fix(mcp): freeze new header dicts to satisfy LIT002 type-discipline budget

_extra_headers_for_probe built its normalized/forwarded lookups as plain
dict comprehensions, and _probe_upstream_auth's extra_headers fallback used
a bare {} literal. Each is flagged as mutable-collection construction
(LIT002) by scripts/check_type_discipline.py, and the three new violations
pushed the repo-wide LIT002 count past type-discipline-budget.json's ceiling,
failing the lint job's type-discipline-budget step.

Wrap both dict comprehensions and the empty-dict fallback in
types.MappingProxyType so they freeze after construction like the rest of
the codebase's header/config maps, and widen _extra_headers_for_probe's
return type and _probe_upstream_auth's extra_headers parameter from
dict[str, str] to Mapping[str, str] to match.

Signed-off-by: Pujitha Paladugu <10557236+pujitha24@users.noreply.github.com>
This commit is contained in:
Pujitha Paladugu 2026-09-21 07:44:02 -07:00
parent d5c9d17d47
commit 818d421010
No known key found for this signature in database

View file

@ -1855,7 +1855,7 @@ if MCP_AVAILABLE:
return None
return _get_authorization_header_from_scope(scope)
def _extra_headers_for_probe(server: MCPServer, raw_headers: Mapping[str, str] | None) -> dict[str, str] | None:
def _extra_headers_for_probe(server: MCPServer, raw_headers: Mapping[str, str] | None) -> Mapping[str, str] | None:
"""Caller's values for headers this upstream is configured to read
(``server.extra_headers``), minus ``authorization`` which the probe
sets itself. Lets the pre-session probe re-run the same auth path a
@ -1863,19 +1863,21 @@ if MCP_AVAILABLE:
"""
if not server.extra_headers or not raw_headers:
return None
normalized: Final = {k.lower(): v for k, v in raw_headers.items()}
forwarded: Final = {
header: normalized[header.lower()]
for header in server.extra_headers
if header.lower() != "authorization" and header.lower() in normalized
}
normalized: Final = types.MappingProxyType({k.lower(): v for k, v in raw_headers.items()})
forwarded: Final = types.MappingProxyType(
{
header: normalized[header.lower()]
for header in server.extra_headers
if header.lower() != "authorization" and header.lower() in normalized
}
)
return forwarded or None
async def _probe_upstream_auth(
url: str,
auth_header: str,
timeout: float = 5.0,
extra_headers: dict[str, str] | None = None,
extra_headers: Mapping[str, str] | None = None,
) -> tuple[int, str | None]:
"""JSON-RPC initialize-probe the upstream URL to check whether the token is accepted.
@ -1913,7 +1915,7 @@ if MCP_AVAILABLE:
probe_headers: Final = {
"Accept": "application/json, text/event-stream",
**({"Authorization": auth_header} if auth_header else {}),
**(extra_headers or {}),
**(extra_headers or types.MappingProxyType({})),
}
try:
resp: Final = await client.post(