Skip to content

fix(api): suppress Sentry errors for anonymous bad GraphQL queries - #2452

Open
sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/suppress-anon-gql-errors
Open

sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/suppress-anon-gql-errors

Conversation

@sentry

@sentry sentry Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

The error_formatter in apps/codecov-api/graphql_api/views.py was incorrectly configured to only suppress Sentry reporting for invalid GraphQL field queries (Cannot query field) from authenticated users. This meant that anonymous users making such malformed queries would trigger an internal server error log and Sentry capture.

This change modifies the condition in error_formatter to suppress these client-side GraphQL validation errors for all users, regardless of their authentication status. This reduces Sentry noise from expected client-side query mistakes.

Legal Boilerplate

Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.

Fixes API-F76

@sentry <feedback>: Autofix iterates on these changes
@sentry stop iterating: Autofix stops iterating on this run

This PR was automatically generated by Sentry. You can adjust this setting at any time.


Note

Low Risk
Single conditional change in GraphQL error handling; only affects how malformed field queries are formatted and whether they reach Sentry.

Overview
GraphQL error_formatter no longer requires an authenticated user before treating invalid field queries as client errors.

The early return that uses format_error (and skips the generic INTERNAL SERVER ERROR path, log.error, and capture_exception) now runs whenever the message contains Cannot query field, not only when not is_anonymous. Anonymous callers with malformed queries get the normal GraphQL validation message instead of being treated like unexpected server failures, which cuts Sentry noise from expected client mistakes.

Reviewed by Cursor Bugbot for commit 996e22e. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 996e22e. Configure here.

# the only way to check for a malformed query
is_bad_query = "Cannot query field" in error.formatted["message"]
if debug or (not is_anonymous and is_bad_query):
if debug or is_bad_query:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Anonymous clients receive unmasked query errors

Medium Severity

The updated debug or is_bad_query check returns format_error for every Cannot query field error, including anonymous requests. That early return changes the client-facing message, not just Sentry capture, so unauthenticated callers now get schema details instead of the generic INTERNAL SERVER ERROR previously returned on that path.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 996e22e. Configure here.

@sentry

sentry Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Sentry needs additional GitHub App permissions

The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing.

Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants