Skip to content

fix(event_handler): clear context when route resolution raises - #8539

Open
vyrnsynx wants to merge 1 commit into
aws-powertools:developfrom
vyrnsynx:fix/event-handler-clear-context-on-error
Open

vyrnsynx wants to merge 1 commit into
aws-powertools:developfrom
vyrnsynx:fix/event-handler-clear-context-on-error

Conversation

@vyrnsynx

@vyrnsynx vyrnsynx commented Oct 7, 2026

Copy link
Copy Markdown

Issue number: closes #8538

Summary

Changes

resolve() and resolve_async() only cleared the routing context after the response was built, so when a route raised an unhandled exception the context (including the cached _request) carried over to the next invocation.

  • Clear the context in a finally block in both resolve() and resolve_async().
  • Drop the except Exception: self.clear_context() in the ALB response size validation, since resolve()/resolve_async() now handle it. The existing ALB tests still check the context is empty on each error path.
  • Added tests for the sync and async paths, and one for Request injection across two failing invocations.
  • test_failed_handler_cannot_leak_claims_into_later_invocations expected application_value to still be in the context after the handler raised. It now expects the context to be empty. I left the JWT middleware's own finally that pops claims as it is.

User experience

Before: after an unhandled exception, the next invocation on the same warm container could get the previous Request from app.request, Request injection or Depends(), plus any data added with append_context. The repro in #8538 fails on its second case.

After: the context is cleared after every invocation, whether the route returns or raises, as the docs say. The #8538 repro passes.

Tested locally with the full pytest -m "not perf" --ignore tests/e2e, the test_with_only_required_packages and test_with_auth_required_packages nox sessions, ruff format --check, ruff check, mypy and ty.


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Disclaimer: We value your time and bandwidth. As such, any pull requests created on non-triaged issues might not be successful.

resolve() and resolve_async() only cleared the routing context after a
response was built, so an exception escaping a route handler left the
previous invocation's context in place, including the cached Request.
A warm Lambda container could then hand that stale Request to the next
invocation.

Clear the context in a finally block instead. The ALB response size
validation no longer needs its own clean-up on error, and the JWT
middleware test now expects the whole context to be gone after a
failing handler rather than only the claims.
@vyrnsynx
vyrnsynx requested a review from a team as a code owner October 7, 2026 07:30
@vyrnsynx
vyrnsynx requested a review from hjgraca October 7, 2026 07:30
@powertools-for-aws-oss-automation powertools-for-aws-oss-automation Bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Oct 7, 2026
@boring-cyborg boring-cyborg Bot added the tests label Oct 7, 2026
@boring-cyborg

boring-cyborg Bot commented Oct 7, 2026

Copy link
Copy Markdown

Thanks a lot for your first contribution! Please check out our contributing guidelines and don't hesitate to ask whatever you need.
In the meantime, check out the #python channel on our Powertools for AWS Lambda Discord: Invite link

@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

event_handlers size/M Denotes a PR that changes 30-99 lines, ignoring generated files. tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: Event Handler context not cleared on error; cached Request can be stale

1 participant