Skip to content

fix(graphql): Prevent Sentry reporting of client-side GraphQL validation errors - #2447

Open
sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-client-errors-sentry-qXQIGc
Open

sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-client-errors-sentry-qXQIGc

Conversation

@sentry

@sentry sentry Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR addresses an issue where malformed GraphQL queries from clients were being reported to Sentry as internal server errors, leading to noise in error monitoring.

The fix involves two main changes:

  1. Modified graphql_api/views.py: The error_formatter function now explicitly checks for GraphQLError instances that do not have an original_error. These errors typically indicate client-side query validation or parsing issues (e.g., querying a non-existent field). For such errors, the API will no longer log them as internal server errors or call sentry_sdk.capture_exception.
  2. Added sentry_filters.py and updated settings_base.py: A new before_send filter has been introduced for Sentry. This filter intercepts events generated by the Ariadne integration. It drops events that are identified as client-side GraphQL validation errors (either by checking for GraphQLError without an original_error or by matching common validation error messages). This ensures that even if the Ariadne integration automatically captures these errors, they are filtered out before being sent to Sentry.

These changes ensure that Sentry is not cluttered with non-actionable errors originating from malformed client requests, allowing the team to focus on genuine server-side issues.

Legal Boilerplate

Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.

Fixes API-F7E

@sentry <feedback>: Autofix iterates on these changes
@sentry stop iterating: Autofix stops iterating on this run

This PR was automatically generated by Sentry. You can adjust this setting at any time.


Note

Low Risk
Observability-only filtering; genuine resolver exceptions with original_error are still reported.

Overview
Stops malformed GraphQL client queries (parse/validation failures) from being treated as server bugs in Sentry.

The GraphQL error_formatter now treats GraphQLError with no original_error as a client-side validation issue and skips internal error logging and capture_exception. A new codecov/sentry_filters.before_send hook is registered in sentry_sdk.init to drop Ariadne-mechanism events that match client validation (GraphQLError without a wrapped exception, or known message patterns like "Cannot query field"). Resolver failures that wrap a real exception still flow to Sentry.

Reviewed by Cursor Bugbot for commit 45fef0f. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 45fef0f. Configure here.

# resolver errors do, and those must still be reported.
if exc.original_error is not None:
return False
return True

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Filter drops server GraphQL errors

High Severity

The new filter treats every GraphQLError without an original_error as a client validation issue. GraphQL execution also raises those for server bugs such as returning null from a non-nullable field, so those events are now dropped from Sentry and no longer logged.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 45fef0f. Configure here.

@sentry

sentry Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Sentry needs additional GitHub App permissions

The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing.

Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update

@codecov-notifications

codecov-notifications Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 21.21212% with 26 lines in your changes missing coverage. Please review.
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
apps/codecov-api/codecov/sentry_filters.py 13.33% 26 Missing ⚠️

📢 Thoughts on this report? Let us know!

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 21.21212% with 26 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.60%. Comparing base (65af8ae) to head (45fef0f).
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
apps/codecov-api/codecov/sentry_filters.py 13.33% 26 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2447      +/-   ##
==========================================
- Coverage   91.65%   91.60%   -0.05%     
==========================================
  Files        1341     1342       +1     
  Lines       53342    53375      +33     
  Branches     1649     1649              
==========================================
+ Hits        48888    48895       +7     
- Misses       4133     4159      +26     
  Partials      321      321              
Flag Coverage Δ
apiunit 93.91% <21.21%> (-0.11%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants