eschutho commented on PR #43896:
URL: https://github.com/apache/superset/pull/43896#issuecomment-5964072544

   Follow-up in 6eba8b31d4: I've broadened the form-read guard to `except 
Exception`, so it now fails closed on *any* exception, as you originally asked. 
My earlier `(HTTPException, OSError)` turned out to be too narrow. When the 
server terminates the input stream (for example a chunked body under gunicorn), 
werkzeug reads the server's stream directly. gunicorn parses chunked trailers 
lazily inside that read and raises `ParseException` subclasses 
(`InvalidHeaderName`, `ObsoleteFolding`, …) on a malformed trailer. Those are 
plain `Exception`s, not `OSError`, so they still escaped as a bare 500. The 
inline comment records why the catch is deliberately broad.
   
   Tests: the unreadable-body test now uses a body with no token, so it can 
only pass by failing closed. It's parametrized over a real werkzeug 
`RequestEntityTooLarge` and a server stream whose `read()` raises a plain 
`Exception` subclass. The second case fails against the narrow catch and passes 
with the broad one. I also corrected two comments. One overstated the form 
fallback: a body whose first parse in the request loader already failed 
part-way re-parses as an empty form and is treated as token-free (no guest was 
authenticated on that request). The other overstated the chart-data sanitize 
block.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to