Page MenuHomePhabricator

Convert some whiny exceptions into quiet MalformedRequest exceptions
ClosedPublic

Authored by epriestley on Aug 16 2016, 9:07 PM.
Tags
None
Referenced Files
F18771100: D16402.id39447.diff
Wed, Oct 8, 5:33 PM
F18666118: D16402.id39444.diff
Wed, Sep 24, 5:59 AM
F18659233: D16402.id39444.diff
Sep 23 2025, 10:36 AM
F18647335: D16402.diff
Sep 19 2025, 12:50 PM
F18630010: D16402.diff
Sep 16 2025, 10:31 AM
F18507985: D16402.id.diff
Sep 5 2025, 2:33 AM
F18208610: D16402.id39447.diff
Aug 18 2025, 9:29 PM
F18084517: D16402.id.diff
Aug 5 2025, 3:53 PM
Subscribers
None

Details

Summary

Fixes T11480. This cleans up the error logs a little by quieting three common errors which are really malformed requests:

  • The CSRF error happens when bots hit anything which does write checks.
  • The "wrong cookie domain" errors happen when bots try to use the security.alternate-file-domain to browse stuff like /auth/start/.
  • The "no phcid" errors happen when bots try to go through the login flow.

All of these are clearly communicated to human users, commonly encountered by bots, and not useful to log.

I collapsed the CSRFException type into a standard malformed request exception, since nothing catches it and I can't really come up with a reason why anything would ever care.

Test Plan

Hit each error through some level of curl -H ... and/or fakery. Verified that they showed to users before/after, but no longer log.

Hit some other real errors, verified that they log.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Convert some whiny exceptions into quiet MalformedRequest exceptions.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: chad.
chad edited edge metadata.
This revision is now accepted and ready to land.Aug 16 2016, 10:43 PM
This revision was automatically updated to reflect the committed changes.