Hmbown/CodeWhale · error

expected refusal, got

Error message

expected refusal, got {other:?}

What it means

Test-only panic in credentialed_base_urls_are_refused_and_the_error_names_the_route: map_identity did not return DshAdapter::Unsupported for a base URL containing userinfo credentials, so the security refusal for credentialed custom gateways did not fire.

Solutions

  1. Make map_identity reject any base URL whose authority contains user:password userinfo
  2. Return DshAdapter::Unsupported with a reason mentioning the credentialed URL
  3. Verify URL parsing strips credentials before the check so the refusal still triggers
Defensive patterns

Strategy: type-guard

When it happens

Trigger: Thrown at crates/tui/src/integrations/dsh/tests.rs:326 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/83b42d49bf4c99c1. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/integrations/dsh/tests.rs:326

        mapped
            .disclosures
            .iter()
            .any(|d| d.contains("Reasoning tier is not mapped"))
    );
}

#[test]
fn credentialed_base_urls_are_refused_and_the_error_names_the_route() {
    let id = identity(
        "custom",
        "m",
        "https://user:token@gateway/v1",
        WireProtocol::ChatCompletions,
    );
    let mapped = map_identity(&id, false);
    match mapped.adapter {
        DshAdapter::Unsupported { reason } => assert!(reason.contains("userinfo")),
        other => panic!("expected refusal, got {other:?}"),
    }
    let id = identity(
        "custom",
        "m",
        "https://gateway/v1?key=abc",
        WireProtocol::ChatCompletions,
    );
    assert!(!map_identity(&id, false).mappable());
    // A Responses-dialect route with a credentialed URL is still refused —
    // carrying the dialect never relaxes the structural-URL guard.
    let id = identity(
        "custom",
        "m",
        "https://user:token@gateway/v1",
        WireProtocol::Responses,
    );
    assert!(!map_identity(&id, false).mappable());

View on GitHub (pinned to 433685b202)