Skip to content
This repository was archived by the owner on Jun 13, 2025. It is now read-only.

Commit e8a5caf

Browse files
authored
fix: Don't show detailed errors for anonymous users (#956)
1 parent 02f2f83 commit e8a5caf

File tree

2 files changed

+13
-2
lines changed

2 files changed

+13
-2
lines changed

graphql_api/tests/test_views.py

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ async def test_when_debug_is_false_and_exception_we_know(self):
113113
assert data["errors"][0]["type"] == "Unauthorized"
114114
assert data["errors"][0].get("extensions") is None
115115

116-
@override_settings(DEBUG=False)
116+
@override_settings(DEBUG=True)
117117
async def test_when_bad_query(self):
118118
schema = generate_schema_that_raise_with(Unauthorized())
119119
data = await self.do_query(schema, " { fieldThatDoesntExist }")
@@ -123,6 +123,13 @@ async def test_when_bad_query(self):
123123
== "Cannot query field 'fieldThatDoesntExist' on type 'Query'."
124124
)
125125

126+
@override_settings(DEBUG=False)
127+
async def test_when_bad_query_and_anonymous(self):
128+
schema = generate_schema_that_raise_with(Unauthorized())
129+
data = await self.do_query(schema, " { fieldThatDoesntExist }")
130+
assert data["errors"] is not None
131+
assert data["errors"][0]["message"] == "INTERNAL SERVER ERROR"
132+
126133
@override_settings(DEBUG=False, GRAPHQL_QUERY_COST_THRESHOLD=1000)
127134
@patch("logging.Logger.error")
128135
async def test_when_costly_query(self, mock_error_logger):

graphql_api/views.py

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -293,6 +293,8 @@ async def post(self, request, *args, **kwargs):
293293

294294
def context_value(self, request, *_):
295295
request_body = json.loads(request.body.decode("utf-8")) if request.body else {}
296+
self.request = request
297+
296298
return {
297299
"request": request,
298300
"service": request.resolver_match.kwargs["service"],
@@ -301,9 +303,11 @@ def context_value(self, request, *_):
301303
}
302304

303305
def error_formatter(self, error, debug=False):
306+
user = self.request.user
307+
is_anonymous = user.is_anonymous if user else True
304308
# the only way to check for a malformed query
305309
is_bad_query = "Cannot query field" in error.formatted["message"]
306-
if debug or is_bad_query:
310+
if debug or (not is_anonymous and is_bad_query):
307311
return format_error(error, debug)
308312
formatted = error.formatted
309313
formatted["message"] = "INTERNAL SERVER ERROR"

0 commit comments

Comments
 (0)