eschutho commented on PR #43896: URL: https://github.com/apache/superset/pull/43896#issuecomment-5964072544
Follow-up in 6eba8b31d4: I've broadened the form-read guard to `except Exception`, so it now fails closed on *any* exception, as you originally asked. My earlier `(HTTPException, OSError)` turned out to be too narrow. When the server terminates the input stream (for example a chunked body under gunicorn), werkzeug reads the server's stream directly. gunicorn parses chunked trailers lazily inside that read and raises `ParseException` subclasses (`InvalidHeaderName`, `ObsoleteFolding`, …) on a malformed trailer. Those are plain `Exception`s, not `OSError`, so they still escaped as a bare 500. The inline comment records why the catch is deliberately broad. Tests: the unreadable-body test now uses a body with no token, so it can only pass by failing closed. It's parametrized over a real werkzeug `RequestEntityTooLarge` and a server stream whose `read()` raises a plain `Exception` subclass. The second case fails against the narrow catch and passes with the broad one. I also corrected two comments. One overstated the form fallback: a body whose first parse in the request loader already failed part-way re-parses as an empty form and is treated as token-free (no guest was authenticated on that request). The other overstated the chart-data sanitize block. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
