Skip to content

feat(routes)!: require dependencies in add_routes and hide previews by default - #413

Merged
allen0099 merged 1 commit into
masterfrom
feat/298-add-routes-require-dependencies
Sep 30, 2026
Merged

allen0099 merged 1 commit into
masterfrom
feat/298-add-routes-require-dependencies

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Closes #298. The 0.3.9 warning was #301.

Changes

  • add_routes(app, prefix="", include_in_schema=False, *, dependencies, include_content_preview=False):
    • dependencies is required and keyword-only. Pass a guard, or dependencies=[] to mount the routes unguarded on purpose.
    • Passing None raises TypeError, with a message that names both fixes. Leaving dependencies out gets Python's own "missing required keyword-only argument" error. Type checkers flag both.
    • include_content_preview defaults to False. It also becomes keyword-only, because it follows dependencies.
    • prefix and include_in_schema can still be passed by position.
  • The 0.3.9 UserWarning is removed.
  • Docs, in docs/ and i18n/zh-TW/docs/:
    • HTTP_CACHING: the example shows include_content_preview=True, and the warning box states that dependencies is required.
    • MIGRATING_0_4:
      • explains the keyword-only arguments and the TypeError;
      • lists the two cases 0.3.9 did not warn about: positional calls, and relying on the preview default while passing dependencies;
      • the summary table states that 0.3.9 warned only when dependencies was left out.
  • Changelog fragment changelog.d/298.changed.md.

Tests

  • TestDependenciesRequired covers:
    • leaving dependencies out;
    • None, which raises and mounts no route;
    • a 0.3.x positional call;
    • [], which mounts the routes unguarded;
    • prefix and include_in_schema passed by position.
  • The preview test is parametrized over the default and False.
  • Mutation check: each of these makes exactly one test fail:
    • removing the None check;
    • flipping the preview default back to True;
    • giving dependencies a default.
  • Full suite, including the live Redis/Memcached tests: 1586 passed, 1 skipped, coverage 99.82%.
  • mypy (strict package, tests, scripts), pre-commit, both strict docs builds and tox -e lowest pass.

…y default

The monitoring routes have no authentication of their own. add_routes()
now takes dependencies as a required keyword-only argument: pass a guard,
or dependencies=[] to mount the routes unguarded on purpose. Passing None
raises TypeError. include_content_preview is keyword-only and defaults to
False. The 0.3.9 UserWarning is removed.

BREAKING CHANGE: add_routes() without dependencies, with dependencies=None,
or with dependencies or include_content_preview passed by position raises
TypeError. /cached-records reports content_preview as null unless
include_content_preview=True is passed.

Closes #298
@allen0099 allen0099 added this to the 0.4.0 milestone Sep 30, 2026
@allen0099 allen0099 added enhancement New feature or request breaking-change Changes public behaviour or API; needs a minor/major release security Security vulnerability or hardening monitoring add_routes monitoring endpoints labels Sep 30, 2026
@allen0099
allen0099 merged commit 905aeb6 into master Sep 30, 2026
16 checks passed
@allen0099
allen0099 deleted the feat/298-add-routes-require-dependencies branch September 30, 2026 04:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking-change Changes public behaviour or API; needs a minor/major release enhancement New feature or request monitoring add_routes monitoring endpoints security Security vulnerability or hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

add_routes: monitoring routes are unauthenticated and expose content previews by default

1 participant