Repository navigation
fix(graphql): prevent client validation errors from being reported as server errors - #2450
sentry[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit f47cded. Configure here.
| is_bad_query = ( | ||
| original_error is None | ||
| or "Cannot query field" in error.formatted["message"] | ||
| ) |
There was a problem hiding this comment.
Server errors treated as client errors
Medium Severity
is_bad_query treats any GraphQL error without original_error as a client mistake. Execution failures like non-null violations and abstract type resolution also omit original_error, so they skip logging and Sentry capture, and authenticated clients receive unmasked internal error details.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit f47cded. Configure here.
|
The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing. Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! 🚀 New features to boost your workflow:
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2450 +/- ##
=======================================
Coverage 91.65% 91.65%
=======================================
Files 1341 1341
Lines 53342 53345 +3
Branches 1649 1649
=======================================
+ Hits 48888 48891 +3
Misses 4133 4133
Partials 321 321
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |


Previously, client-side GraphQL validation errors (e.g., querying a field that doesn't exist on a type) were being reported to Sentry as internal server errors. This occurred for two reasons:
error_formatteringraphql_api/views.pyonly applied its bad-query exemption to authenticated users. Anonymous users' invalid queries would fall through to the generic error handling, leading tolog.error("GraphQL internal server error")andcapture_exception.mechanism: ariadne.This change addresses both issues:
error_formatternow correctly identifies GraphQL validation errors (those without anoriginal_erroror containing "Cannot query field") as client errors for all users. For anonymous users, the response still masks schema details with "INTERNAL SERVER ERROR", but these errors are no longer logged or captured as internal server errors.settings_base.pynow explicitly disables theAriadneIntegration. This prevents duplicate capture of validation errors and ensures that only genuine, unexpected resolver exceptions (which are still explicitly captured byerror_formatter) are sent to Sentry.Legal Boilerplate
Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.
Fixes API-F7A
@sentry <feedback>: Autofix iterates on these changes@sentry stop iterating: Autofix stops iterating on this runThis PR was automatically generated by Sentry. You can adjust this setting at any time.
Note
Low Risk
Changes only error classification and Sentry integration for GraphQL; genuine resolver exceptions are still captured explicitly in error_formatter.
Overview
Stops GraphQL client validation errors (unknown fields, malformed queries) from being treated as internal server failures in observability.
Sentry:
sentry_sdk.initnow disablesAriadneIntegration, so the SDK no longer auto-reports schema/validation mistakes as unhandled errors. Real resolver failures remain reported viaAsyncGraphqlView.error_formatter.GraphQL responses:
error_formatterbroadens bad-query detection to errors with nooriginal_error(typical validation) or the existing"Cannot query field"check. Authenticated users still get full validation messages; anonymous users still see masked"INTERNAL SERVER ERROR"but those cases no longer hitlog.error/capture_exception.Reviewed by Cursor Bugbot for commit f47cded. Bugbot is set up for automated code reviews on this repo. Configure here.