Skip to content

feat(stealth-provider): redact error details in logs - #3090

Merged
steebchen merged 6 commits into
mainfrom
claude/stealth-provider-error-redaction-o8560e
Jul 17, 2026
Merged

steebchen merged 6 commits into
mainfrom
claude/stealth-provider-error-redaction-o8560e

Conversation

@steebchen

@steebchen steebchen commented Jul 16, 2026 •

Copy link
Copy Markdown
Member

Summary

Implements error redaction for stealth providers to prevent sensitive upstream error details from being exposed in logs and client responses. Stealth providers' errors are now redacted to only show HTTP status codes, while internal error details are stored separately for debugging.

Key Changes

  • New stealth provider error handling module (stealth-provider-errors.ts): Provides utilities to detect stealth providers and redact their error details, including:

    • shouldRedactProviderError() - determines if a provider's errors should be redacted
    • redactErrorDetails() - sanitizes error objects for stealth providers
    • redactedProviderErrorText() - generates client-facing error messages with only status codes
    • buildUpstreamErrorClientPayload() - constructs safe error payloads for responses
  • Database schema update: Added internalErrorDetails column to the log table to store raw upstream errors separately from the public errorDetails field

  • Log insertion logic (logs.ts): Updated to redact error details for stealth providers before storing in the public errorDetails field, while preserving raw errors in internalErrorDetails

  • Client error normalization (normalize-client-error.ts): Integrated stealth provider error redaction when normalizing errors for API responses

  • API routes: Updated log query schemas to include the new internalErrorDetails field in admin and public log endpoints

  • Comprehensive test coverage: Added unit tests for error redaction logic and log insertion behavior with stealth providers

Implementation Details

  • Stealth provider detection leverages the existing isStealthProvider() utility from the models package
  • Error redaction preserves HTTP status codes and canonical status text for debugging while hiding implementation details
  • The separation of errorDetails (public) and internalErrorDetails (internal) allows secure logging without exposing sensitive information to end users

https://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP

Summary by CodeRabbit

  • New Features

    • Added “stealth provider” error redaction across chat and embeddings, standardizing client-facing error messages while preventing upstream details from leaking.
  • Bug Fixes

    • Public log endpoints no longer expose internal error details or sensitive upstream identifiers.
    • Admin log views can now display additional internal error details for troubleshooting.
  • Tests

    • Added/extended test coverage for stealth-provider redaction and confirmed internal vs public log payload behavior.

For stealth providers, upstream error bodies (and network error
messages, which can embed the secret base URL) are no longer passed
through to clients or publicly visible log fields. Clients now receive
only the upstream HTTP status code with a generic message, in both
streaming and non-streaming responses.

The raw upstream error is preserved in a new internal-only
internalErrorDetails log column, which is excluded from the public
logs API and UI and only exposed on the admin-gated log endpoints.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP
Copilot AI review requested due to automatic review settings July 16, 2026 12:16
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: b5cfa546-1824-4c34-8803-1c868e982281

📥 Commits

Reviewing files that changed from the base of the PR and between 47b39d9 and 6b3278f.

📒 Files selected for processing (2)
  • apps/api/src/routes/logs.spec.ts
  • apps/gateway/src/stealth-error-redaction.spec.ts

Walkthrough

Changes

Stealth provider error redaction

Layer / File(s) Summary
Redaction helper contract
apps/gateway/src/lib/stealth-provider-errors.ts, apps/gateway/src/lib/stealth-provider-errors.spec.ts
Adds provider detection, canonical status text, redacted error formatting, and client payload construction with unit tests.
Internal log error storage
packages/db/src/schema.ts, packages/db/migrations/*, apps/gateway/src/lib/logs.ts, apps/gateway/src/lib/logs-stealth-redaction.spec.ts
Adds internalErrorDetails storage and separates raw stealth-provider details from sanitized errorDetails.
Gateway error response redaction
apps/gateway/src/chat/chat.ts, apps/gateway/src/embeddings/embeddings.ts, apps/gateway/src/chat/tools/*, apps/gateway/src/stealth-error-redaction.spec.ts
Applies redacted messaging and payloads across chat, embeddings, streaming, non-streaming, network, and normalized client errors.
Admin and public log projections
apps/api/src/routes/admin.ts, apps/api/src/routes/logs.ts, apps/api/src/routes/logs.spec.ts
Includes internal error details in admin project logs and excludes them from public log endpoints.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant Gateway
  participant UpstreamProvider
  participant LogStorage
  Client->>Gateway: Send chat or embeddings request
  Gateway->>UpstreamProvider: Request completion or embeddings
  UpstreamProvider-->>Gateway: Return provider error
  Gateway->>Gateway: Redact stealth-provider details
  Gateway-->>Client: Return sanitized error payload
  Gateway->>LogStorage: Store sanitized errorDetails and internalErrorDetails
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 62.50% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise and clearly reflects the main change: redacting error details in logs for stealth providers.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/stealth-provider-error-redaction-o8560e

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot changed the title Add stealth provider error redaction for logs and responses feat(stealth-provider): redact error details in logs Jul 16, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
apps/api/src/routes/admin.ts (1)

8340-8342: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Group by raw upstream errors for stealth providers.

The getUnstableMappingErrors endpoint aggregates errors to help admins troubleshoot provider instability. Because errorDetails is redacted for stealth providers, aggregating on it will mask the underlying failures and group everything under a generic message.

Use COALESCE to group by internalErrorDetails when available, ensuring admins see the true error distribution.

💡 Proposed fix
 		WITH recent_errors AS (
-			SELECT ${tables.log.errorDetails} AS error_details
+			SELECT COALESCE(${tables.log.internalErrorDetails}, ${tables.log.errorDetails}) AS error_details
 			FROM ${tables.log}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/api/src/routes/admin.ts` around lines 8340 - 8342, Update the
recent_errors query in getUnstableMappingErrors to group errors using
COALESCE(internalErrorDetails, errorDetails), preferring the raw internal
details when available while retaining the redacted details as fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@apps/api/src/routes/admin.ts`:
- Around line 8340-8342: Update the recent_errors query in
getUnstableMappingErrors to group errors using COALESCE(internalErrorDetails,
errorDetails), preferring the raw internal details when available while
retaining the redacted details as fallback.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: b096c990-ce77-4d2c-9762-77da7d20636d

📥 Commits

Reviewing files that changed from the base of the PR and between b37ce00 and 47b39d9.

📒 Files selected for processing (14)
  • apps/api/src/routes/admin.ts
  • apps/api/src/routes/logs.ts
  • apps/gateway/src/chat/chat.ts
  • apps/gateway/src/chat/tools/normalize-client-error.spec.ts
  • apps/gateway/src/chat/tools/normalize-client-error.ts
  • apps/gateway/src/embeddings/embeddings.ts
  • apps/gateway/src/lib/logs-stealth-redaction.spec.ts
  • apps/gateway/src/lib/logs.ts
  • apps/gateway/src/lib/stealth-provider-errors.spec.ts
  • apps/gateway/src/lib/stealth-provider-errors.ts
  • packages/db/migrations/1784204428_freezing_fabian_cortez.sql
  • packages/db/migrations/meta/1784204428_snapshot.json
  • packages/db/migrations/meta/_journal.json
  • packages/db/src/schema.ts

Adds route-level tests proving stealth provider errors are redacted on
/v1/chat/completions (non-streaming, streaming HTTP error, immediate and
mid-stream SSE errors), /v1/responses, /v1/messages (incl. streaming),
/v1/images/generations, and network failures, with raw errors preserved
only in internalErrorDetails. Also adds API tests asserting the public
log list/detail endpoints never return internalErrorDetails.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP
@steebchen
steebchen merged commit 7323b3d into main Jul 17, 2026
22 of 23 checks passed
@steebchen
steebchen deleted the claude/stealth-provider-error-redaction-o8560e branch July 17, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants