Repository navigation
fix(api): suppress Sentry errors for anonymous bad GraphQL queries - #2452
sentry[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 996e22e. Configure here.
| # the only way to check for a malformed query | ||
| is_bad_query = "Cannot query field" in error.formatted["message"] | ||
| if debug or (not is_anonymous and is_bad_query): | ||
| if debug or is_bad_query: |
There was a problem hiding this comment.
Anonymous clients receive unmasked query errors
Medium Severity
The updated debug or is_bad_query check returns format_error for every Cannot query field error, including anonymous requests. That early return changes the client-facing message, not just Sentry capture, so unauthenticated callers now get schema details instead of the generic INTERNAL SERVER ERROR previously returned on that path.
Reviewed by Cursor Bugbot for commit 996e22e. Configure here.
|
The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing. Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update |


The
error_formatterinapps/codecov-api/graphql_api/views.pywas incorrectly configured to only suppress Sentry reporting for invalid GraphQL field queries (Cannot query field) from authenticated users. This meant that anonymous users making such malformed queries would trigger an internal server error log and Sentry capture.This change modifies the condition in
error_formatterto suppress these client-side GraphQL validation errors for all users, regardless of their authentication status. This reduces Sentry noise from expected client-side query mistakes.Legal Boilerplate
Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.
Fixes API-F76
@sentry <feedback>: Autofix iterates on these changes@sentry stop iterating: Autofix stops iterating on this runThis PR was automatically generated by Sentry. You can adjust this setting at any time.
Note
Low Risk
Single conditional change in GraphQL error handling; only affects how malformed field queries are formatted and whether they reach Sentry.
Overview
GraphQL
error_formatterno longer requires an authenticated user before treating invalid field queries as client errors.The early return that uses
format_error(and skips the generic INTERNAL SERVER ERROR path,log.error, andcapture_exception) now runs whenever the message containsCannot query field, not only whennot is_anonymous. Anonymous callers with malformed queries get the normal GraphQL validation message instead of being treated like unexpected server failures, which cuts Sentry noise from expected client mistakes.Reviewed by Cursor Bugbot for commit 996e22e. Bugbot is set up for automated code reviews on this repo. Configure here.