Skip to content

fix/SOF-8067: endpoints send the current token on every request; every call has a timeout - #49

Merged
VsevolodX merged 5 commits into
mainfrom
fix/SOF-8067-auth-headers-per-request
Oct 8, 2026
Merged

VsevolodX merged 5 commits into
mainfrom
fix/SOF-8067-auth-headers-per-request

Conversation

@VsevolodX

@VsevolodX VsevolodX commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Endpoints send the current token on every request, so a re-login reaches the existing client, and every request gets the client's timeout instead of none.

🤖 Generated with Claude Code

VsevolodX and others added 4 commits October 7, 2026 15:17
Since #47 an endpoint builds its headers once, at construction, from the
AuthContext. A token replaced on the shared context after a re-login
(client.auth.access_token = new) never reached client.jobs, client.materials
or client.properties: their next request still carried the expired bearer
token and failed with 401.

BaseEndpoint.get_request_headers() returns the endpoint headers merged with
the auth context's current headers, and request() uses it whenever the
caller passes the endpoint's own headers. BaseEndpoint.auth exposes the
auth context read-only. Together they give callers that send requests
themselves, such as the browser fetch in api-examples, a public way to the
current headers instead of private members.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…st is given

8f48e68 refreshed the token only when the caller passed the endpoint's own
headers object, and to check that it read self.headers. A plain BaseEndpoint
has no headers attribute, so api-examples' upload_files, which builds a
BaseEndpoint and passes headers from get_headers(), raised AttributeError.

request() now passes any headers it is given through get_request_headers(),
which merges in the auth context's current credentials. The endpoint's own
headers are the default only when no headers are given. The first
login request passes none and has no auth context, so it is left as is.

Docstrings on auth and get_request_headers say why the token is read per
request: a token replaced on the shared AuthContext after a re-login must
reach every endpoint. The test now covers jobs.list() and the raw endpoint
the api-examples files path uses, for both auth types.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The connection stored the client's timeout_seconds on session.timeout, an
attribute requests ignores, and called session.request without timeout=.
Endpoint calls therefore had no timeout at all: a platform that stops
answering froze any notebook cell forever, natively and in JupyterLite.

The connection now passes the stored value as timeout= on each request, so
APIClient's timeout_seconds (60 by default) bounds every endpoint call.
The /users/me request already sent its own 30 s timeout.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… merged over the given ones

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
request() merges the endpoint's auth context headers into the given ones;
the endpoint keeps the auth context as a plain public attribute. One test
covers a token replaced after the client is built and the client timeout.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@VsevolodX
VsevolodX merged commit 641f3d4 into main Oct 8, 2026
3 checks passed
@VsevolodX
VsevolodX deleted the fix/SOF-8067-auth-headers-per-request branch October 8, 2026 02:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants