address greptile review feedback (greploop iteration 40)

- fix duplicate error logging: demote first format-error log to DEBUG
  so the detailed ERROR in strict-mode branch is not duplicated
- add HTTP status code assertions to all PKCE ProxyException tests
  for better regression protection against accidental code changes
This commit is contained in:
Ishaan Jaffer 2026-03-06 14:30:54 -08:00
parent 9b87bdf176
commit 0c60c0f892
2 changed files with 9 additions and 2 deletions

View file

@ -2592,7 +2592,10 @@ class SSOAuthenticationHandler:
"Future storage will use dict format."
)
else:
verbose_proxy_logger.error(
# Defer the detailed ERROR log to the strict-mode branch below
# (which includes state and a diagnostic message). Log at DEBUG
# here to avoid duplicate ERROR entries in the same request.
verbose_proxy_logger.debug(
"Unexpected PKCE verifier cache format (type=%s); skipping.",
type(cached_data).__name__,
)

View file

@ -3546,6 +3546,7 @@ class TestPKCEFunctionality:
)
assert "invalid_grant" in exc_info.value.message
assert str(exc_info.value.code) == "401"
@pytest.mark.asyncio
@ -3631,6 +3632,7 @@ class TestPKCEFunctionality:
)
assert "unavailable" in exc_info.value.message.lower()
assert str(exc_info.value.code) == "401"
@pytest.mark.asyncio
@ -3775,6 +3777,7 @@ class TestPKCEFunctionality:
)
assert "cache" in exc_info.value.message.lower() or "verifier" in exc_info.value.message.lower() or "format" in exc_info.value.message.lower()
assert str(exc_info.value.code) == "401"
@pytest.mark.asyncio
async def test_pkce_cache_miss_non_strict_logs_warning_and_continues(self):
@ -3844,7 +3847,8 @@ class TestPKCEFunctionality:
additional_headers={},
)
assert "401" in exc_info.value.message or "token" in exc_info.value.message.lower()
assert "token" in exc_info.value.message.lower()
assert str(exc_info.value.code) == "401"
@pytest.mark.asyncio
async def test_pkce_cache_miss_unexpected_format_non_strict_logs_warning(self):