Skip to content

Commit 27ac53a

Browse files
authored
fix(server): stop exposing named defects (#27471)
1 parent 7801557 commit 27ac53a

2 files changed

Lines changed: 21 additions & 3 deletions

File tree

packages/opencode/src/server/routes/instance/httpapi/middleware/error.ts

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,6 @@ export const errorLayer = HttpRouter.middleware<{ handles: unknown }>()((effect)
2020
const error = defect.defect
2121
log.error("failed", { error, cause: Cause.pretty(cause) })
2222

23-
if (error instanceof NamedError) {
24-
return Effect.succeed(HttpServerResponse.jsonUnsafe(error.toObject(), { status: 500 }))
25-
}
2623
return Effect.succeed(
2724
HttpServerResponse.jsonUnsafe(
2825
new NamedError.Unknown({

packages/opencode/test/server/httpapi-error-middleware.test.ts

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
import { NodeHttpServer, NodeServices } from "@effect/platform-node"
2+
import { NamedError } from "@opencode-ai/core/util/error"
23
import { describe, expect } from "bun:test"
34
import { Effect, Layer } from "effect"
45
import { HttpClient, HttpClientRequest, HttpRouter } from "effect/unstable/http"
@@ -29,6 +30,26 @@ describe("HttpApi error middleware", () => {
2930
}),
3031
)
3132

33+
it.live("returns a safe body for named defects", () =>
34+
Effect.gen(function* () {
35+
yield* HttpRouter.add(
36+
"GET",
37+
"/named",
38+
Effect.die(new NamedError.Unknown({ message: "secret named marker" })),
39+
).pipe(Layer.provide(errorLayer), HttpRouter.serve, Layer.build)
40+
41+
const response = yield* HttpClientRequest.get("/named").pipe(HttpClient.execute)
42+
const body = yield* response.json
43+
44+
expect(response.status).toBe(500)
45+
expect(body).toEqual({
46+
name: "UnknownError",
47+
data: { message: "Unexpected server error. Check server logs for details." },
48+
})
49+
expect(JSON.stringify(body)).not.toContain("secret named marker")
50+
}),
51+
)
52+
3253
it.live("does not map storage not-found defects to 404", () =>
3354
Effect.gen(function* () {
3455
yield* HttpRouter.add(

0 commit comments

Comments
 (0)