You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 7e8e00f
Browse filesBrowse the repository at this point in the historyBrowse files
fix(stack-auth): a refused exchange's ServerError names the status, never the body
The Go binding's test for a 403 from the edge in front of the auth server
showed the access-key and OIDC refreshers putting the whole response body
into ServerError's message: "Server error: 403: <html>...nginx
CSAK...</html>". A body from the edge is an HTML page, and any body may
echo the credential the request carried, so under the rule on
ErrorPayload it never belongs in a message. With se_last_error that
message now crosses into every binding.
ServerError::refused builds the message from the status and, when the
body is the auth server's JSON error, its error_description, which the
rule allows. ServerError::unparseable replaces serde_json's message, which
can quote the body, with where the JSON broke. The refresh-lock join
failure no longer repeats tokio's error text. The body is still logged at
debug level where it was before.
The test that asserted the body was in the message now asserts it is not.
Refs #1099
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01URtfKsTToFUCRwq3g7gCUf
Copy file name to clipboardExpand all lines: .changeset/auth-error-codes-and-help.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,6 +7,7 @@ Auth failures carry more help, and their messages never quote a credential or an
7
7
-`REQUEST_ERROR`'s message no longer repeats the transport's own error, which can carry a URL with its query string. It gains `help` saying what to check.
8
8
-`INVALID_TOKEN` for a token whose claims do not decode no longer quotes the decoder's message, which could carry a byte or a claim of the token.
9
9
- A failed device binding reports ZeroKMS's status, not its response body.
10
+
-`SERVER_ERROR` for a refused token exchange names the HTTP status and the auth server's `error_description`, not the response body, which from the edge in front of it is an HTML page and can echo the access key. A body that is not JSON is reported by where it broke, not by the parser's message.
10
11
- A profile file that is not valid JSON is reported by error kind, line and column, not by the parser's message, which could quote the file.
11
12
-`INVALID_GRANT`, `INVALID_WORKSPACE_ID` and `ALREADY_CONSUMED` gain `help`, and `NOT_AUTHENTICATED`'s help names `stash auth login`.
12
13
- A `STORE_ERROR` carries the help of the profile failure underneath it, such as logging in again when the profile file is missing.
0 commit comments