fix(auth): tolerate request objects without path_params in common_checks

The PATCH /team/{team_id} org-context wiring reads request.path_params to
resolve the team id from the path. A real Starlette Request always exposes
path_params, but common_checks is exercised with lightweight request doubles
that don't, which raised AttributeError. Read it defensively so a missing or
null path_params falls back to no path team id, matching the "not a bare team
route" outcome; real requests are unaffected
This commit is contained in:
Yuneng Jiang 2026-07-11 09:44:31 -07:00
parent 6875ca00d0
commit c9259e4bf2
No known key found for this signature in database

View file

@ -726,7 +726,7 @@ async def common_checks(
route=route,
request_body=request_body,
fetch_team_org_id=_fetch_team_org_id,
path_team_id=request.path_params.get("team_id"),
path_team_id=(getattr(request, "path_params", None) or {}).get("team_id"),
)
_is_route_allowed = _is_api_route_allowed(