security: preview handlers leak raw err.Error() to clients #413
Labels
No labels
backend
bug
chore
duplication
effort:complex
effort:medium
effort:trivial
enhancement
follow-up
frontend
fullstack
priority:high
ready-for-agent
refactor
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
dries/ocman#413
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Finding #7 (Low) from a security review.
Problem
The GitHub/Forgejo preview handlers return raw
err.Error()(with a 502) to the browser. Transport errors fromhttp.Client.Doembed the full request URL and other internal detail. No token leak (auth is header-borne), but this contradicts the rest of the codebase which deliberately genericizes errors viaserverError(internal/server/server.go:632-634).Refs
internal/server/handlers_integrations.go:90,102,113,175,187,198Suggested fix
Return a generic client message and log the real error server-side, matching the
serverErrorpattern used elsewhere.Acceptance
this is acceptable