Skip to content

MEASURE: /gui 4xx exception text (throwaway, verifies the CodeQL finding clears) - #2

Closed
modusensus wants to merge 1 commit into
pr-base-upstreamfrom
fix/gui-error-page-exception-text
Closed

modusensus wants to merge 1 commit into
pr-base-upstreamfrom
fix/gui-error-page-exception-text

Conversation

@modusensus

Copy link
Copy Markdown
Owner

Throwaway PR. Its only purpose is to make the Security workflow analyse this branch inside the fork, so the code scanning result count for the pull request ref can be read back. Closes unmerged.

examples/server.py answered a 4xx on /gui by reading `str(exc.detail)` off the
HTTPException the limits check raised, and `_error_lines` fell back to `str(exc)`
for anything it did not classify. Both put exception-derived text on a page, which
code scanning reports as stack-trace exposure (py/stack-trace-exposure) -- the one
alert the previous fix left open, since that one covered the three 500 surfaces.

`_limit_violation` now returns `(status, message)` where it used to raise: the
sentence is built from the request and the constants, and `_check_request_limits`
raises the same pair for /predict and /predict/batch, so the API and the page
cannot disagree about the words. A state `_state_length` cannot measure comes back
the same way, off the `_STATE_NOT_SERIALIZABLE` literal rather than off the 400.

`_error_lines` answers an unclassified failure with a fixed line and logs the cause
at warning level: a caller's bad request is not a server error, but its cause still
belongs in the log.

What a caller sees is unchanged, except for that last line: a 413 page still names
the limit and the number that broke it, and a 422 still names the field to fix.

tests/test_example_server_errors.py asserts an oversized /gui names the limit and
carries no exception text, and that the fallback's cause reaches the log.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9782807d-25d1-45f0-bb1f-f69763b6c067

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@modusensus

Copy link
Copy Markdown
Owner Author

Measurement done: CodeQL on refs/pull/2/merge reports 0 results for the changed file (main, unmodified, reports the finding). Closing without merging.

@modusensus modusensus closed this Oct 1, 2026
@modusensus
modusensus deleted the fix/gui-error-page-exception-text branch October 1, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant