Repository navigation
fix/SOF-8067: endpoints send the current token on every request; every call has a timeout - #49
Merged
Merged
Conversation
Since #47 an endpoint builds its headers once, at construction, from the AuthContext. A token replaced on the shared context after a re-login (client.auth.access_token = new) never reached client.jobs, client.materials or client.properties: their next request still carried the expired bearer token and failed with 401. BaseEndpoint.get_request_headers() returns the endpoint headers merged with the auth context's current headers, and request() uses it whenever the caller passes the endpoint's own headers. BaseEndpoint.auth exposes the auth context read-only. Together they give callers that send requests themselves, such as the browser fetch in api-examples, a public way to the current headers instead of private members. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…st is given 8f48e68 refreshed the token only when the caller passed the endpoint's own headers object, and to check that it read self.headers. A plain BaseEndpoint has no headers attribute, so api-examples' upload_files, which builds a BaseEndpoint and passes headers from get_headers(), raised AttributeError. request() now passes any headers it is given through get_request_headers(), which merges in the auth context's current credentials. The endpoint's own headers are the default only when no headers are given. The first login request passes none and has no auth context, so it is left as is. Docstrings on auth and get_request_headers say why the token is read per request: a token replaced on the shared AuthContext after a re-login must reach every endpoint. The test now covers jobs.list() and the raw endpoint the api-examples files path uses, for both auth types. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The connection stored the client's timeout_seconds on session.timeout, an attribute requests ignores, and called session.request without timeout=. Endpoint calls therefore had no timeout at all: a platform that stops answering froze any notebook cell forever, natively and in JupyterLite. The connection now passes the stored value as timeout= on each request, so APIClient's timeout_seconds (60 by default) bounds every endpoint call. The /users/me request already sent its own 30 s timeout. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… merged over the given ones Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
request() merges the endpoint's auth context headers into the given ones; the endpoint keeps the auth context as a plain public attribute. One test covers a token replaced after the client is built and the client timeout. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
timurbazhirov
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Endpoints send the current token on every request, so a re-login reaches the existing client, and every request gets the client's timeout instead of none.
🤖 Generated with Claude Code