mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
fix: stop leaking upstream auth body in unexpected-result branch
The 2xx-but-missing-token/url branch echoed the parsed upstream response body into the user-facing error. Return a generic message and log response_data server-side only, mirroring the existing HTTPStatusError fix (Gap 4).
This commit is contained in:
parent
ebeb2663fd
commit
969b8e3882
2 changed files with 32 additions and 1 deletions
|
|
@ -192,7 +192,12 @@ async def get_github_token_for_user(ls_user_id: str, tenant_id: str) -> dict[str
|
|||
return result
|
||||
if auth_url:
|
||||
return {"auth_url": auth_url}
|
||||
return {"error": f"Unexpected auth result: {response_data}"}
|
||||
# Log the full upstream body server-side only; the returned error becomes a
|
||||
# user-facing Slack/Linear comment, so never echo the raw response body.
|
||||
logger.error(
|
||||
"GitHub auth returned an unexpected result (no token/url): %s", response_data
|
||||
)
|
||||
return {"error": "GitHub auth returned an unexpected result"}
|
||||
|
||||
except httpx.HTTPStatusError as e:
|
||||
# Log the full upstream body server-side only; the returned error becomes a
|
||||
|
|
|
|||
|
|
@ -43,6 +43,19 @@ class _Client:
|
|||
return self._resp
|
||||
|
||||
|
||||
class _OkResp:
|
||||
"""A 2xx response whose JSON body lacks both a token and an auth url."""
|
||||
|
||||
def __init__(self, payload: Any) -> None:
|
||||
self._payload = payload
|
||||
|
||||
def raise_for_status(self) -> None:
|
||||
return None
|
||||
|
||||
def json(self) -> Any:
|
||||
return self._payload
|
||||
|
||||
|
||||
def test_http_error_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id")
|
||||
monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret")
|
||||
|
|
@ -53,3 +66,16 @@ def test_http_error_returns_generic_message(monkeypatch: pytest.MonkeyPatch) ->
|
|||
assert "error" in result
|
||||
assert _SECRET_BODY not in result["error"]
|
||||
assert "500" in result["error"]
|
||||
|
||||
|
||||
def test_unexpected_result_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""The 2xx-but-missing-token/url branch must not echo the upstream body."""
|
||||
monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id")
|
||||
monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret")
|
||||
body = {"unexpected_field": _SECRET_BODY}
|
||||
monkeypatch.setattr(httpx, "AsyncClient", lambda *a, **k: _Client(_OkResp(body)))
|
||||
|
||||
result = asyncio.run(auth.get_github_token_for_user("ls-user", "tenant"))
|
||||
|
||||
assert result == {"error": "GitHub auth returned an unexpected result"}
|
||||
assert _SECRET_BODY not in result["error"]
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue