fix: surface the response body on 4xx so 403s are diagnosable
Media downloads logged "HTTP Error 403:" with no reason. That string is
curl_cffi's raise_for_status() format, "HTTP Error {code}: {reason}", and
HTTP/2 carries no reason phrase — so the message said nothing, and
_make_request threw the response body away. The provider's JSON `detail`
is the only explanation available for a refused asset.
- base._make_request: end non-retryable statuses with a ProviderError
carrying the body's detail/error/message (redacted, truncated to 300
chars) instead of a bare raise_for_status().
- media: bucket 403 as `forbidden` in the run summary, separately from
`download-error` — "the asset is gone" and "we were refused" are
different problems.
- utils.redact_secrets: match secret key names per word. Exact matching
let access_token, api_key, and session-token through into logged
bodies; "keywords"/"monkey"/"tokenizer" stay intact.
- tests/test_config.py: test_defaults depended on the absence of a local
.env — load_config() calls load_dotenv(override=False), which restored
the variable the test had just deleted. Stub dotenv discovery.
305 tests pass.
This commit is contained in:
@@ -170,6 +170,22 @@ class TestResolveMedia:
|
||||
# Still renders as a placeholder, not a broken image link
|
||||
assert render_blocks_to_markdown([block]).startswith("> 🖼️")
|
||||
|
||||
def test_forbidden_counted_separately_from_generic_error(self, tmp_path):
|
||||
"""403 is a distinct bucket: the asset exists, we were refused."""
|
||||
ref = "sediment://file_denied"
|
||||
provider = _FakeProvider(
|
||||
fail_refs={ref: RuntimeError("HTTP 403 — detail: unauthorized")}
|
||||
)
|
||||
block = make_image_placeholder(ref=ref, source="model_generated")
|
||||
report = LossReport()
|
||||
|
||||
resolve_media(
|
||||
_conv_with([block]), provider, tmp_path, "provider/project/year",
|
||||
"images", report,
|
||||
)
|
||||
assert report.media_failed["forbidden"] == 1
|
||||
assert "download-error" not in report.media_failed
|
||||
|
||||
def test_provider_without_download_asset(self, tmp_path):
|
||||
"""claude-code has no remote assets — resolve_media must no-op."""
|
||||
class NoDownload:
|
||||
|
||||
Reference in New Issue
Block a user