Repository navigation
feat(stealth-provider): redact error details in logs - #3090
Conversation
For stealth providers, upstream error bodies (and network error messages, which can embed the secret base URL) are no longer passed through to clients or publicly visible log fields. Clients now receive only the upstream HTTP status code with a generic message, in both streaming and non-streaming responses. The raw upstream error is preserved in a new internal-only internalErrorDetails log column, which is excluded from the public logs API and UI and only exposed on the admin-gated log endpoints. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
WalkthroughChangesStealth provider error redaction
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant Client
participant Gateway
participant UpstreamProvider
participant LogStorage
Client->>Gateway: Send chat or embeddings request
Gateway->>UpstreamProvider: Request completion or embeddings
UpstreamProvider-->>Gateway: Return provider error
Gateway->>Gateway: Redact stealth-provider details
Gateway-->>Client: Return sanitized error payload
Gateway->>LogStorage: Store sanitized errorDetails and internalErrorDetails
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP
…er-error-redaction-o8560e
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP
…er-error-redaction-o8560e
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
apps/api/src/routes/admin.ts (1)
8340-8342: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winGroup by raw upstream errors for stealth providers.
The
getUnstableMappingErrorsendpoint aggregates errors to help admins troubleshoot provider instability. BecauseerrorDetailsis redacted for stealth providers, aggregating on it will mask the underlying failures and group everything under a generic message.Use
COALESCEto group byinternalErrorDetailswhen available, ensuring admins see the true error distribution.💡 Proposed fix
WITH recent_errors AS ( - SELECT ${tables.log.errorDetails} AS error_details + SELECT COALESCE(${tables.log.internalErrorDetails}, ${tables.log.errorDetails}) AS error_details FROM ${tables.log}🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@apps/api/src/routes/admin.ts` around lines 8340 - 8342, Update the recent_errors query in getUnstableMappingErrors to group errors using COALESCE(internalErrorDetails, errorDetails), preferring the raw internal details when available while retaining the redacted details as fallback.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@apps/api/src/routes/admin.ts`:
- Around line 8340-8342: Update the recent_errors query in
getUnstableMappingErrors to group errors using COALESCE(internalErrorDetails,
errorDetails), preferring the raw internal details when available while
retaining the redacted details as fallback.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: b096c990-ce77-4d2c-9762-77da7d20636d
📒 Files selected for processing (14)
apps/api/src/routes/admin.tsapps/api/src/routes/logs.tsapps/gateway/src/chat/chat.tsapps/gateway/src/chat/tools/normalize-client-error.spec.tsapps/gateway/src/chat/tools/normalize-client-error.tsapps/gateway/src/embeddings/embeddings.tsapps/gateway/src/lib/logs-stealth-redaction.spec.tsapps/gateway/src/lib/logs.tsapps/gateway/src/lib/stealth-provider-errors.spec.tsapps/gateway/src/lib/stealth-provider-errors.tspackages/db/migrations/1784204428_freezing_fabian_cortez.sqlpackages/db/migrations/meta/1784204428_snapshot.jsonpackages/db/migrations/meta/_journal.jsonpackages/db/src/schema.ts
Adds route-level tests proving stealth provider errors are redacted on /v1/chat/completions (non-streaming, streaming HTTP error, immediate and mid-stream SSE errors), /v1/responses, /v1/messages (incl. streaming), /v1/images/generations, and network failures, with raw errors preserved only in internalErrorDetails. Also adds API tests asserting the public log list/detail endpoints never return internalErrorDetails. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP
Summary
Implements error redaction for stealth providers to prevent sensitive upstream error details from being exposed in logs and client responses. Stealth providers' errors are now redacted to only show HTTP status codes, while internal error details are stored separately for debugging.
Key Changes
New stealth provider error handling module (
stealth-provider-errors.ts): Provides utilities to detect stealth providers and redact their error details, including:shouldRedactProviderError()- determines if a provider's errors should be redactedredactErrorDetails()- sanitizes error objects for stealth providersredactedProviderErrorText()- generates client-facing error messages with only status codesbuildUpstreamErrorClientPayload()- constructs safe error payloads for responsesDatabase schema update: Added
internalErrorDetailscolumn to thelogtable to store raw upstream errors separately from the publicerrorDetailsfieldLog insertion logic (
logs.ts): Updated to redact error details for stealth providers before storing in the publicerrorDetailsfield, while preserving raw errors ininternalErrorDetailsClient error normalization (
normalize-client-error.ts): Integrated stealth provider error redaction when normalizing errors for API responsesAPI routes: Updated log query schemas to include the new
internalErrorDetailsfield in admin and public log endpointsComprehensive test coverage: Added unit tests for error redaction logic and log insertion behavior with stealth providers
Implementation Details
isStealthProvider()utility from the models packageerrorDetails(public) andinternalErrorDetails(internal) allows secure logging without exposing sensitive information to end usershttps://claude.ai/code/session_01JNdfzqa2xoAXnPGWWwfzkP
Summary by CodeRabbit
New Features
Bug Fixes
Tests