Skip to content

feat(routes): warn when add_routes() mounts the monitoring routes unguarded - #302

Merged
allen0099 merged 2 commits into
masterfrom
feat/add-routes-warn-unguarded
Sep 27, 2026
Merged

allen0099 merged 2 commits into
masterfrom
feat/add-routes-warn-unguarded

Conversation

@allen0099

@allen0099 allen0099 commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

add_routes() now emits a UserWarning when dependencies is left as None (the default). The monitoring routes /cached-hits and /cached-records have no access control of their own, and until now the only notice was a docstring sentence.

  • The warning (stacklevel points at the caller) says the routes are mounted without access control and expose every cached key (including query strings) and response previews. It names dependencies, says 0.4.0 will require it and turn include_content_preview off by default (add_routes: monitoring routes are unauthenticated and expose content previews by default #298), and points to dependencies=[] as the deliberate opt-out.
  • An explicit dependencies=[] (any non-None sequence) does not warn.
  • No other behaviour change: routes, responses and the include_content_preview default are unchanged.
  • Docstring updated; the example now passes a guard.
  • docs/HTTP_CACHING.md and the zh-TW mirror: the monitoring-routes warning box mentions the UserWarning, the 0.4.0 change and the dependencies=[] opt-out. The code examples there and in examples/http_cache.py already passed a guard.

Tests

  • Existing tests/test_routes.py calls to add_routes() without dependencies now pass dependencies=[] (pytest runs with filterwarnings = ["error"]).
  • test_add_routes_with_none_dependencies_no_error became test_add_routes_with_none_dependencies_warns_and_mounts, which expects the warning and still checks that the routes respond.
  • New TestUnguardedWarning: the default warns once with a message that names dependencies, dependencies=[], 0.4.0, include_content_preview and add_routes: monitoring routes are unauthenticated and expose content previews by default #298, and the warning's filename is the calling test file. dependencies=[] and a real Depends guard both do not warn.

Full suite: 860 passed, 191 skipped (live Redis/Memcached), coverage 93.62%. ruff check, ruff format --check, mypy --strict and pre-commit all pass.

CHANGELOG

The entry is in changelog.d/301.deprecated.md and is merged into CHANGELOG.md at release time.

Closes #301
Refs #298

…uarded

add_routes() now emits a UserWarning when dependencies is left as None,
naming the parameter and the 0.4.0 change (#298). An explicit
dependencies=[] opts out without the warning. No other behaviour change.

Closes #301
Refs #298
@allen0099 allen0099 added this to the 0.3.9 milestone Sep 27, 2026
@allen0099 allen0099 added enhancement New feature or request security Security vulnerability or hardening labels Sep 27, 2026
@allen0099
allen0099 merged commit 60fd8a8 into master Sep 27, 2026
12 checks passed
@allen0099
allen0099 deleted the feat/add-routes-warn-unguarded branch September 27, 2026 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request security Security vulnerability or hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

add_routes: warn when the monitoring routes are mounted without dependencies

1 participant