Commit 1e1b6b3
committed
fix(proxy): don't expose upstream exception detail in passthrough 502
The RemoteProtocolError handler added for the #1112 transient-retry fix
interpolated the raw httpx exception into the JSON error message returned
to the external client, so upstream stack-trace/exception text could leak
to callers (CodeQL py/stack-trace-exposure, alert #136 at openai.py:6341).
Keep the full exception in the server-side logger.warning (unchanged) and
return a generic "upstream closed the connection without sending a complete
response" message with the same 502 status. Only the flagged path is
touched; behaviour and the existing 502 contract are otherwise unchanged.1 parent 5ffdf21 commit 1e1b6b3
1 file changed
Lines changed: 5 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6486 | 6486 | | |
6487 | 6487 | | |
6488 | 6488 | | |
| 6489 | + | |
| 6490 | + | |
| 6491 | + | |
| 6492 | + | |
6489 | 6493 | | |
6490 | 6494 | | |
6491 | | - | |
| 6495 | + | |
6492 | 6496 | | |
6493 | 6497 | | |
6494 | 6498 | | |
| |||
0 commit comments