aminghadersohi opened a new pull request, #44666:
URL: https://github.com/apache/superset/pull/44666
### SUMMARY
`show_http_exception` logged every `HTTPException` at WARNING with
`exc_info=True`, regardless of status. A request for a URL with no matching
route (werkzeug routing `NotFound`) therefore produced a multi-line WARNING
with a traceback ending in `werkzeug/routing/map.py`. That is a client
condition, not a server fault. Scanner and bot traffic turn it into a steady
stream of warnings that bury real ones and read like server errors during
triage.
This change picks the log level from the status code:
| Status | Before | After |
|---|---|---|
| 404 | WARNING + traceback | DEBUG, single line (`HTTPException: 404
<path>`) |
| other 4xx | WARNING + traceback | WARNING, single line (`HTTPException:
<code> <name>: <description>`), no traceback |
| 5xx (e.g. 502/503/504) | WARNING + traceback | unchanged |
Why these levels:
- **404 → DEBUG.** Unmatched URLs are the high-volume case and carry no
actionable server-side signal. DEBUG keeps the path available when someone
turns up the logger, without emitting a line per scanner hit at the default
INFO level.
- **Other 4xx → WARNING without traceback.** This matches what
`get_logger_from_status` already does for 4xx `SupersetException`s (WARNING),
so 400/401/403/405 etc. stay visible. The traceback is dropped because it only
ever points into werkzeug/Flask dispatch or at the `abort()` call, which says
nothing about a server fault.
- **5xx → unchanged.** Server faults keep their traceback.
`InternalServerError` does not reach this handler at all: it is routed to
`show_unexpected_exception` via `errorhandler(500)`, which is not modified here
and still logs with a traceback. A test pins that too.
The response is unchanged: same status code, same branded 404 HTML page
(with its JSON fallback when the page is not built), and the same JSON error
body. `refresh_csrf_token` (which handles `CSRFError`, a `BadRequest` subclass)
is not touched, and its existing tests still pass.
### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
N/A (logging only).
Before, `GET /no-such-path`:
```
WARNING superset.views.error_handling: HTTPException
Traceback (most recent call last):
...
File ".../werkzeug/routing/map.py", line 629, in match
raise NotFound() from None
werkzeug.exceptions.NotFound: 404 Not Found: ...
```
After: nothing at INFO or above; with DEBUG enabled, `HTTPException: 404
/no-such-path`.
### TESTING INSTRUCTIONS
```
pytest tests/unit_tests/views/test_error_handling.py
```
New `TestShowHttpException` cases:
- routing 404 → at most one sub-WARNING, single-line record, no `exc_info`
- 400/401/403 → exactly one WARNING, no `exc_info`
- 502/503/504 → WARNING with `exc_info` for the raised exception
- `InternalServerError` → still logged with a traceback
- 404 with `Accept: text/html` → branded `404.html`, and the JSON fallback
when the page is missing
- 404/403/504 JSON bodies unchanged
Manually: run Superset, request a nonexistent path, and confirm no
WARNING/traceback appears in the server log while the 404 page still renders.
### ADDITIONAL INFORMATION
- [ ] Has associated issue:
- [ ] Required feature flags:
- [ ] Changes UI
- [ ] Includes DB Migration (follow approval process in
[SIP-59](https://github.com/apache/superset/issues/13351))
- [ ] Migration is atomic, supports rollback & is backwards-compatible
- [ ] Confirm DB migration upgrade and downgrade tested
- [ ] Runtime estimates and downtime expectations provided
- [ ] Introduces new feature or API
- [ ] Removes existing feature or API
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]