fix(pr-triage): diagnose non-JSON model replies, never follow redirects, log credential presence - #3
Merged
Conversation
…rects Co-Authored-By: Lykos (Fable 5.1) <noreply@lykos.ai>
mohnjiles
approved these changes
Sep 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The first credentialed live run (Core #100, run 33835572197) landed on the offline path with
Model unreachable: JSONDecodeError: Expecting value: line 1 column 1 (char 0)about 250 ms after the request: a 2xx with a non-JSON body, which is what urllib produces when it follows a Cloudflare Access 302 to the login page. The script now says so itself._NoRedirectopener). A 3xx is reported asHTTP 302 redirect to <Location host>; an Access login page means the service token was not accepted. Only the host of the Location is logged, not its query.CF_ACCESS_CLIENT_ID,CF_ACCESS_CLIENT_SECRET,LLM_API_KEY, whether it was present and non-empty plus its length, never a character of it. That separates "headers not sent" from "sent and refused" on the next run.::warning::in the log, exit 0).http()returns anHttpResponse(status, body, headers, final URL) instead of a tuple.Tests, 47 → 52, all local: the fake server gained
redirectandhtmlmodes. The redirect Location points back at the fake, so following it would show up as a second request; the test asserts exactly one model request and none to the login path, and that the warning names the 302 and the host. The HTML case asserts status, URL, Content-Type and the capped prefix against a body over 200 characters (my first version of that assertion was vacuous against a 103-character body, under the cap; it failed and the body got longer). Presence line pinned both ways (values set →present=True len=N; unset/empty →present=False len=0).ask_modelis also called directly against the fake for both modes.Mutation probe, committed first: flip
follow_redirects=Falseback toTrueon the model call →test_access_redirect_is_reported_as_a_302_and_never_followedandtest_ask_model_raises_a_diagnosable_error_on_redirect_and_htmlred; reverted; 52 green.Not verified: the next live run, which is what this exists to read.
🐺 Generated with Lykos (Fable 5.1)