Repository navigation
Commit 762a56c
fix(rhai): hide errors from the router's own Rhai functions from clients
The router's Rhai functions raised their errors as plain strings, the same
shape as a script's own `throw "..."`, so their text reached clients. Any
caller could learn which environment variables a script reads
(`env::get()` on an unset variable), or trigger parser errors from
`base64::decode()` and `json::decode()` on a client header.
Those functions now raise a `RouterFunctionError`. `process_error`
recognises it before the thrown-string branch: the client gets the status
code's reason phrase and the full text is logged. A thrown string that the
script chose still reaches the client unchanged.
Rhai prints a custom type by its type name, so the error is swapped for its
text before it is logged, and the script `log_*` functions do the same.
`to_string` and `to_debug` are registered so `${err}` in a script shows the
text.
This replaces `NO_CLIENT_MESSAGE`. A missing header now raises a message that
names the header, since that text no longer reaches the client.
A `catch` block that catches one of these errors now receives an error
object instead of a string. `${err}` still gives the message, but
`type_of(err)` and comparisons such as `err == "..."` change. The docs and
changeset call this out.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>1 parent 40abde7 commit 762a56c
9 files changed
Lines changed: 297 additions & 122 deletions
File tree
- .changesets
- apollo-router
- src/plugins/rhai
- engine
- snapshots
- tests
- fixtures
- integration
- docs/source/routing/customization/rhai
Lines changed: 7 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
26 | 30 | | |
27 | 31 | | |
28 | 32 | | |
29 | 33 | | |
30 | | - | |
| 34 | + | |
31 | 35 | | |
32 | 36 | | |
0 commit comments