{"record":{"id":"691307e7d2e87b71","repo":"affaan-m/ECC","slug":"live-transport-requires-taste-forge-allow-live-1-691307","errorCode":null,"errorMessage":"live transport requires TASTE_FORGE_ALLOW_LIVE=1","messagePattern":"live transport requires TASTE_FORGE_ALLOW_LIVE=1","errorType":"exception","errorClass":"FalError","httpStatus":null,"severity":"error","filePath":"skills/taste-distillation/scripts/taste/falapi.py","lineNumber":182,"sourceCode":"\ndef is_dry_run() -> bool:\n    \"\"\"True when ``TASTE_FORGE_DRY_RUN`` is set to a truthy value.\n\n    Read live rather than snapshotted at import so a CLI's ``--dry-run`` flag\n    can enable it after this module is already imported.\n    \"\"\"\n    return os.environ.get(DRY_RUN_ENV, \"\").strip().lower() in {\"1\", \"true\", \"yes\", \"on\"}\n\n\ndef enable_dry_run() -> None:\n    \"\"\"Turn on dry-run mode for this process (what ``--dry-run`` calls).\"\"\"\n    os.environ[DRY_RUN_ENV] = \"1\"\n\n\ndef require_live() -> None:\n    \"\"\"Require explicit process-level authorization before any live transport.\"\"\"\n    if os.environ.get(\"TASTE_FORGE_ALLOW_LIVE\") != \"1\":\n        raise FalError(\"live transport requires TASTE_FORGE_ALLOW_LIVE=1\")\n\n\ndef safe_url(url: str) -> str:\n    \"\"\"Log only origin: paths, queries and userinfo can carry signed secrets.\"\"\"\n    try:\n        parsed = urllib.parse.urlsplit(url)\n        return f\"{parsed.scheme}://{parsed.hostname or '[invalid-host]'}\"\n    except ValueError:\n        return \"[invalid-url]\"\n\n\ndef api_key() -> str:\n    \"\"\"Return ``FAL_KEY`` after live opt-in. Never logs the value.\"\"\"\n    require_live()\n    key = os.environ.get(\"FAL_KEY\", \"\").strip()\n    if not key:\n        raise MissingKeyError(\n            \"FAL_KEY is not set.\\n\"","sourceCodeStart":164,"sourceCodeEnd":200,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/taste-distillation/scripts/taste/falapi.py#L164-L200","documentation":"require_live() is a safety gate: any live (network) transport — api_key, submit, upload, download — calls it first, and it raises falapi.FalError unless the process environment explicitly sets TASTE_FORGE_ALLOW_LIVE=1. This prevents accidental paid/unintended API calls; dry-run mode is the default posture.","triggerScenarios":"Calling falapi.api_key(), submit(), upload(), or download() (directly or via distill in live mode) while os.environ['TASTE_FORGE_ALLOW_LIVE'] != '1' — including when the variable is unset, set to '0', 'true', or 'yes' (only the exact string '1' passes).","commonSituations":"Running distill.py live for the first time without opting in; setting TASTE_FORGE_ALLOW_LIVE=true (wrong value) in CI or shell profile; exporting the variable in one shell but running the script in another; dry-run env var still set forcing the gate.","solutions":["Export TASTE_FORGE_ALLOW_LIVE=1 in the same shell/session that runs the command (exact value '1').","Prefix the command inline: TASTE_FORGE_ALLOW_LIVE=1 python distill.py <genre>.","Verify no conflicting dry-run env var (the module's DRY_RUN_ENV) is set if live calls are intended.","If live calls are NOT intended, this error is working as designed — enable dry-run mode or stop.","In scripts/CI, set the env var at the job step level rather than relying on an interactive profile."],"exampleFix":"// before\npython distill.py cinematic  # FalError: live transport requires TASTE_FORGE_ALLOW_LIVE=1\n\n// after\nexport TASTE_FORGE_ALLOW_LIVE=1   # exact value '1', not 'true'\npython distill.py cinematic","handlingStrategy":"validation","validationCode":"if os.environ.get(\"TASTE_FORGE_ALLOW_LIVE\") != \"1\":\n    raise SystemExit(\"set TASTE_FORGE_ALLOW_LIVE=1 to enable live API calls\")","typeGuard":"null","tryCatchPattern":"try:\n    falapi.submit(...)\nexcept falapi.FalError as exc:\n    if \"TASTE_FORGE_ALLOW_LIVE\" in str(exc):\n        log.error(\"live mode not authorized; export TASTE_FORGE_ALLOW_LIVE=1\")\n    raise","preventionTips":["Set TASTE_FORGE_ALLOW_LIVE=1 (exact string '1', not 'true'/'yes') in the same shell as the command","Prefer dry-run mode for development and CI","Add an env-var assertion at the top of pipeline scripts that need live mode","Remember require_live gates api_key, submit, upload, and download","Check that a lingering dry-run env var isn't blocking intended live calls"],"tags":["env-var","safety-gate","api","configuration"],"backgroundTag":"missing-env-var","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}