fix(query-engine): stop stripping angle brackets from warehouse error SQL - #1212
Conversation
… SQL cleanErrorMessage removed every <...> span to scrub HTML error pages, so an echoed query lost everything between a <= and a later >=. Match only real HTML tags. Covers run_sql, raw_sql widgets and raw_query alerts.
Maple review🟢 Confidence 4/5 · likely safe to merge Narrows the HTML scrubber in
Findings🟠 Warning · F1 ·
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 35 minutes. View limit detailsLimit details: You’ve used all 4 included reviews currently available. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthrough
ChangesSQL error cleanup
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Merge Risk: 🔵 Low · up to Some warehouse failures may display residual HTML markup in their error text. This is a bounded presentation regression, so merge with owner awareness and follow-up. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change preserves SQL diagnostics without changing query execution or permissions. Some additional markup can remain in error messages. The inspected consumers return text or typed errors, but downstream display handling is not fully established. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ror pages Review follow-up: the narrowed tag grammar left <!DOCTYPE html> and <p class=x> in cleaned errors. Match the doctype on its own and allow unquoted values after '=', which still leaves x<b AND y>3 intact.
Maple review🟢 Confidence 4/5 · likely safe to merge Narrows the HTML scrubber in
Findings🔵 Note · F2 ·
|
Problem
cleanErrorMessagescrubbed HTML error pages with.replace(/<[^>]+>/g, " "). ClickHouse errors echo the failing query back, so a query with a<=and a later>=(for example$__timeFilterin severalUNION ALLbranches) came back with everything in between removed. The SQL that ran was correct, but the error text an agent or user saw showed a different, mangled query, which sent debugging the wrong way.The cleaner runs on every warehouse failure (
toWarehouseQueryError,mapWarehouseError), so this affectedrun_sql,inspect_chart_data, raw_sql dashboard widgets, raw_query alert rules and the HTTP raw-SQL route.Fix
a < 5 AND b > 3and<= ... >=survive;<b>,<p class="x">and doctype tags are still removed.<, so a comparison against a column namedtitledoesn't truncate the message.Tests
errors.test.ts: regression test with three UNION branches of>=/<=plusa < 5 AND b > 3. It fails with the old regex. A second test confirms inline HTML is still stripped.raw-sql.test.ts:$__timeFilterexpanded across three UNION branches keeps all six comparisons.bunx vitest run src/executioninpackages/query-engine: 117 passed.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit
<=and>=remain intact, while inline HTML tags are removed and their text is preserved.UNION ALLbranches, preserving the final branch in the prepared query.