A10: mask raw internal error text on CodeInternal responses #17

Closed
opened 2026-08-13 09:35:04 +00:00 by nalum · 0 comments
Owner

MapDBError falls through to connect.NewError(connect.CodeInternal, err) with the raw wrapped error (internal/services/svc/errors.go:57), and the pervasive fmt.Errorf("failed to X: %w", err) pattern rides the same path — including to unauthenticated callers via the auth interceptor (internal/auth/interceptor.go:117,145,161,190). Driver strings ("database is locked", pgx messages naming tables or constraints) cross the wire. No stack traces, paths, or secrets were observed.

The "failures name their reason" system rule pulls the other way, so scope this to CodeInternal only: domain and validation errors stay verbatim.

Fix: a final interceptor that keeps the code, replaces the Internal message with a generic reason plus a correlation id, and logs the detail server-side under that id.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

`MapDBError` falls through to `connect.NewError(connect.CodeInternal, err)` with the raw wrapped error (`internal/services/svc/errors.go:57`), and the pervasive `fmt.Errorf("failed to X: %w", err)` pattern rides the same path — including to unauthenticated callers via the auth interceptor (`internal/auth/interceptor.go:117,145,161,190`). Driver strings ("database is locked", pgx messages naming tables or constraints) cross the wire. No stack traces, paths, or secrets were observed. The "failures name their reason" system rule pulls the other way, so scope this to `CodeInternal` only: domain and validation errors stay verbatim. **Fix**: a final interceptor that keeps the code, replaces the Internal message with a generic reason plus a correlation id, and logs the detail server-side under that id. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:47 +00:00
nalum closed this issue 2026-08-13 11:39:12 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#17
No description provided.