Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,8 @@
**Vulnerability:** The FastAPI application was missing the `Referrer-Policy` security header, which could leak sensitive path information or query parameters via the `Referer` header to external sites when navigating away from the application.
**Learning:** Even when setting strict `Content-Security-Policy` and `X-Frame-Options`, `Referrer-Policy` is needed to prevent cross-origin information leakage on outbound requests.
**Prevention:** Always include `Referrer-Policy: no-referrer` in the global security headers middleware to strictly drop referrer information on all outbound requests.

## 2026-07-28 - Explicitly log exceptions in custom FastAPI exception handlers
**Vulnerability:** The global `Exception` handler bypassed Starlette's `ServerErrorMiddleware`, swallowing exceptions and blinding operators to critical server errors.
**Learning:** When overriding a global `Exception` handler in FastAPI/Starlette, the built-in exception logging is bypassed.
**Prevention:** Always explicitly log the exception (e.g., `log.error("Unhandled exception", exc_info=_exc)`) inside global exception handlers to preserve visibility.
1 change: 1 addition & 0 deletions src/tacet/serve/server.py
Original file line number Diff line number Diff line change
Expand Up @@ -357,6 +357,7 @@ async def add_security_headers(request: Request, call_next):

@app.exception_handler(Exception)
async def unhandled_exception_handler(request: Request, _exc: Exception) -> Response:
log.error("Unhandled server error", exc_info=_exc)
response = PlainTextResponse("Internal Server Error", status_code=500)
return _apply_security_headers(response, request.url.path)

Expand Down
Loading