Skip to content

fix(graphql): prevent client validation errors from Sentry - #2454

Open
sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-validation-sentry-noise-oPQ3Ef
Open

sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-validation-sentry-noise-oPQ3Ef

Conversation

@sentry

@sentry sentry Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Previously, GraphQL validation errors, such as a client querying an object field (patchTotals) without selecting subfields, were being reported to Sentry as internal server errors. This was due to the error_formatter in apps/codecov-api/graphql_api/views.py having an insufficient check for client-side malformed queries.

This change modifies the error_formatter to correctly identify all GraphQL validation errors. These errors are characterized by having error.original_error as None, as they originate from the GraphQL validation layer rather than a resolver's execution. By checking for error.original_error is None, we can now accurately classify these as client errors.

As a result, these client-side validation errors will no longer trigger log.error and capture_exception calls, reducing Sentry noise and ensuring that only genuine internal server errors are reported.

Legal Boilerplate

Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.

Fixes API-F6Z

@sentry <feedback>: Autofix iterates on these changes
@sentry stop iterating: Autofix stops iterating on this run

This PR was automatically generated by Sentry. You can adjust this setting at any time.


Note

Low Risk
Narrows error classification in GraphQL response formatting only; lowers observability noise without changing resolver or auth logic.

Overview
GraphQL validation failures (malformed queries, missing subfield selections, unknown fields, etc.) were sometimes treated like internal server errors and sent to Sentry via log.error / capture_exception in error_formatter.

The formatter now treats any error with error.original_error is None as a client-side validation error (not only messages containing "Cannot query field"). Those errors return the normal GraphQL format_error response for all callers, and no longer require an authenticated user to see the real message. Genuine resolver/execution failures still flow through the masked INTERNAL SERVER ERROR path and Sentry when appropriate.

Reviewed by Cursor Bugbot for commit acd8f89. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit acd8f89. Configure here.

# selection of subfields") have no original_error — they originate from
# the validation layer, not from a resolver. Treat them as client errors.
is_bad_query = error.original_error is None
if debug or is_bad_query:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Anonymous users see schema validation details

Medium Severity

The not is_anonymous guard was dropped from the error_formatter early-return condition, so anonymous clients now receive raw GraphQL validation messages instead of INTERNAL SERVER ERROR. That exposes schema field and type names that production hides by disabling introspection, and user/is_anonymous are now unused.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit acd8f89. Configure here.

@sentry

sentry Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Sentry needs additional GitHub App permissions

The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing.

Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants