fix(guardrails): return explicitly from every Agent 365 preflight exchange outcome

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
yucheng 2026-09-30 08:39:05 +00:00
parent f00a2c1c18
commit be5a5ccf81

View file

@ -497,26 +497,25 @@ class Agent365Guardrail(CustomGuardrail):
detail=f"the Entra token endpoint could not be reached ({type(exc).__name__})",
fail_open=self.unreachable_fallback == "fail_open",
)
match exchange_result:
case Ok(_):
return SignedIn()
case Error(error):
match error.tag:
case "unauthorized":
return Rejected(detail=error.unauthorized.detail, claims=error.unauthorized.claims)
case "misconfigured":
return Unavailable(
detail=(
f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); "
"check the guardrail's client_id and client_secret"
),
fail_open=self.unreachable_fallback == "fail_open",
)
case _:
return Unavailable(
detail=f"the Entra token exchange failed ({error.summary})",
fail_open=self.unreachable_fallback == "fail_open",
)
if isinstance(exchange_result, Ok):
return SignedIn()
error: Final = exchange_result.error
match error.tag:
case "unauthorized":
return Rejected(detail=error.unauthorized.detail, claims=error.unauthorized.claims)
case "misconfigured":
return Unavailable(
detail=(
f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); "
"check the guardrail's client_id and client_secret"
),
fail_open=self.unreachable_fallback == "fail_open",
)
case _:
return Unavailable(
detail=f"the Entra token exchange failed ({error.summary})",
fail_open=self.unreachable_fallback == "fail_open",
)
async def _post_allowing_error_status(
self,