Skip to content

fix: stop returning the request body in validation errors - #363

Merged
Priyanshu-u07 merged 1 commit into
mainfrom
validation-errors-drop-input
Sep 25, 2026
Merged

Priyanshu-u07 merged 1 commit into
mainfrom
validation-errors-drop-input

Conversation

@Priyanshu-u07

Copy link
Copy Markdown
Collaborator

validation_error_handler returned exc.errors() as-is, and Pydantic puts the whole request body under input, so a failed login sent the password back in the 422.

Drops input from every validation error. loc, msg and type survive, so clients can still show which field failed.

Two other paths did the same thing: the pool endpoints in deployment_server.py raise HTTPException directly and never reach the handler, so they're fixed too.

Also registers the shared handlers on the unified_web parent app. Its two root routes take no body, so nothing leaks today, but routes added with include_router run on the parent rather than a mount and inherit no handlers from the sub-apps, so the next body-taking route would echo by default. Both routes are browser redirect targets and raise only HTTPException, which FastAPI handles itself, so no existing response changes.

Closes #330

Signed-off-by: Priyanshu-u07 <connect.priyanshu8271@gmail.com>
@Priyanshu-u07
Priyanshu-u07 merged commit 1a8c159 into main Sep 25, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validation errors echo the request body, including passwords

1 participant