feat(routes): warn when add_routes() mounts the monitoring routes unguarded - #302
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
add_routes()now emits aUserWarningwhendependenciesis left asNone(the default). The monitoring routes/cached-hitsand/cached-recordshave no access control of their own, and until now the only notice was a docstring sentence.dependencies, says 0.4.0 will require it and turninclude_content_previewoff by default (add_routes: monitoring routes are unauthenticated and expose content previews by default #298), and points todependencies=[]as the deliberate opt-out.dependencies=[](any non-Nonesequence) does not warn.include_content_previewdefault are unchanged.docs/HTTP_CACHING.mdand the zh-TW mirror: the monitoring-routes warning box mentions theUserWarning, the 0.4.0 change and thedependencies=[]opt-out. The code examples there and inexamples/http_cache.pyalready passed a guard.Tests
tests/test_routes.pycalls toadd_routes()withoutdependenciesnow passdependencies=[](pytest runs withfilterwarnings = ["error"]).test_add_routes_with_none_dependencies_no_errorbecametest_add_routes_with_none_dependencies_warns_and_mounts, which expects the warning and still checks that the routes respond.TestUnguardedWarning: the default warns once with a message that namesdependencies,dependencies=[], 0.4.0,include_content_previewand add_routes: monitoring routes are unauthenticated and expose content previews by default #298, and the warning's filename is the calling test file.dependencies=[]and a realDependsguard both do not warn.Full suite: 860 passed, 191 skipped (live Redis/Memcached), coverage 93.62%. ruff check, ruff format --check, mypy --strict and pre-commit all pass.
CHANGELOG
The entry is in
changelog.d/301.deprecated.mdand is merged intoCHANGELOG.mdat release time.Closes #301
Refs #298