fix(iac): keep the clone error out of logs and responses

This commit is contained in:
pedrooot committed 2026-10-09 11:15:12 +02:00
1 parent 40590aad6d
commit d964233e56
2 files changed
+13 -4

No files matched your search

+5 -2
View File
@@ -416,11 +416,14 @@ class IacProvider(Provider):
return temporary_directory, branch_name
except Exception as error:
# the authenticated URL embeds the token, and ProwlerException puts
# original_exception into its str(), which the API returns verbatim
logger.critical(
f"{error.__class__.__name__}:{error.__traceback__.tb_lineno} -- {error}"
f"{error.__class__.__name__}:{error.__traceback__.tb_lineno}"
)
raise IacRepositoryCloneError(
file=__file__, original_exception=error
file=__file__,
message=f"Unable to clone the repository to scan ({error.__class__.__name__})",
) from error
def run(self) -> List[CheckReportIAC]:
+8 -2
View File
@@ -861,13 +861,19 @@ class TestIacProvider:
lets the API report the failure as a normal task error instead of a
`SystemExit` escaping the Celery worker.
"""
mock_clone.side_effect = Exception("repository not found")
mock_clone.side_effect = Exception(
"https://x-access-token:SENTINEL_TOKEN@github.com/user/repo.git refused"
)
with pytest.raises(IacRepositoryCloneError) as exc_info:
IacProvider(scan_repository_url="https://github.com/user/repo.git")
assert "repository not found" in str(exc_info.value)
# ProwlerException formats original_exception into its str(), and the API
# returns that, so the authenticated URL must not reach it
assert "SENTINEL_TOKEN" not in str(exc_info.value)
assert "Exception" in str(exc_info.value)
assert exc_info.value.code == 21000
assert isinstance(exc_info.value.__cause__, Exception)
def test_detect_branch_name_main(self):
"""Test detecting 'main' branch from .git/HEAD"""