security: preview handlers leak raw err.Error() to clients #413

Closed
opened 2026-07-21 00:06:08 +02:00 by dries · 1 comment
Owner

Finding #7 (Low) from a security review.

Problem

The GitHub/Forgejo preview handlers return raw err.Error() (with a 502) to the browser. Transport errors from http.Client.Do embed the full request URL and other internal detail. No token leak (auth is header-borne), but this contradicts the rest of the codebase which deliberately genericizes errors via serverError (internal/server/server.go:632-634).

Refs

  • internal/server/handlers_integrations.go:90,102,113,175,187,198

Suggested fix

Return a generic client message and log the real error server-side, matching the serverError pattern used elsewhere.

Acceptance

  • Preview failures return a generic message to the client; detail only in server logs.
Finding #7 (Low) from a security review. ## Problem The GitHub/Forgejo preview handlers return raw `err.Error()` (with a 502) to the browser. Transport errors from `http.Client.Do` embed the full request URL and other internal detail. No token leak (auth is header-borne), but this contradicts the rest of the codebase which deliberately genericizes errors via `serverError` (`internal/server/server.go:632-634`). ## Refs - `internal/server/handlers_integrations.go:90,102,113,175,187,198` ## Suggested fix Return a generic client message and log the real error server-side, matching the `serverError` pattern used elsewhere. ## Acceptance - Preview failures return a generic message to the client; detail only in server logs.
Author
Owner

this is acceptable

this is acceptable
dries closed this issue 2026-07-21 11:09:47 +02:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dries/ocman#413
No description provided.