address greptile review feedback (greploop iteration 1)

- Fix HTTPException swallowed by broad except block in get_user_daily_activity
  and get_user_daily_activity_aggregated: re-raise HTTPException before the
  generic handler so 403 status codes propagate correctly
- Add status_code assertions in non-admin access tests

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
yuneng-jiang 2026-02-16 17:22:01 -08:00
parent 0d2aac6928
commit 310cca1578
2 changed files with 6 additions and 0 deletions

View file

@ -1995,6 +1995,8 @@ async def get_user_daily_activity(
timezone_offset_minutes=timezone,
)
except HTTPException:
raise
except Exception as e:
verbose_proxy_logger.exception(
"/spend/daily/analytics: Exception occured - {}".format(str(e))
@ -2093,6 +2095,8 @@ async def get_user_daily_activity_aggregated(
timezone_offset_minutes=timezone,
)
except HTTPException:
raise
except Exception as e:
verbose_proxy_logger.exception(
"/user/daily/activity/aggregated: Exception occured - {}".format(str(e))

View file

@ -1213,6 +1213,7 @@ async def test_get_user_daily_activity_non_admin_cannot_view_other_users(monkeyp
user_api_key_dict=non_admin_key_dict,
)
assert exc_info.value.status_code == 403
assert "Non-admin users can only view their own spend data" in str(
exc_info.value.detail
)
@ -1231,6 +1232,7 @@ async def test_get_user_daily_activity_non_admin_cannot_view_other_users(monkeyp
user_api_key_dict=non_admin_key_dict,
)
assert exc_info.value.status_code == 403
assert "Non-admin users must provide a user_id" in str(exc_info.value.detail)