Studio: don't leak exception details in RAG warmup/precache responses
CodeQL flagged information exposure through an exception in the /warmup
and /reranker/precache endpoints: both returned str(exc) in the JSON
body, exposing internal paths and stack details to the client. Keep
the full exception in the server-side warning log and return a generic
error message ('Failed to load embedder' / 'Failed to download
reranker') to the caller instead. The frontend only surfaces the
message in a toast, so a generic string is sufficient.
This commit is contained in:
parent
290201f62e
commit
95622dc405
1 changed files with 10 additions and 2 deletions
|
|
@ -466,8 +466,10 @@ def warmup_rag_embedder(
|
|||
try:
|
||||
embeddings.get_embedder(model_name)
|
||||
except Exception as exc: # noqa: BLE001
|
||||
# Log the detailed exception server-side; return a generic message
|
||||
# so internal paths / stack info aren't exposed to the client.
|
||||
logger.warning("RAG warmup failed for %s: %s", model_name, exc)
|
||||
return {"ok": False, "model": model_name, "error": str(exc)}
|
||||
return {"ok": False, "model": model_name, "error": "Failed to load embedder"}
|
||||
return {"ok": True, "model": model_name}
|
||||
|
||||
|
||||
|
|
@ -488,12 +490,18 @@ def precache_rag_reranker(
|
|||
try:
|
||||
precache_reranker()
|
||||
except Exception as exc: # noqa: BLE001
|
||||
# Detailed exception logged server-side; client gets a generic
|
||||
# message so internal paths / stack info aren't exposed.
|
||||
logger.warning(
|
||||
"RAG reranker precache failed",
|
||||
model = RAG_RERANKER_MODEL,
|
||||
error = str(exc),
|
||||
)
|
||||
return {"ok": False, "model": RAG_RERANKER_MODEL, "error": str(exc)}
|
||||
return {
|
||||
"ok": False,
|
||||
"model": RAG_RERANKER_MODEL,
|
||||
"error": "Failed to download reranker",
|
||||
}
|
||||
return {"ok": True, "model": RAG_RERANKER_MODEL}
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue