Skip to content

fix(graphql): prevent anonymous bad queries from being logged as internal errors - #2456

Open
sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-bad-query-logging-RYD8FB
Open

sentry[bot] wants to merge 1 commit into
mainfrom
seer/fix/graphql-bad-query-logging-RYD8FB

Conversation

@sentry

@sentry sentry Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Previously, anonymous GraphQL queries attempting to access non-existent fields (e.g., headReport on Pull type) were incorrectly logged as internal server errors and sent to Sentry.

The root cause was identified in apps/codecov-api/graphql_api/views.py within the error_formatter method. The condition to suppress client-side schema validation errors ("Cannot query field") only applied to authenticated users. As a result, anonymous requests with such errors would fall through to the generic error handling, triggering log.error and capture_exception.

This change modifies the condition on line 349 of apps/codecov-api/graphql_api/views.py to suppress these client-side validation errors for all users, regardless of their authentication status. This ensures that only genuine server-side issues are logged and reported to Sentry, reducing noise and improving error signal.

Legal Boilerplate

Look, I get it. The entity doing business as "Codecov" is owned by Harness, Inc. In 2026 Harness acquired Codecov and as a result Harness is going to need some rights from me in order to utilize my contributions in this PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Harness can use, modify, copy, and redistribute my contributions, under Harness's choice of terms.

Fixes API-F71

@sentry <feedback>: Autofix iterates on these changes
@sentry stop iterating: Autofix stops iterating on this run

This PR was automatically generated by Sentry. You can adjust this setting at any time.


Note

Low Risk
Single conditional change in GraphQL error formatting with no auth or data-path changes; main effect is logging/Sentry signal for anonymous bad queries.

Overview
GraphQL error handling no longer treats anonymous requests differently for invalid fields. In error_formatter, the branch that returns the real GraphQL validation message (when the error contains "Cannot query field") used to run only for authenticated users (debug or (not is_anonymous and is_bad_query)); it now runs for everyone (debug or is_bad_query).

Anonymous callers with malformed queries get the normal validation error in the response instead of a generic INTERNAL SERVER ERROR, so those cases skip the log.error / capture_exception path reserved for unexpected server failures. Authenticated behavior for this error type was already correct; this aligns anonymous traffic with that and cuts Sentry noise from client-side schema mistakes.

Reviewed by Cursor Bugbot for commit 87c26c2. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 87c26c2. Configure here.

# the only way to check for a malformed query
is_bad_query = "Cannot query field" in error.formatted["message"]
if debug or (not is_anonymous and is_bad_query):
if debug or is_bad_query:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Schema errors leaked to anonymous users

Medium Severity

Dropping the is_anonymous check returns raw GraphQL field-validation errors to unauthenticated clients. Production has introspection disabled, so those messages previously stayed hidden. The existing test_when_bad_query_and_anonymous test still expects INTERNAL SERVER ERROR, and this goes beyond only skipping Sentry for client-side validation failures.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 87c26c2. Configure here.

@sentry

sentry Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Sentry needs additional GitHub App permissions

The Sentry GitHub App installation for this repository is missing permissions it needs to keep iterating on this pull request to get CI passing.

Review and accept the updated permissions to let Seer continue: https://github.com/organizations/codecov/settings/installations/86101127/permissions/update

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants