Skip to content

Conversation

@cursor
Copy link
Contributor

@cursor cursor bot commented Nov 19, 2025

Refactors OAuth error handling to sanitize and validate error codes from identity providers before logging or displaying them. This prevents arbitrary user-controlled input from being reflected in logs and error messages, mitigating potential security vulnerabilities. Only known, safe error codes are now included in user-facing messages.

Legal Boilerplate

Look, I get it. The entity doing business as "Sentry" was incorporated in the State of Delaware in 2015 as Functional Software, Inc. and is gonna need some rights from me in order to utilize my contributions in this here PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Sentry can use, modify, copy, and redistribute my contributions, under Sentry's choice of terms.


Open in Cursor Open in Web

This change introduces a new utility function to sanitize OAuth error codes, preventing potential security vulnerabilities and improving error message clarity. It also updates the error handling logic in the OAuth2 callback views to leverage this new sanitization, ensuring that sensitive or malformed error details are not exposed to the user.

Co-authored-by: jenn.muengtaweepongsa <jenn.muengtaweepongsa@sentry.io>
@github-actions github-actions bot added the Scope: Backend Automatically applied to PRs that change backend components label Nov 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Scope: Backend Automatically applied to PRs that change backend components

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants