gabotorresruiz commented on code in PR #44666:
URL: https://github.com/apache/superset/pull/44666#discussion_r4190368808


##########
superset/views/error_handling.py:
##########
@@ -248,7 +248,15 @@ def refresh_csrf_token(ex: CSRFError) -> FlaskResponse:
 
     @app.errorhandler(HTTPException)
     def show_http_exception(ex: HTTPException) -> FlaskResponse:
-        logger.warning("HTTPException", exc_info=True)
+        status = ex.code or 500
+        if status == 404:
+            # Unmatched URLs are a client condition, and scanner traffic makes
+            # them frequent; a traceback here only adds noise.
+            logger.debug("HTTPException: 404 %r", request.path)

Review Comment:
   Confirmed on `4301016`: the masked denial in `core.py` now logs one WARNING 
with `/dashboard/<id>/` and no traceback, and the unmatched URL stays at DEBUG. 
Thanks for the quick turnaround.



##########
superset/views/error_handling.py:
##########
@@ -248,7 +248,15 @@ def refresh_csrf_token(ex: CSRFError) -> FlaskResponse:
 
     @app.errorhandler(HTTPException)
     def show_http_exception(ex: HTTPException) -> FlaskResponse:
-        logger.warning("HTTPException", exc_info=True)
+        status = ex.code or 500
+        if status == 404:
+            # Unmatched URLs are a client condition, and scanner traffic makes
+            # them frequent; a traceback here only adds noise.
+            logger.debug("HTTPException: 404 %r", request.path)
+        elif status < 500:
+            logger.warning("HTTPException: %r", str(ex))

Review Comment:
   Verified, the 403 and 405 records now carry the `%r` escaped path. Thanks.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to