Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ rather than run unoptimised, and the same applies to the PyO3 module, which need
Most tests are integration tests that call a live backend via `create_api_service()`. They read configuration from a local `.env` file (gitignored). Required:

- `BASE_URL` — backend root, e.g. `http://localhost:8081`
- Either `TOKEN` (bearer token used as-is, no expiry) **or** the OAuth2 client-credentials set: `CLIENT_ID`, `CLIENT_SECRET`, `TOKEN_URI` (optional: `PROJECT_NAME`)
- Either `TOKEN` (bearer token used as-is, no expiry) **or** the OAuth2 client-credentials set: `CLIENT_ID`, `CLIENT_SECRET`, `TOKEN_URI`

Tests that mutate backend state (create/delete) often `sleep` a few seconds between operations and are sensitive to race conditions — prefer running them serially or isolating by unique external IDs.

Expand Down Expand Up @@ -245,10 +245,10 @@ refusal, so a by-id 404 carries `type: …/errors/not-found` and **`slug()` matc
stays as the regression guard.

401s carry a problem document too, with `type: …/errors/unauthorized` and a `detail` naming the
check that failed — a missing, empty, malformed or ambiguous `organization` claim. That is the
reason `src/auth_diagnostics.rs` reconstructs from the token it just sent, so the SDK now appends
a near-duplicate of what the server already said. Note every entry-point 401 shares the
`unauthorized` slug, so the cause is in the prose and cannot be branched on.
check that failed — a missing, empty, malformed or ambiguous `organization` claim. That retired
the SDK's own `auth_diagnostics` module, which existed only to reconstruct the reason from the
token it had just sent. Note every entry-point 401 shares the `unauthorized` slug, so the cause is
in the prose and cannot be branched on.

### Filters (`src/filters.rs`)

Expand Down
3 changes: 0 additions & 3 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -39,9 +39,6 @@ infer = { version = "0.19", default-features = false, features = ["std"] }
thiserror = "2.0.17"
zstd = "0.13"
geojson = "1"
# Reading (never verifying) the payload of a JWT the SDK already holds, to explain an
# otherwise-unexplained 401 — see `auth_diagnostics`.
base64 = "0.22"
arrow-array = "59.3"
arrow-schema = "59.3"
arrow-ipc = "59.3"
Expand Down
1 change: 0 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,6 @@ environment:
- `BASE_URL` — backend root, e.g. `http://localhost:8081` (required)
- Either `TOKEN` (bearer token used as-is, never considered expired), **or** the OAuth2
client-credentials set: `CLIENT_ID`, `CLIENT_SECRET`, `TOKEN_URI`
- `PROJECT_NAME` — optional
- `SCOPE` — against DataHub, needed when the realm uses Keycloak Organizations: that claim comes
from a dynamic client scope, so the request must name it (`organization:*`, or
`organization:<alias>` to pin one tenant). Without it the token carries no tenant and every call
Expand Down
8 changes: 0 additions & 8 deletions datahub_python_bindings/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -150,7 +150,6 @@ fn build_buffered_config(
token_url: Option<String>,
client_id: Option<String>,
client_secret: Option<String>,
project_name: Option<String>,
enable_buffering: bool,
buffer_retention_secs: Option<i64>,
buffer_max_bytes: Option<u64>,
Expand All @@ -171,7 +170,6 @@ fn build_buffered_config(
token_url,
client_id,
client_secret,
project_name,
);
if let Some(secs) = buffer_retention_secs {
config.set_buffer_retention_secs(secs);
Expand Down Expand Up @@ -226,7 +224,6 @@ impl PySyncClient {
token_url=None,
client_id=None,
client_secret=None,
project_name=None,
enable_buffering=false,
buffer_retention_secs=None,
buffer_max_bytes=None,
Expand All @@ -247,7 +244,6 @@ impl PySyncClient {
token_url: Option<String>,
client_id: Option<String>,
client_secret: Option<String>,
project_name: Option<String>,
enable_buffering: bool,
buffer_retention_secs: Option<i64>,
buffer_max_bytes: Option<u64>,
Expand All @@ -269,7 +265,6 @@ impl PySyncClient {
token_url,
client_id,
client_secret,
project_name,
enable_buffering,
buffer_retention_secs,
buffer_max_bytes,
Expand Down Expand Up @@ -404,7 +399,6 @@ impl PyAsyncClient {
token_url=None,
client_id=None,
client_secret=None,
project_name=None,
enable_buffering=false,
buffer_retention_secs=None,
buffer_max_bytes=None,
Expand All @@ -425,7 +419,6 @@ impl PyAsyncClient {
token_url: Option<String>,
client_id: Option<String>,
client_secret: Option<String>,
project_name: Option<String>,
enable_buffering: bool,
buffer_retention_secs: Option<i64>,
buffer_max_bytes: Option<u64>,
Expand All @@ -447,7 +440,6 @@ impl PyAsyncClient {
token_url,
client_id,
client_secret,
project_name,
enable_buffering,
buffer_retention_secs,
buffer_max_bytes,
Expand Down
2 changes: 1 addition & 1 deletion python_tests/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,7 @@ The fixtures build a client from an env file containing at least:

- `BASE_URL` — backend root, e.g. `http://localhost:8081`
- **either** `TOKEN` (a bearer token used as-is) **or** the OAuth2 client-credentials set
`CLIENT_ID` / `CLIENT_SECRET` / `TOKEN_URI` (optional `PROJECT_NAME`)
`CLIENT_ID` / `CLIENT_SECRET` / `TOKEN_URI`

A gitignored `.env` already exists at the repo root. Make sure it points at a backend you
can reach and that the credentials are valid.
Expand Down
2 changes: 0 additions & 2 deletions python_tests/test_auth_constructor.py
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,6 @@ def _client_credentials_kwargs(env):
client_secret=client_secret,
scope=env.get("SCOPE"),
audience=env.get("AUDIENCE"),
project_name=env.get("PROJECT_NAME"),
)


Expand All @@ -75,7 +74,6 @@ def _federated_kwargs(env):
token_url=env["TOKEN_URI"],
scope=env.get("SCOPE"),
audience=env.get("AUDIENCE"),
project_name=env.get("PROJECT_NAME"),
assertion=env.get("ASSERTION"),
assertion_token_url=env.get("ASSERTION_TOKEN_URI"),
assertion_client_id=env.get("ASSERTION_CLIENT_ID"),
Expand Down
221 changes: 0 additions & 221 deletions src/auth_diagnostics.rs

This file was deleted.

1 change: 0 additions & 1 deletion src/buffer_integration.rs
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,6 @@ fn unreachable_buffered_service(dir: &PathBuf) -> Arc<ApiService> {
None,
None,
None,
None,
);
config
.set_buffer_dir(dir.clone())
Expand Down
Loading
Loading