Remove str(e) from 4xx and per-row error bodies #68
Labels
No labels
bug
chore
data
feature
frontend
good first issue
intermediate
needs/docs
needs/research
needs/upstream
type/bug
type/external
type/feature
type/refactor
urgency
high
urgency
immediate
urgency
low
urgency
medium
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
ScottyLabs/cal#68
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What's wrong
Generic 500 bodies landed in #21, but a few non-500 responses still return raw exception text:
GET /api/organizations/get_courses: 404 withstr(e)of a FileNotFoundError, which includes the server file path (api/app/utils/course_data.pyL18).DELETE /api/organizations/<org_id>/calendar-sources/<id>/events: 404 withstr(e)of a ValueError.DELETE /api/google/unauthorize: 400 withstr(e)of any exception, including network errors from the token revoke call.POST /api/organizations/bulk_create_admins: each failed email addsf"Error processing {email}: {str(e)}"to the 201 body, which can include SQL.How to reproduce
In a test, mock
app.api.organizations.get_course_datato raiseFileNotFoundError("File not found: /srv/secret/path.json"), then GET/api/organizations/get_courses. The path is in the body.Expected
A fixed message (e.g. "Course data not available", "Calendar source not found", "Could not disconnect Google", "Could not add "), with the detail written to the log by
log.exception. Unauthorize failures should be 502 or 500, not 400.Where to look
api/app/api/organizations.pyL271-272, L391-392, L589-590.api/app/api/google.pyunauthorize_google()L64-72.2c5f2e9.Done when
api/tests/api/test_error_responses.pythat mock each failure and assert the body has none of the exception message