diff --git a/agent/utils/auth.py b/agent/utils/auth.py index a8a0dfb1..53ea6c1e 100644 --- a/agent/utils/auth.py +++ b/agent/utils/auth.py @@ -192,7 +192,12 @@ async def get_github_token_for_user(ls_user_id: str, tenant_id: str) -> dict[str return result if auth_url: return {"auth_url": auth_url} - return {"error": f"Unexpected auth result: {response_data}"} + # Log the full upstream body server-side only; the returned error becomes a + # user-facing Slack/Linear comment, so never echo the raw response body. + logger.error( + "GitHub auth returned an unexpected result (no token/url): %s", response_data + ) + return {"error": "GitHub auth returned an unexpected result"} except httpx.HTTPStatusError as e: # Log the full upstream body server-side only; the returned error becomes a diff --git a/tests/test_auth_error_leak.py b/tests/test_auth_error_leak.py index 02907887..33cb1cbc 100644 --- a/tests/test_auth_error_leak.py +++ b/tests/test_auth_error_leak.py @@ -43,6 +43,19 @@ class _Client: return self._resp +class _OkResp: + """A 2xx response whose JSON body lacks both a token and an auth url.""" + + def __init__(self, payload: Any) -> None: + self._payload = payload + + def raise_for_status(self) -> None: + return None + + def json(self) -> Any: + return self._payload + + def test_http_error_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None: monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id") monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret") @@ -53,3 +66,16 @@ def test_http_error_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> assert "error" in result assert _SECRET_BODY not in result["error"] assert "500" in result["error"] + + +def test_unexpected_result_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None: + """The 2xx-but-missing-token/url branch must not echo the upstream body.""" + monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id") + monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret") + body = {"unexpected_field": _SECRET_BODY} + monkeypatch.setattr(httpx, "AsyncClient", lambda *a, **k: _Client(_OkResp(body))) + + result = asyncio.run(auth.get_github_token_for_user("ls-user", "tenant")) + + assert result == {"error": "GitHub auth returned an unexpected result"} + assert _SECRET_BODY not in result["error"]