Repository navigation
fix(sentry-app): Adds better validation for invalid token request bodies - #80289
Merged
Merged
Conversation
ameliahsu
approved these changes
Nov 5, 2024
Contributor
|
curious Q: How does this fix SENTRY-3HBC ? Were we passing in |
cathteng
approved these changes
Nov 5, 2024
markstory
approved these changes
Nov 5, 2024
markstory
left a comment
Member
There was a problem hiding this comment.
Looks good to me. I tried locally with empty string and the response codes were correct as well.
GabeVillalobos
enabled auto-merge (squash)
November 5, 2024 22:33
Contributor
|
@Christinarlong Yup, no |
GabeVillalobos
disabled auto-merge
November 5, 2024 22:46
GabeVillalobos
enabled auto-merge (squash)
November 5, 2024 22:55
jan-auer
added a commit
that referenced
this pull request
Nov 6, 2024
* master: (67 commits) feat(dynamic-sampling): Sampling breakdown (#80304) feat(profiling): add organizations:continuous-profiling to the list of exposable features (#80236) chore(broadcasts): remove cta column from broadcast model (#80201) feat(dynamic-sampling): Use sample rates endpoint (#80235) feat(issues): Rearrange all events columns, sizes (#80296) fix(issues): All event table pagination counts (#80297) fix(issues): Preserve query parameters on all events close (#80295) feat(issues): Hide "comment" button until focused (#80283) fix(sentry-app): Adds better validation for invalid token request bodies (#80289) feat(workflow_engine): Add in hook for producing occurrences from the stateful detector (#80168) feat(issue summary) New structured issue summary design (#80273) feat(workflow_engine): Return status change messages when a stateful detector resolves (#80122) feat(insights): Add insights query date range footer hook (#80276) ref(crons): Switch to cronsim in sample data generator (#80278) feat(issue-details): Hide merged/similar issues for non-error issues (#80284) feat(issue summary) Update issue summary model (#80270) feat(crons): Add cronsim behind an option (#80271) fix(anomaly detection): add alerts analytics reqs to utils/analytics.tsx (#80281) feat(trace-explorer): Sort traces by timestamp in EAP (#80274) feat(workflow_engine): Implement basic evaluation in `DataCondition` (#80118) ...
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes SENTRY-3HBC
Adds serializers for both token Authorization and Refresh flows.
This affects POST requests to the
/sentry-app-installations/<uuid>/authorization/endpoint, providing explicit 400 status codes with invalid field information when a request body is misconfigured.Additional Context
Some fields in the request body (such as
client_idandsecret), are validated by a a separate Authentication flow prior to the defined serializer code, resulting in a 401 exception instead, hence the tests asserting for both cases.