Hmbown/CodeWhale · error
expected refusal, got
Error message
expected refusal, got {other:?} What it means
Test-only panic in credentialed_base_urls_are_refused_and_the_error_names_the_route: map_identity did not return DshAdapter::Unsupported for a base URL containing userinfo credentials, so the security refusal for credentialed custom gateways did not fire.
Solutions
- Make map_identity reject any base URL whose authority contains user:password userinfo
- Return DshAdapter::Unsupported with a reason mentioning the credentialed URL
- Verify URL parsing strips credentials before the check so the refusal still triggers
Defensive patterns
Strategy: type-guard
When it happens
Trigger: Thrown at crates/tui/src/integrations/dsh/tests.rs:326 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15).
Data as JSON: /api/errors/83b42d49bf4c99c1.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/src/integrations/dsh/tests.rs:326
mapped
.disclosures
.iter()
.any(|d| d.contains("Reasoning tier is not mapped"))
);
}
#[test]
fn credentialed_base_urls_are_refused_and_the_error_names_the_route() {
let id = identity(
"custom",
"m",
"https://user:token@gateway/v1",
WireProtocol::ChatCompletions,
);
let mapped = map_identity(&id, false);
match mapped.adapter {
DshAdapter::Unsupported { reason } => assert!(reason.contains("userinfo")),
other => panic!("expected refusal, got {other:?}"),
}
let id = identity(
"custom",
"m",
"https://gateway/v1?key=abc",
WireProtocol::ChatCompletions,
);
assert!(!map_identity(&id, false).mappable());
// A Responses-dialect route with a credentialed URL is still refused —
// carrying the dialect never relaxes the structural-URL guard.
let id = identity(
"custom",
"m",
"https://user:token@gateway/v1",
WireProtocol::Responses,
);
assert!(!map_identity(&id, false).mappable());
View on GitHub (pinned to 433685b202)