pub struct SanitizedRegistryError(/* private fields */);Expand description
Wraps a reqwest::Error with its embedded request URL stripped, for storage in
DepsError::RegistryError’s source field.
reqwest::Error’s own Display appends " for url (...)" when the underlying error
carries a URL — reqwest::Error::without_url() strips this, but relying on every
RegistryError-construction site to remember to call it is exactly the discipline gap
this type closes (issue #789, see RedactedUrl’s own docs for the same problem on the
URL-string side). The only constructor (From<reqwest::Error>) applies .without_url()
unconditionally, so a raw URL can never reach DepsError’s Display/Debug through
{source} forwarding, even when a future call site forgets.
self.0’s own source chain is never exposed, through either Debug or
std::error::Error::source — this is deliberate, not an oversight. .without_url()
only clears the outer error’s own url field; reqwest’s source field is
independent of it, and that source is not always a URL-free hyper/io error: reqwest
0.13.4’s redirect policy (src/redirect.rs, the https_only check in
TowerPolicy::redirect) rejects an http:// redirect target by building
crate::error::redirect(crate::error::url_bad_scheme(next_url.clone()), next_url) — the
inner url_bad_scheme(...) error is itself a full reqwest::Error with next_url
populated via .with_url(...), nested as the outer error’s source. That inner url
is a field .without_url() on the outer error never touches, and reqwest::Error’s own
derived-style Debug impl recursively prints source’s Debug (including that inner
url) — so both a manual .source() walk and {:?} on the raw reqwest::Error can leak
it. Since reqwest exposes no source_mut()-style API to reach in and strip that nested
URL, this type treats itself as a leaf node instead: its std::error::Error::source
impl always returns None, and Debug is hand-written to forward to the (already-safe)
Display text rather than to self.0’s own Debug.
Precision note on what is actually verified today: this project’s own client
configuration never calls reqwest::ClientBuilder::https_only (grep -rn '\.https_only(' crates/ finds no hits), so the nested-URL shape above cannot currently occur through this
crate’s own request paths — the regression test below instead exercises a genuinely
populated source chain via a real connection-refused (io-level) failure, which is what
this project’s client config can actually produce, and confirms it is discarded. The
https_only/redirect mechanism itself is read directly from reqwest 0.13.4’s pinned
source (redirect.rs), not reproduced live here (doing so would need a TLS test harness
this project does not otherwise have). source() returning None unconditionally — not
only when a URL-bearing nested error is possible — is what makes this correct regardless:
if a future change enables https_only on a shared client, this type’s contract does not
need re-auditing.
§Examples
use deps_core::error::SanitizedRegistryError;
// A builder-only `reqwest::Error` never carries a URL in the first place, so this
// demonstrates the wrapper's `Display`/`Debug` forwarding without needing a real request.
let raw = reqwest::Client::new().get("not a url").build().unwrap_err();
let sanitized: SanitizedRegistryError = raw.into();
assert!(!sanitized.to_string().is_empty());Trait Implementations§
Source§impl Debug for SanitizedRegistryError
impl Debug for SanitizedRegistryError
Source§fn fmt(&self, f: &mut Formatter<'_>) -> Result
fn fmt(&self, f: &mut Formatter<'_>) -> Result
Hand-written, not derived: forwards to Display (safe — reqwest::Error’s own
Display never recurses into its source’s text) instead of self.0’s own Debug,
which does recurse into source and would reopen the nested-URL leak this type’s own
docs describe.
Source§impl Display for SanitizedRegistryError
impl Display for SanitizedRegistryError
Source§impl Error for SanitizedRegistryError
impl Error for SanitizedRegistryError
Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
Always None — see this type’s own docs for why the wrapped error’s source chain is
never safe to expose, even via this trait’s usual chain-walking contract.
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()