Skip to content

Log why a Dataverse server rejected a token at connect - #280

Merged
jodeleeuw merged 1 commit into
testfrom
fix/dataverse-token-validation-logging
Sep 28, 2026
Merged

jodeleeuw merged 1 commit into
testfrom
fix/dataverse-token-validation-logging

Conversation

@jodeleeuw

Copy link
Copy Markdown
Member

Refs #278.

Why

When a researcher connects Dataverse, validateStaticToken treats any non-200 from /api/users/:me as an invalid token, and the connect endpoint reports "Invalid API token" without logging anything. A real 401, a firewall 403, and an outage 5xx all look the same afterward.

For #278 (Harvard Dataverse), prod logs show about 20 failed connects on 2026-09-26 around when the issue was filed, but nothing about what Harvard returned. Harvard also returned 504s to our server the next morning.

What

  • On a non-200, log the server, the HTTP status, and the first 300 characters of the response body as a warning. Any copy of the token in the body is replaced with [redacted].
  • Token validation and the message users see are unchanged.
  • Adds a test that checks the status, server and body are logged and the token is not.

Follow-up

Once the logs show what Harvard returns, show a separate "couldn't reach the server" message for 5xx responses and network errors, instead of "did not accept the token".

🤖 Generated with Claude Code

validateStaticToken collapsed every non-200 into "invalid", and the
connect endpoint turns that into "Invalid API token" without logging
anything. A real 401, a firewall 403, and an outage 5xx looked the same
after the fact, which left #278 undiagnosable. Log the server, status,
and a truncated, token-scrubbed body so the next failure says why.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jodeleeuw
jodeleeuw merged commit 64c97d1 into test Sep 28, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant