mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix: error-only Sentry telemetry, storm-proof capture, and crash fixes (#476)
Removes Sentry tracing entirely (BullMQ idle polling burned 4.8M transactions in 2 days at the baked 0.1 rate), decouples PostHog sampling, and replaces the type-only error scrub with a vetted-field sanitizer plus SafeError/ToolInputError contracts. One classified capture path with per-signature throttles and a per-process ceiling makes storms impossible (NODE-1E was 4,541 events from one 30s loop). Browser errors move to a dedicated web Sentry project with their own source maps. Adds the SNAPOTTER_TELEMETRY runtime kill switch and silences test fleets. Crash fixes: remote 204/304 SSRF process kill (NODE-20), conversion-preset boot crash loop (NODE-21), Redis version preflight + unhandled subscribe rejection (NODE-1T), Sign PDF on plain-http origins (NODE-1K/1M), wavesurfer/pdf.js teardown rejections (NODE-1P/1N), bundle-import ZlibError to 400 (NODE-1Z), chart-maker input errors declassified (NODE-1H/1J), asset requests skip the session DB lookup (NODE-1D).
This commit is contained in:
@@ -4,5 +4,6 @@ export const ANALYTICS_BAKED = {
|
||||
posthogApiKey: "",
|
||||
posthogHost: "",
|
||||
sentryDsn: "",
|
||||
sampleRate: 0,
|
||||
sentryDsnWeb: "",
|
||||
posthogSampleRate: 0,
|
||||
} as const;
|
||||
|
||||
@@ -0,0 +1,142 @@
|
||||
/**
|
||||
* Pure error-inspection helpers shared by the api and web Sentry scrubbers.
|
||||
* Everything here rebuilds safe strings from VETTED FIELDS ONLY; raw error
|
||||
* messages are never passed through (except SafeError, whose messages we
|
||||
* author). Returning null means "no safe rebuild known, use type-only".
|
||||
*/
|
||||
import { isSafeMessageError } from "../tool-errors.js";
|
||||
|
||||
interface ErrLike {
|
||||
name?: unknown;
|
||||
code?: unknown;
|
||||
syscall?: unknown;
|
||||
severity?: unknown;
|
||||
routine?: unknown;
|
||||
message?: unknown;
|
||||
cause?: unknown;
|
||||
issues?: unknown;
|
||||
status?: unknown;
|
||||
}
|
||||
|
||||
const NODE_CODE = /^E[A-Z0-9_]+$/;
|
||||
const SQLSTATE = /^[0-9A-Z]{5}$/;
|
||||
const PG_CONNECTIVITY = /^(08|57P0[123])/;
|
||||
const PG_ROUTINE = /^[A-Za-z_][A-Za-z0-9_]{0,63}$/;
|
||||
const REPLY_TOKEN = /^[A-Z][A-Z0-9_]{1,19}$/;
|
||||
const SAFE_NAME = /^[A-Za-z][A-Za-z0-9_$]{0,63}$/;
|
||||
const SAFE_PATH_SEGMENT = /^[A-Za-z0-9_-]{1,64}$/;
|
||||
const NET_CODES = new Set([
|
||||
"ECONNREFUSED",
|
||||
"ECONNRESET",
|
||||
"ETIMEDOUT",
|
||||
"EHOSTUNREACH",
|
||||
"EPIPE",
|
||||
"EAI_AGAIN",
|
||||
"ENOTFOUND",
|
||||
]);
|
||||
|
||||
function chain(err: unknown, max = 6): ErrLike[] {
|
||||
const out: ErrLike[] = [];
|
||||
let cur = err;
|
||||
while (cur && typeof cur === "object" && out.length < max) {
|
||||
out.push(cur as ErrLike);
|
||||
cur = (cur as ErrLike).cause;
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
function looksLikePg(links: ErrLike[]): boolean {
|
||||
return links.some(
|
||||
(l) =>
|
||||
(typeof l.code === "string" && SQLSTATE.test(l.code) && !NODE_CODE.test(l.code)) ||
|
||||
l.severity !== undefined ||
|
||||
l.name === "PostgresError" ||
|
||||
l.name === "DrizzleQueryError" ||
|
||||
(typeof l.message === "string" && l.message.startsWith("Failed query")),
|
||||
);
|
||||
}
|
||||
|
||||
/** Safe replacement for exception.value, or null for type-only fallback. */
|
||||
export function rebuildErrorValue(err: unknown): string | null {
|
||||
try {
|
||||
if (isSafeMessageError(err)) return err.message;
|
||||
const links = chain(err);
|
||||
if (links.length === 0) return null;
|
||||
|
||||
for (const l of links) {
|
||||
if (typeof l.code === "string" && SQLSTATE.test(l.code) && !NODE_CODE.test(l.code)) {
|
||||
return typeof l.routine === "string" && PG_ROUTINE.test(l.routine)
|
||||
? `pg ${l.code} ${l.routine}`
|
||||
: `pg ${l.code}`;
|
||||
}
|
||||
}
|
||||
for (const l of links) {
|
||||
if (typeof l.code === "string" && NODE_CODE.test(l.code)) {
|
||||
// syscall is libuv vocabulary or "spawn <server-binary>", never user args.
|
||||
return typeof l.syscall === "string" ? `${l.code} ${l.syscall}` : l.code;
|
||||
}
|
||||
}
|
||||
const top = links[0];
|
||||
if (top.name === "ReplyError" && typeof top.message === "string") {
|
||||
const token = top.message.split(" ")[0];
|
||||
return REPLY_TOKEN.test(token) ? `reply ${token}` : "reply";
|
||||
}
|
||||
if (top.name === "ZodError" && Array.isArray(top.issues) && top.issues[0]) {
|
||||
const issue = top.issues[0] as { code?: string; path?: Array<string | number> };
|
||||
const path = (issue.path ?? [])
|
||||
.map((seg) => {
|
||||
if (typeof seg === "number") return String(seg);
|
||||
return typeof seg === "string" && SAFE_PATH_SEGMENT.test(seg) ? seg : "~";
|
||||
})
|
||||
.join(".");
|
||||
return `zod ${issue.code ?? "invalid"} at ${path}`;
|
||||
}
|
||||
if (typeof top.status === "number") {
|
||||
const name =
|
||||
typeof top.name === "string" && SAFE_NAME.test(top.name) ? top.name : "HttpError";
|
||||
return `${name} ${top.status}`;
|
||||
}
|
||||
return null;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
export type ConnectivityClass = "pg-unavailable" | "redis-unavailable" | "net-unavailable";
|
||||
|
||||
/** Infra-connectivity classification used for fingerprinting + throttling. */
|
||||
export function connectivityClass(err: unknown): ConnectivityClass | null {
|
||||
try {
|
||||
const links = chain(err);
|
||||
if (links.length === 0) return null;
|
||||
if (links.some((l) => l.name === "MaxRetriesPerRequestError")) return "redis-unavailable";
|
||||
const hasPgState = links.some(
|
||||
(l) => typeof l.code === "string" && SQLSTATE.test(l.code) && PG_CONNECTIVITY.test(l.code),
|
||||
);
|
||||
const hasNetCode = links.some((l) => typeof l.code === "string" && NET_CODES.has(l.code));
|
||||
if (hasPgState || (hasNetCode && looksLikePg(links))) return "pg-unavailable";
|
||||
if (hasNetCode) return "net-unavailable";
|
||||
return null;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/** Client went away mid-request; operational noise, never reported. */
|
||||
export function isClientAbort(err: unknown): boolean {
|
||||
try {
|
||||
const links = chain(err);
|
||||
if (links.length === 0) return false;
|
||||
const top = links[0];
|
||||
if (top.code === "ECONNRESET" || top.code === "ERR_STREAM_PREMATURE_CLOSE") return true;
|
||||
return links.some(
|
||||
(l) =>
|
||||
l.name === "RequestAbortedError" ||
|
||||
l.name === "AbortError" ||
|
||||
(typeof l.message === "string" &&
|
||||
/^(request aborted|premature close|aborted)$/i.test(l.message)),
|
||||
);
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -3,6 +3,7 @@ export interface AnalyticsConfig {
|
||||
posthogApiKey: string;
|
||||
posthogHost: string;
|
||||
sentryDsn: string;
|
||||
sampleRate: number;
|
||||
sentryDsnWeb: string;
|
||||
posthogSampleRate: number;
|
||||
instanceId: string;
|
||||
}
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
export * from "./analytics/baked.js";
|
||||
export * from "./analytics/error-sanitize.js";
|
||||
export * from "./analytics/events.js";
|
||||
export * from "./analytics/feedback.js";
|
||||
export * from "./analytics/types.js";
|
||||
@@ -12,4 +13,5 @@ export * from "./permissions.js";
|
||||
export * from "./pipeline-templates.js";
|
||||
export * from "./search/format-aliases.js";
|
||||
export * from "./section.js";
|
||||
export * from "./tool-errors.js";
|
||||
export * from "./types.js";
|
||||
|
||||
@@ -0,0 +1,60 @@
|
||||
/**
|
||||
* Error classes shared by api, web, and the engine packages.
|
||||
*
|
||||
* SafeError: an error whose message was AUTHORED BY US and is safe to send to
|
||||
* Sentry verbatim. RULE: the message must be a CONSTANT string; anything
|
||||
* variable (exit codes, versions, counts) goes into `code` so Sentry grouping
|
||||
* stays stable. Detection is by marker property, not instanceof, so it
|
||||
* survives error copying across module boundaries.
|
||||
*
|
||||
* ToolInputError: the user's input was the problem (bad CSV, corrupt media).
|
||||
* Never reported to Sentry. Engine packages can import these helpers
|
||||
* directly; the raw marker form Object.assign(err, { isToolInputError: true })
|
||||
* remains the wire format for contexts where an import is undesirable, and
|
||||
* because instanceof is brittle across duplicate module instances.
|
||||
*/
|
||||
export type SafeErrorKind = "operational" | "bug";
|
||||
|
||||
export class SafeError extends Error {
|
||||
readonly isSafeMessage = true;
|
||||
readonly kind: SafeErrorKind;
|
||||
readonly code?: string;
|
||||
readonly statusCode?: number;
|
||||
|
||||
constructor(
|
||||
message: string,
|
||||
opts: { kind?: SafeErrorKind; code?: string; statusCode?: number; cause?: unknown } = {},
|
||||
) {
|
||||
super(message, opts.cause !== undefined ? { cause: opts.cause } : undefined);
|
||||
this.name = "SafeError";
|
||||
this.kind = opts.kind ?? "operational";
|
||||
this.code = opts.code;
|
||||
this.statusCode = opts.statusCode;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Marker-detected errors that were copied across module boundaries may lack
|
||||
* `kind`, `code`, or `statusCode`, so consumers must tolerate their absence.
|
||||
*/
|
||||
export function isSafeMessageError(err: unknown): err is SafeError {
|
||||
return err instanceof Error && (err as { isSafeMessage?: unknown }).isSafeMessage === true;
|
||||
}
|
||||
|
||||
export class ToolInputError extends Error {
|
||||
readonly isToolInputError = true;
|
||||
readonly statusCode = 400;
|
||||
|
||||
constructor(message: string) {
|
||||
super(message);
|
||||
this.name = "ToolInputError";
|
||||
}
|
||||
}
|
||||
|
||||
export function isToolInputError(err: unknown): err is Error & { isToolInputError: true } {
|
||||
return err instanceof Error && (err as { isToolInputError?: unknown }).isToolInputError === true;
|
||||
}
|
||||
|
||||
export function markToolInputError<E extends Error>(err: E): E {
|
||||
return Object.assign(err, { isToolInputError: true });
|
||||
}
|
||||
Reference in New Issue
Block a user