A10: mask raw internal error text on CodeInternal responses #17
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#17
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
MapDBErrorfalls through toconnect.NewError(connect.CodeInternal, err)with the raw wrapped error (internal/services/svc/errors.go:57), and the pervasivefmt.Errorf("failed to X: %w", err)pattern rides the same path — including to unauthenticated callers via the auth interceptor (internal/auth/interceptor.go:117,145,161,190). Driver strings ("database is locked", pgx messages naming tables or constraints) cross the wire. No stack traces, paths, or secrets were observed.The "failures name their reason" system rule pulls the other way, so scope this to
CodeInternalonly: domain and validation errors stay verbatim.Fix: a final interceptor that keeps the code, replaces the Internal message with a generic reason plus a correlation id, and logs the detail server-side under that id.
Source: OWASP Top 10 (2025) audit of
v1.1.0, 2026-08-13. File references point at thev1.1.0tree.