Skip to content

fix(graphql): prevent client validation errors from being reported as server errors - #2450

Open
sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-client-validation-errors-4eL8D7
Open

sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-client-validation-errors-4eL8D7

Conversation

@sentry

@sentry sentry Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Previously, client-side GraphQL validation errors (e.g., querying a field that doesn't exist on a type) were being reported to Sentry as internal server errors. This occurred for two reasons:

  1. The error_formatter in graphql_api/views.py only applied its bad-query exemption to authenticated users. Anonymous users' invalid queries would fall through to the generic error handling, leading to log.error("GraphQL internal server error") and capture_exception.
  2. Sentry's auto-enabled Ariadne integration was also capturing these validation errors, tagging them with mechanism: ariadne.

This change addresses both issues:

  • error_formatter now correctly identifies GraphQL validation errors (those without an original_error or containing "Cannot query field") as client errors for all users. For anonymous users, the response still masks schema details with "INTERNAL SERVER ERROR", but these errors are no longer logged or captured as internal server errors.
  • The Sentry SDK initialization in settings_base.py now explicitly disables the AriadneIntegration. This prevents duplicate capture of validation errors and ensures that only genuine, unexpected resolver exceptions (which are still explicitly captured by error_formatter) are sent to Sentry.

Legal Boilerplate

Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.

Fixes API-F7A

@sentry <feedback>: Autofix iterates on these changes
@sentry stop iterating: Autofix stops iterating on this run

This PR was automatically generated by Sentry. You can adjust this setting at any time.


Note

Low Risk
Changes only error classification and Sentry integration for GraphQL; genuine resolver exceptions are still captured explicitly in error_formatter.

Overview
Stops GraphQL client validation errors (unknown fields, malformed queries) from being treated as internal server failures in observability.

Sentry: sentry_sdk.init now disables AriadneIntegration, so the SDK no longer auto-reports schema/validation mistakes as unhandled errors. Real resolver failures remain reported via AsyncGraphqlView.error_formatter.

GraphQL responses: error_formatter broadens bad-query detection to errors with no original_error (typical validation) or the existing "Cannot query field" check. Authenticated users still get full validation messages; anonymous users still see masked "INTERNAL SERVER ERROR" but those cases no longer hit log.error / capture_exception.

Reviewed by Cursor Bugbot for commit f47cded. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f47cded. Configure here.

is_bad_query = (
original_error is None
or "Cannot query field" in error.formatted["message"]
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Server errors treated as client errors

Medium Severity

is_bad_query treats any GraphQL error without original_error as a client mistake. Execution failures like non-null violations and abstract type resolution also omit original_error, so they skip logging and Sentry capture, and authenticated clients receive unmasked internal error details.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit f47cded. Configure here.

@sentry

sentry Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Sentry needs additional GitHub App permissions

The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing.

Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update

@codecov-notifications

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 91.65%. Comparing base (65af8ae) to head (f47cded).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2450   +/-   ##
=======================================
  Coverage   91.65%   91.65%           
=======================================
  Files        1341     1341           
  Lines       53342    53345    +3     
  Branches     1649     1649           
=======================================
+ Hits        48888    48891    +3     
  Misses       4133     4133           
  Partials      321      321           
Flag Coverage Δ
apiunit 94.02% <100.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants