fix(guardrails): return the Entra exchange fallback verdict from one path so CodeQL sees no implicit None

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
yucheng 2026-09-30 09:16:03 +00:00
parent be5a5ccf81
commit 06e5d9f7c5
2 changed files with 20 additions and 16 deletions

View file

@ -500,22 +500,15 @@ class Agent365Guardrail(CustomGuardrail):
if isinstance(exchange_result, Ok):
return SignedIn()
error: Final = exchange_result.error
match error.tag:
case "unauthorized":
return Rejected(detail=error.unauthorized.detail, claims=error.unauthorized.claims)
case "misconfigured":
return Unavailable(
detail=(
f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); "
"check the guardrail's client_id and client_secret"
),
fail_open=self.unreachable_fallback == "fail_open",
)
case _:
return Unavailable(
detail=f"the Entra token exchange failed ({error.summary})",
fail_open=self.unreachable_fallback == "fail_open",
)
if error.tag == "unauthorized":
return Rejected(detail=error.unauthorized.detail, claims=error.unauthorized.claims)
detail: Final = (
f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); "
"check the guardrail's client_id and client_secret"
if error.tag == "misconfigured"
else f"the Entra token exchange failed ({error.summary})"
)
return Unavailable(detail=detail, fail_open=self.unreachable_fallback == "fail_open")
async def _post_allowing_error_status(
self,

View file

@ -1284,6 +1284,17 @@ class TestPreflightCallerSignIn:
"the field was removed from the config; do not tell admins to check it"
)
@pytest.mark.asyncio
async def test_token_endpoint_failure_is_unavailable_under_the_fallback_policy(self):
exchanger: Final = StubTokenExchanger([Error(CredError.of_upstream_unavailable("token endpoint 503"))])
guardrail: Final = _make_guardrail(FakeHandler([]), exchanger=exchanger, unreachable_fallback="fail_open")
verdict: Final = await guardrail.preflight_caller_sign_in(_server(), _user(), FAKE_ASSERTION)
assert verdict == Unavailable(
detail="the Entra token exchange failed (upstream unavailable: token endpoint 503)", fail_open=True
)
@pytest.mark.asyncio
async def test_endpoint_unreachable_fail_open_is_unavailable(self):
exchanger: Final = StubTokenExchanger(