Repository navigation
fix(graphql): prevent anonymous bad queries from being logged as internal errors - #2456
sentry[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 87c26c2. Configure here.
| # the only way to check for a malformed query | ||
| is_bad_query = "Cannot query field" in error.formatted["message"] | ||
| if debug or (not is_anonymous and is_bad_query): | ||
| if debug or is_bad_query: |
There was a problem hiding this comment.
Schema errors leaked to anonymous users
Medium Severity
Dropping the is_anonymous check returns raw GraphQL field-validation errors to unauthenticated clients. Production has introspection disabled, so those messages previously stayed hidden. The existing test_when_bad_query_and_anonymous test still expects INTERNAL SERVER ERROR, and this goes beyond only skipping Sentry for client-side validation failures.
Reviewed by Cursor Bugbot for commit 87c26c2. Configure here.
|
The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing. Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update |


Previously, anonymous GraphQL queries attempting to access non-existent fields (e.g.,
headReportonPulltype) were incorrectly logged as internal server errors and sent to Sentry.The root cause was identified in
apps/codecov-api/graphql_api/views.pywithin theerror_formattermethod. The condition to suppress client-side schema validation errors ("Cannot query field") only applied to authenticated users. As a result, anonymous requests with such errors would fall through to the generic error handling, triggeringlog.errorandcapture_exception.This change modifies the condition on line 349 of
apps/codecov-api/graphql_api/views.pyto suppress these client-side validation errors for all users, regardless of their authentication status. This ensures that only genuine server-side issues are logged and reported to Sentry, reducing noise and improving error signal.Legal Boilerplate
Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.
Fixes API-F71
@sentry <feedback>: Autofix iterates on these changes@sentry stop iterating: Autofix stops iterating on this runThis PR was automatically generated by Sentry. You can adjust this setting at any time.
Note
Low Risk
Single conditional change in GraphQL error formatting with no auth or data-path changes; main effect is logging/Sentry signal for anonymous bad queries.
Overview
GraphQL error handling no longer treats anonymous requests differently for invalid fields. In
error_formatter, the branch that returns the real GraphQL validation message (when the error contains"Cannot query field") used to run only for authenticated users (debug or (not is_anonymous and is_bad_query)); it now runs for everyone (debug or is_bad_query).Anonymous callers with malformed queries get the normal validation error in the response instead of a generic INTERNAL SERVER ERROR, so those cases skip the
log.error/capture_exceptionpath reserved for unexpected server failures. Authenticated behavior for this error type was already correct; this aligns anonymous traffic with that and cuts Sentry noise from client-side schema mistakes.Reviewed by Cursor Bugbot for commit 87c26c2. Bugbot is set up for automated code reviews on this repo. Configure here.