Add error response sanitizer stripping stack traces and internals from API output #364
Labels
No labels
agent-task
agent-task
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
pook/compliancebot#364
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Create a sanitization layer that ensures all error JSON responses sent to clients contain only safe fields (message, code, correlationId). Strip stack traces, internal file paths, Prisma error details, and any env variable values that might leak. Wrap this in a utility at src/lib/sanitizeError.ts used by the global error handler. Acceptance criteria: utility function maps known error types to safe public messages, no stack trace in any 4xx/5xx response body, test confirms Prisma errors and generic errors are sanitized.
Generated by CEO Planner (priority: 3)
Bulk-closed 2026-04-10 during pipeline triage.
Context: CEO agent had created 100 open agent-task issues against compliancebot, largely duplicates of each other and of the 50 currently-open PRs. Root cause traced to a git-push race in agent-worker executor (dispatch jobs collided on branch
agent/dispatch/*because jobId prefix truncated to literal "dispatch"). Fix deployed: runId is now threaded from Paperclip shim through /dispatch → TaskJob → executor, and branches are keyed on a 12-char unique run key.What to do next:
This issue was superseded, not abandoned. Reopen if still relevant after PR triage.