Homec4science

Convert some whiny exceptions into quiet MalformedRequest exceptions

Authored by epriestley <git@epriestley.com> on Aug 16 2016, 23:00.

Description

Convert some whiny exceptions into quiet MalformedRequest exceptions

Summary:
Fixes T11480. This cleans up the error logs a little by quieting three common errors which are really malformed requests:

  • The CSRF error happens when bots hit anything which does write checks.
  • The "wrong cookie domain" errors happen when bots try to use the security.alternate-file-domain to browse stuff like /auth/start/.
  • The "no phcid" errors happen when bots try to go through the login flow.

All of these are clearly communicated to human users, commonly encountered by bots, and not useful to log.

I collapsed the CSRFException type into a standard malformed request exception, since nothing catches it and I can't really come up with a reason why anything would ever care.

Test Plan:
Hit each error through some level of curl -H ... and/or fakery. Verified that they showed to users before/after, but no longer log.

Hit some other real errors, verified that they log.

Reviewers: chad

Reviewed By: chad

Maniphest Tasks: T11480

Differential Revision: https://secure.phabricator.com/D16402

Details

Committed
epriestley <git@epriestley.com>Aug 17 2016, 00:50
Pushed
aubortJan 31 2017, 17:16
Parents
rPHf50e550c9ea0: Correct various spelling errors
Branches
Unknown
Tags
Unknown

Event Timeline

epriestley <git@epriestley.com> committed rPH95cf83f14ead: Convert some whiny exceptions into quiet MalformedRequest exceptions (authored by epriestley <git@epriestley.com>).Aug 17 2016, 00:50