fix(login): reject malformed API token values in sign-in responses

This commit is contained in:
Alex Schapiro 2026-08-26 21:24:57 +00:00
parent d6ccb7c38a
commit 04a77e50e7

View file

@ -265,7 +265,8 @@ def _signed_in_record(response: requests.Response) -> dict[str, Any]:
def _require_api_token(record: dict[str, Any]) -> dict[str, Any]:
if not str(record.get("api_token") or ""):
api_token = record.get("api_token")
if not isinstance(api_token, str) or not api_token.strip():
raise PlatformAuthError("the server returned a sign-in response without an API token")
return record