782 included.ServiceUnavailablemessage, which ends with the backend's last error verbatim.CloudServiceError,JsonPromotionError) keep the engine's: those are raised with no cause, and the backend ones are raisedfromthe backend error.dfe schema applyCLI still prints it from there.POST /queries/raw(admin only, the text is ClickHouse's answer to the caller's own SQL) and the OIDC provider test, verify-login and sync routes (admin only, they exist to diagnose the IdP connection).tests/unit/test_api/test_no_backend_error_text.pymakes each backend fail with a sentinel carryingIDENTIFIEDand a fake hash, then checks the response has none of it and the engine log has it.Done when no route under
src/dfe_engine/api/sends a backend's error text to its caller.