eschutho commented on PR #43896:
URL: https://github.com/apache/superset/pull/43896#issuecomment-5963903364

   Thanks @rusackas — both addressed in 197954e969 (after merging master to 
clear the conflict):
   
   1. **Form-read fallback:** `request.form.get("guest_token")` is now wrapped 
in its own try/except and fails closed (redacts) if the body can't be read. I 
checked the pinned werkzeug (3.1.6): first access to `.form` can raise 
`RequestEntityTooLarge` (over `max_content_length` / `max_form_memory_size` / 
`max_form_parts`) or `ClientDisconnected` (truncated body) — both 
`HTTPException`s — plus `OSError` from the WSGI server's input stream 
(gunicorn's body-read errors are `OSError` subclasses) or the multipart 
temp-file spool. Parser `ValueError`s are already swallowed since the parser 
runs with `silent=True`. So the clause catches `(HTTPException, OSError)`. 
Added a test that drives a real oversized body through it; it raises 
`RequestEntityTooLarge` without the guard and passes with it.
   2. **Half-redaction test:** now uses a single raising `side_effect` and 
asserts the lookup happens exactly once, so the raising path the docstring 
describes is actually exercised.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to