{"record":{"id":"1365ee70a9f6ea2e","repo":"tiangolo/fastapi","slug":"no-jessica-token-provided","errorCode":null,"errorMessage":"No Jessica token provided","messagePattern":"No Jessica token provided","errorType":"http","errorClass":"HTTPException","httpStatus":400,"severity":"error","filePath":"docs_src/bigger_applications/app_an_py310/dependencies.py","lineNumber":13,"sourceCode":"from typing import Annotated\n\nfrom fastapi import Header, HTTPException\n\n\nasync def get_token_header(x_token: Annotated[str, Header()]):\n    if x_token != \"fake-super-secret-token\":\n        raise HTTPException(status_code=400, detail=\"X-Token header invalid\")\n\n\nasync def get_query_token(token: str):\n    if token != \"jessica\":\n        raise HTTPException(status_code=400, detail=\"No Jessica token provided\")\n","sourceCodeStart":1,"sourceCodeEnd":14,"githubUrl":"https://github.com/tiangolo/fastapi/blob/3e8d1526d83a90aaf7d6eb6dc682bf150f180b25/docs_src/bigger_applications/app_an_py310/dependencies.py#L1-L14","documentation":"Raised (400) by get_query_token, a startup-time dependency passed to FastAPI() constructor (dependencies=) in the bigger-applications example. It validates that the 'token' query parameter equals 'jessica'. Because it is an app-level dependency, it runs for every route in the app, not just /items.","triggerScenarios":"Any request to the app that omits ?token=jessica or sends a different value. App-level dependencies fire before route matching details, so even unrelated routes are gated.","commonSituations":"Forgetting the query param entirely; sending ?token=Jessica (case mismatch); assuming the gate is route-local when it is actually global.","solutions":["Append ?token=jessica to every request URL.","Move this from a global dependency to specific routes if it should not apply app-wide.","Remove the demo dependency entirely in real apps and use header/JWT auth."],"exampleFix":"// before\nGET /items/\n// after\nGET /items/?token=jessica","handlingStrategy":"validation","validationCode":"import httpx\nresp = httpx.get('http://localhost:8000/items/?token=jessica', headers={'X-Token': 'fake-super-secret-token'})","typeGuard":"def is_valid_query_token(value: object) -> bool:\n    return isinstance(value, str) and value == 'jessica'","tryCatchPattern":null,"preventionTips":["Remember this is an app-level dependency: it applies to every route.","Append ?token=jessica via a base-URL helper.","Remove the demo dependency before shipping."],"tags":["fastapi","authentication","query-param","dependency","bigger-applications"],"backgroundTag":null,"analyzedSha":"3e8d1526d83a90aaf7d6eb6dc682bf150f180b25","analyzedAt":"2026-08-11T02:34:52.986Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}