Skip to content

Auth middleware return only client msg - #2946

Merged
jakubno merged 2 commits into
mainfrom
fix/api-return-only-client-error
Jun 8, 2026
Merged

jakubno merged 2 commits into
mainfrom
fix/api-return-only-client-error

Conversation

@sitole

@sitole sitole commented Jun 8, 2026

Copy link
Copy Markdown
Member

Remove validation error possibly leaking internal informations.

Remove validation error possibly leaking internal informations.
@cursor

cursor Bot commented Jun 8, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Small, intentional hardening of auth error responses; internal errors remain logged and forbidden-team handling is unchanged.

Overview
On failed API key / token validation (except team forbidden cases, which are unchanged), the middleware no longer wraps the internal validationError.Err in the returned error. Clients only see the fixed guidance text plus ClientMsg; underlying validation failures (e.g. DB or wrapped errors) stay in telemetry via ReportError and are not propagated through %w.

Reviewed by Cursor Bugbot for commit 57a055b. Bugbot is set up for automated code reviews on this repo. Configure here.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

In packages/auth/pkg/auth/middleware.go, the fmt.Errorf call uses the %w verb but does not provide a corresponding error argument, which will cause a formatting error at runtime.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread packages/auth/pkg/auth/middleware.go Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 38fbc35. Configure here.

Comment thread packages/auth/pkg/auth/middleware.go Outdated
@codecov

codecov Bot commented Jun 8, 2026 •

Copy link
Copy Markdown

❌ 2 Tests Failed:

Tests completed Failed Passed Skipped
2746 2 2744 7
View the full list of 2 ❄️ flaky test(s)
github.com/e2b-dev/infra/tests/integration/internal/tests/orchestrator::TestSandboxMemoryIntegrity

Flake rate in main: 54.07% (Passed 919 times, Failed 1082 times)

Stack Traces | 65.2s run time
=== RUN   TestSandboxMemoryIntegrity
=== PAUSE TestSandboxMemoryIntegrity
=== CONT  TestSandboxMemoryIntegrity
    sandbox_memory_integrity_test.go:27: Build completed successfully
--- FAIL: TestSandboxMemoryIntegrity (65.21s)
github.com/e2b-dev/infra/tests/integration/internal/tests/orchestrator::TestSandboxMemoryIntegrity/tmpfs_hash

Flake rate in main: 54.14% (Passed 909 times, Failed 1073 times)

Stack Traces | 202s run time
=== RUN   TestSandboxMemoryIntegrity/tmpfs_hash
=== PAUSE TestSandboxMemoryIntegrity/tmpfs_hash
=== CONT  TestSandboxMemoryIntegrity/tmpfs_hash
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{start:{pid:1251}}
Executing command bash in sandbox i3xlxir7zgthpaheu4kp8 (user: root)
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stdout:"Total memory: 985 MB\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stdout:"Used memory before tmpfs mount: 187 MB\nFree memory before tmpfs mount: 796 MB\nMemory to use in integrity test (60% of free, min 64MB): 477 MB\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stderr:"477+0 records in\n477+0 records out\n500170752 bytes (500 MB, 477 MiB) copied, 2.04935 s, 244 MB/s\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stderr:"\tCommand being timed: \"dd if=/dev/urandom of=/mnt/testfile bs=1M count=477\"\n\tUser time (seconds): 0.00\n\tSystem time (seconds): 2.05\n\tPercent of CPU this job got: 99%\n\tElapsed (wall clock) time (h:mm:ss or m:ss): 0:02.07\n\tAverage shared text size (kbytes): 0\n\tAverage unshared data size (kbytes): 0\n\tAverage stack size (kbytes): 0\n\tAverage total size (kbytes): 0\n\tMaximum resident set size (kbytes): 2632\n\tAverage resident set size (kbytes): 0\n\tMajor (requiring I/O) page faults: 2\n\tMinor (reclaiming a frame) page faults: 342\n\tVoluntary context switches: 3\n\tInvoluntary context switches: 13\n\tSwaps: 0\n\tFile system inputs: 176\n\tFile system outputs: 0\n\tSocket messages sent: 0\n\tSocket messages received: 0\n\tSignals delivered: 0\n\tPage size (bytes): 4096\n\tExit status: 0\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stdout:"Used memory after tmpfs mount and file fill: 667 MB\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{end:{exited:true  status:"exit status 0"}}
    sandbox_memory_integrity_test.go:70: Command [bash] completed successfully in sandbox ii4ytoxha415sjmc6hkcw
Executing command bash in sandbox ii4ytoxha415sjmc6hkcw (user: root)
    sandbox_memory_integrity_test.go:80: Command [bash] output: event:{start:{pid:1268}}
Executing command bash in sandbox i3xlxir7zgthpaheu4kp8 (user: root)
    sandbox_memory_integrity_test.go:80: Command [bash] output: event:{data:{stdout:"bf1768ebe4a70233b66d68c6bd6de85dcbca87753215c35cdcbd779585a88cbd\n"}}
    sandbox_memory_integrity_test.go:80: Command [bash] output: event:{end:{exited:true  status:"exit status 0"}}
    sandbox_memory_integrity_test.go:80: Command [bash] completed successfully in sandbox ii4ytoxha415sjmc6hkcw
    sandbox_memory_integrity_test.go:80: Command [bash] output: event:{start:{pid:1271}}
Executing command bash in sandbox i3xlxir7zgthpaheu4kp8 (user: root)
    sandbox_memory_integrity_test.go:110: 
        	Error Trace:	.../tests/orchestrator/sandbox_memory_integrity_test.go:81
        	            				.../hostedtoolcache/go/1.26.3.../src/runtime/asm_amd64.s:1771
        	Error:      	Received unexpected error:
        	            	failed to execute command bash in sandbox ii4ytoxha415sjmc6hkcw: unavailable: HTTP status 502 Bad Gateway
    sandbox_memory_integrity_test.go:110: 
        	Error Trace:	.../tests/orchestrator/sandbox_memory_integrity_test.go:78
        	            				.../tests/orchestrator/sandbox_memory_integrity_test.go:110
        	Error:      	Condition never satisfied
        	Test:       	TestSandboxMemoryIntegrity/tmpfs_hash
--- FAIL: TestSandboxMemoryIntegrity/tmpfs_hash (201.85s)

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 38fbc35643

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread packages/auth/pkg/auth/middleware.go Outdated
Comment thread packages/auth/pkg/auth/middleware.go Outdated
@jakubno
jakubno merged commit d6aaa83 into main Jun 8, 2026
54 checks passed
@jakubno
jakubno deleted the fix/api-return-only-client-error branch June 8, 2026 14:10
Piwriw pushed a commit to Piwriw/infra that referenced this pull request Jun 12, 2026
Remove validation error possibly leaking internal informations.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants