affaan-m/ECC · error · ProviderNotAuthorizedError

provider is not available: provider generation in…

Error message

provider {provider!r} is not available: provider generation in TasteForge requires explicit separately authorized execution. This package ships no provider adapters and performs no network calls; the deterministic offline workflows (inspect/validate/interview/distill dry-run/apply local/export) need no provider.

What it means

providers.get() fails closed: it raises ProviderNotAuthorizedError before any import or I/O when the provider is absent from the registry or registered without authorization. This enforces the design rule that TasteForge ships no provider adapters and performs no network calls; offline workflows need no provider.

Solutions

  1. Use the offline workflows (inspect/validate/interview/distill dry-run/apply local/export) which require no provider
  2. If provider generation is truly required, call register(name, factory, authorize=True) AND set the TASTEFORGE_ALLOW_PROVIDERS env flag, both deliberately
  3. Remove the provider-generation call entirely — the package intentionally has no built-in adapters

Example fix

// before
adapter = providers.get("openai")  # never registered
// after
# offline path — no provider needed
result = distill_dry_run(pack)  # or: explicitly register + opt-in env flag
providers.register("openai", my_factory, authorize=True)
# with TASTEFORGE_ALLOW_PROVIDERS=1 in the environment
adapter = providers.get("openai")
Defensive patterns

Strategy: try-catch

Validate before calling

# no provider is needed for offline workflows; prefer them
result = validate(pack)  # or inspect / interview / distill dry-run / apply local / export

Try / catch

try:
    adapter = providers.get(name)
except ProviderNotAuthorizedError:
    adapter = None  # fall back to the deterministic offline workflow

Prevention

When it happens

Trigger: Calling get("openai") (or any name) when no adapter was ever registered; calling get on a name registered with authorize=False; calling from code that expects a networked generation path inside an offline workflow.

Common situations: Migrating scripts from other AI toolkits that assume a built-in provider; copy-pasted code calling provider generation when the deterministic offline workflow suffices; expecting an env var alone to enable an unregistered provider.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/17f23c30958ad87a. Report an issue: GitHub.

Appendix: source

Thrown at skills/taste-application/scripts/tasteforge/providers.py:54

AdapterFactory = Callable[[], Any]


def list_providers() -> list[str]:
    """Registered provider ids. Always empty in this lane."""
    return sorted(_REGISTRY)


def get(provider: str) -> Any:
    """Return the adapter for ``provider`` or fail closed.

    Fails closed - raising before any import or I/O - unless the provider was
    explicitly registered with authorization AND the opt-in environment flag
    is set. No provider is ever registered by this package.
    """
    entry = _REGISTRY.get(provider)
    if entry is None or not entry.get("authorized"):
        raise ProviderNotAuthorizedError(_FAIL_CLOSED_MESSAGE.format(provider=provider))
    if os.environ.get(ALLOW_ENV, "").strip().lower() not in {"1", "true", "yes", "on"}:
        raise ProviderNotAuthorizedError(_FAIL_CLOSED_MESSAGE.format(provider=provider))
    return entry["factory"]()


def register(
    provider: str,
    callable_factory: AdapterFactory,
    *,
    authorize: bool = False,
) -> None:
    """Register an adapter factory. Refuses silent authorization.

    ``authorize=True`` without the ``TASTEFORGE_ALLOW_PROVIDERS`` environment
    flag is still a refusal: enabling a provider is a two-step deliberate act,
    never a default.
    """
    if not authorize:

View on GitHub (pinned to 8321021c54)