-
-
Notifications
You must be signed in to change notification settings - Fork 10.3k
Harden selected API error responses #5032
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
028f301
18b992b
47a50cd
8936976
492a271
a9e4401
bfd8753
f042f24
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -10,6 +10,7 @@ import { mergeOpenCodeConfigText } from "@/shared/services/opencodeConfig"; | |
| import { guideSettingsSaveSchema } from "@/shared/validation/schemas"; | ||
| import { isValidationFailure, validateBody } from "@/shared/validation/helpers"; | ||
| import { resolveApiKey, getOrCreateApiKey } from "@/shared/services/apiKeyResolver"; | ||
| import { sanitizeErrorMessage } from "@omniroute/open-sse/utils/error"; | ||
|
|
||
| /** | ||
| * POST /api/cli-tools/guide-settings/:toolId | ||
|
|
@@ -77,7 +78,10 @@ export async function POST(request, { params }) { | |
| ); | ||
| } | ||
| } catch (error) { | ||
| return NextResponse.json({ error: (error as any).message }, { status: 500 }); | ||
| return NextResponse.json( | ||
| { error: sanitizeErrorMessage(error instanceof Error ? error.message : String(error)) }, | ||
| { status: 500 } | ||
| ); | ||
|
Comment on lines
+81
to
+84
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If const rawMessage =
error instanceof Error
? error.message
: error && typeof error === "object" && "message" in error
? String((error as any).message)
: String(error ?? "");
return NextResponse.json(
{ error: sanitizeErrorMessage(rawMessage) },
{ status: 500 }
); |
||
| } | ||
| } | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,6 +1,7 @@ | ||
| import { exportCallLogsSince } from "@/lib/usage/callLogs"; | ||
| import { requireManagementAuth } from "@/lib/api/requireManagementAuth"; | ||
| import { exportProxyLogsSince } from "@/lib/db/proxyLogs"; | ||
| import { sanitizeErrorMessage } from "@omniroute/open-sse/utils/error"; | ||
|
|
||
| /** | ||
| * GET /api/logs/export — export logs as JSON | ||
|
|
@@ -47,7 +48,12 @@ export async function GET(request: Request) { | |
| ); | ||
| } catch (error) { | ||
| return Response.json( | ||
| { error: { message: (error as Error).message, type: "server_error" } }, | ||
| { | ||
| error: { | ||
| message: sanitizeErrorMessage(error instanceof Error ? error.message : String(error)), | ||
| type: "server_error", | ||
| }, | ||
| }, | ||
| { status: 500 } | ||
| ); | ||
|
Comment on lines
50
to
58
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If const rawMessage =
error instanceof Error
? error.message
: error && typeof error === "object" && "message" in error
? String((error as any).message)
: String(error ?? "");
return Response.json(
{
error: {
message: sanitizeErrorMessage(rawMessage),
type: "server_error",
},
},
{ status: 500 }
); |
||
| } | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -5,6 +5,7 @@ import { isAuthRequired, isAuthenticated } from "@/shared/utils/apiAuth"; | |
| import { runJsonMigration, type LegacyJsonData } from "@/lib/db/jsonMigration"; | ||
| import { getSettings } from "@/lib/db/settings"; | ||
| import { setSystemPromptConfig } from "@omniroute/open-sse/services/systemPrompt.ts"; | ||
| import { sanitizeErrorMessage } from "@omniroute/open-sse/utils/error"; | ||
|
|
||
| /** | ||
| * POST /api/settings/import-json | ||
|
|
@@ -88,6 +89,9 @@ export async function POST(request: Request) { | |
| }); | ||
| } catch (err) { | ||
| console.error("[API] Error importing JSON backup:", err); | ||
| return NextResponse.json({ error: (err as Error).message }, { status: 500 }); | ||
| return NextResponse.json( | ||
| { error: sanitizeErrorMessage(err instanceof Error ? err.message : String(err)) }, | ||
| { status: 500 } | ||
| ); | ||
|
Comment on lines
+92
to
+95
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If const rawMessage =
err instanceof Error
? err.message
: err && typeof err === "object" && "message" in err
? String((err as any).message)
: String(err ?? "");
return NextResponse.json(
{ error: sanitizeErrorMessage(rawMessage) },
{ status: 500 }
); |
||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,17 @@ | ||
| import { getProxyLogs, clearProxyLogs, getProxyLogStats } from "@/lib/proxyLogger"; | ||
| import { getProxyLogs, clearProxyLogs } from "@/lib/proxyLogger"; | ||
| import { sanitizeErrorMessage } from "@omniroute/open-sse/utils/error"; | ||
|
|
||
| function serverErrorResponse(error: unknown): Response { | ||
| return Response.json( | ||
| { | ||
| error: { | ||
| message: sanitizeErrorMessage(error instanceof Error ? error.message : String(error)), | ||
| type: "server_error", | ||
| }, | ||
| }, | ||
| { status: 500 } | ||
| ); | ||
|
Comment on lines
+5
to
+13
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If const rawMessage =
error instanceof Error
? error.message
: error && typeof error === "object" && "message" in error
? String((error as any).message)
: String(error ?? "");
return Response.json(
{
error: {
message: sanitizeErrorMessage(rawMessage),
type: "server_error",
},
},
{ status: 500 }
); |
||
| } | ||
|
|
||
| /** | ||
| * GET /api/usage/proxy-logs — get proxy usage logs | ||
|
|
@@ -19,10 +32,7 @@ export async function GET(request: Request) { | |
| const logs = getProxyLogs(filters); | ||
| return Response.json(logs); | ||
| } catch (error) { | ||
| return Response.json( | ||
| { error: { message: (error as any).message, type: "server_error" } }, | ||
| { status: 500 } | ||
| ); | ||
| return serverErrorResponse(error); | ||
| } | ||
| } | ||
|
|
||
|
|
@@ -34,9 +44,6 @@ export async function DELETE() { | |
| clearProxyLogs(); | ||
| return Response.json({ cleared: true }); | ||
| } catch (error) { | ||
| return Response.json( | ||
| { error: { message: (error as any).message, type: "server_error" } }, | ||
| { status: 500 } | ||
| ); | ||
| return serverErrorResponse(error); | ||
| } | ||
| } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If
erroris a plain object with amessageproperty (e.g., forwarded from an upstream API or library) rather than a directErrorinstance,error instanceof Errorwill be false, resulting inString(error)returning"[object Object]". This can be improved by safely checking for amessageproperty on the object.