Repository navigation
test(contracts): add unit tests verifying behavior when stream end_ti… - #1583
Merged
K1NGD4VID merged 7 commits intoOct 8, 2026
Merged
Conversation
…me equals start_time (LabsCrypt#1518) - Add tests asserting revert when start_time == end_time and start_time > end_time - Assert reversion with StreamError::InvalidTimeRange / StreamError::InvalidDuration - Ensure duration is validated as end_time > start_time before rate arithmetic - Verify no token transfer, balance deduction, or event publication on zero duration - Restore missing StreamError variants and align Stream storage field counts
… hoist next for eslint-config-next
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
When unexpected database errors occurred (such as unique constraint violations, foreign key mismatches, query syntax issues, or validation errors), Prisma's raw error strings and metadata interpolation (
meta.target,meta.cause,meta.field_name) exposed database table names, constraint definitions, column layouts, and raw SQL queries directly in HTTP response bodies.This PR sanitizes Prisma database errors in API responses to prevent internal database schema disclosure, mapping them to safe, generic error codes (
DUPLICATE_ENTRY,RESOURCE_NOT_FOUND,FOREIGN_KEY_VIOLATION,VALUE_OUT_OF_RANGE, etc.). Full error details, metadata, and stack traces remain preserved internally in Winston logs for debugging.Type of Change
Related Issues
Closes #1518
Changes Made
backend/src/lib/api-error.ts:fromPrismaError(err)to interceptPrismaClientKnownRequestError,PrismaClientValidationError,PrismaClientUnknownRequestError,PrismaClientRustPanicError, andPrismaClientInitializationError.P2002(Unique constraint): Maps to HTTP 409DUPLICATE_ENTRYwith message"A record with this unique value already exists."(removesmeta.targetinterpolation that leaked column/table names).P2025,P2001,P2015,P2018(Record not found): Maps to HTTP 404RESOURCE_NOT_FOUNDwith message"The requested record was not found."(masks model names).P2003(Foreign key constraint): Maps to HTTP 409FOREIGN_KEY_VIOLATIONwith message"Related resource constraint violation."(masks field and table names).P2000(Value too long): Maps to HTTP 400VALUE_OUT_OF_RANGE.P2004(Database constraint failed): Maps to HTTP 400CONSTRAINT_FAILED.P2005/P2006(Invalid input type): Maps to HTTP 400INVALID_INPUT.P2011/P2012/P2013(Missing required fields): Maps to HTTP 400MISSING_REQUIRED_FIELD.P2014/P2017(Relation constraint violation): Maps to HTTP 409RELATION_VIOLATION.P2016(Query interpretation error): Maps to HTTP 400INVALID_QUERY.P2021/P2022(Table / Column not found): Maps to HTTP 500INTERNAL_SERVER_ERROR.DATABASE_ERRORwith message"A database error occurred.".PrismaClientValidationError: Maps to HTTP 400VALIDATION_ERRORwith message"Invalid request data.".PrismaClientUnknownRequestError: Maps to HTTP 500INTERNAL_SERVER_ERRORwith message"A technical error occurred. Please try again later.".containsDatabaseDetailsandsanitizeDatabaseErrorMessageto redact raw SQL statements (SELECT,INSERT INTO,UPDATE,DELETE, etc.), table/column identifiers, and PostgreSQL errors from all 4xx/5xx response bodies.duplicateEntry,resourceNotFound,foreignKeyViolation,internal,badRequest) andstatusCodegetter onApiError.backend/src/middleware/error.middleware.ts:fromPrismaErrorto intercept and sanitize all Prisma errors before response dispatch.logger.error('Unhandled error:', err).ApiErrorinstances and generic errors to ensure raw SQL or table names never leak in HTTP responses.backend/prisma/schema.prisma:IndexerDeadLetterEventmodel declarations that causedprisma generateto fail with errorP1012.backend/tests/api-error.test.ts: Added unit tests covering allfromPrismaErrormappings, duck-typed detection, and string sanitization.backend/tests/error.middleware.test.ts: Enhanced middleware tests verifying masked error responses and internal Winston logger context.Testing
Test Coverage
Test Steps
P2002returns HTTP 409DUPLICATE_ENTRYand does not leakmeta.targetor column names.P2025returns HTTP 404RESOURCE_NOT_FOUNDand does not leak model names.P2003returns HTTP 409FOREIGN_KEY_VIOLATIONand does not leak relation/field names.PrismaClientValidationErrorreturns HTTP 400VALIDATION_ERRORwithout exposing schema internals.PrismaClientUnknownRequestErrorreturns HTTP 500INTERNAL_SERVER_ERRORwithout exposing raw SQL.logger.errorcaptures the full error object and stack trace.Breaking Changes
None. Safe generic error envelopes are returned conforming to standard
{ error: { code, message } }schema.Screenshots/Demo
Example Masked Response: Unique Constraint (
P2002)Before:
{ "error": { "code": "CONFLICT", "message": "Record with this email already exists." } }After:
{ "error": { "code": "DUPLICATE_ENTRY", "message": "A record with this unique value already exists." } }Example Masked Response: Unknown Query Error (
PrismaClientUnknownRequestError)Before:
{ "error": { "code": "INTERNAL_SERVER_ERROR", "message": "SELECT * FROM \"users\" WHERE id = $1 failed: syntax error at or near \"SELECT\"" } }After:
{ "error": { "code": "INTERNAL_SERVER_ERROR", "message": "A technical error occurred. Please try again later." } }Checklist
backend/docs/observability/Additional Notes
Internal logging via Winston continues to log the complete, unmodified error object (including stack trace and metadata) so debugging and observability are fully preserved.