MEASURE: /gui 4xx exception text (throwaway, verifies the CodeQL finding clears) - #2
modusensus wants to merge 1 commit into
Conversation
examples/server.py answered a 4xx on /gui by reading `str(exc.detail)` off the HTTPException the limits check raised, and `_error_lines` fell back to `str(exc)` for anything it did not classify. Both put exception-derived text on a page, which code scanning reports as stack-trace exposure (py/stack-trace-exposure) -- the one alert the previous fix left open, since that one covered the three 500 surfaces. `_limit_violation` now returns `(status, message)` where it used to raise: the sentence is built from the request and the constants, and `_check_request_limits` raises the same pair for /predict and /predict/batch, so the API and the page cannot disagree about the words. A state `_state_length` cannot measure comes back the same way, off the `_STATE_NOT_SERIALIZABLE` literal rather than off the 400. `_error_lines` answers an unclassified failure with a fixed line and logs the cause at warning level: a caller's bad request is not a server error, but its cause still belongs in the log. What a caller sees is unchanged, except for that last line: a 413 page still names the limit and the number that broke it, and a 422 still names the field to fix. tests/test_example_server_errors.py asserts an oversized /gui names the limit and carries no exception text, and that the fallback's cause reaches the log.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Measurement done: CodeQL on refs/pull/2/merge reports 0 results for the changed file (main, unmodified, reports the finding). Closing without merging. |
Throwaway PR. Its only purpose is to make the Security workflow analyse this branch inside the fork, so the code scanning result count for the pull request ref can be read back. Closes unmerged.