Skip to content

AuthDeclaredButUnwired guard (follow-up on resolve_auth #5661): fail-closed pre-send typed error when an auth is declared but unwired, before the request leaves dispatch_rest -- never a remote 401 - #5683

Merged
briansrls merged 8 commits into
mainfrom
session/fierce-crane-594
Jun 24, 2026

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session fierce-crane-594.
Pushing to session/fierce-crane-594 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 2 commits June 23, 2026 22:00
…ting witness

Split resolve_auth return from (String, Option<String>) into pub AuthResolution
{ NoAuthDeclared | Resolved{header,token} | DeclaredButUnwired{reason} } so
dispatch_rest cannot reach the send path with auth declared but no token —
the DeclaredButUnwired arm raises InterpError::AuthDeclaredButUnwired pre-send
before ureq constructs a request (§5 construction-first, never post-hoc check).

Adds 5-test discriminating witness: declared+withheld → typed error pre-send,
declared+empty auth_input → typed error, no auth declared → guard must NOT fire.
AuthResolution and resolve_auth are pub for snappy-otter-298's perturbation witness.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 23, 2026 22:13
Brian Searls and others added 6 commits June 23, 2026 22:16
Remove early DeclaredButUnwired return inside the auth_input block so that
when api_key is unbound/empty the function falls through to the auth_source
env-var attempt. The guard fires only when BOTH paths are empty, preserving
the precedence-with-fallback the real anthropic_rest.dag service relies on.

Add 2 dual-declare witnesses:
- dual_declare_env_var_fallback_resolves_when_input_empty: env var set →
  Resolved via fallback (regression guard — must NOT raise AuthDeclaredButUnwired)
- dual_declare_both_empty_fails_closed: both paths empty → AuthDeclaredButUnwired

All 7 tests green by execution; fmt + clippy -D warnings clean.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Clarifies that the wet-dispatch tests carry the execution discrimination;
this test is an accessibility check only.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@briansrls
briansrls merged commit b8de6d3 into main Jun 24, 2026
2 checks passed
@briansrls
briansrls deleted the session/fierce-crane-594 branch June 24, 2026 02:44
@gunbai-bot gunbai-bot Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant