{"record":{"id":"74d5fded18a21b64","repo":"JuliusBrussee/caveman","slug":"remote-content-not-enabled-74d5fd","errorCode":"remote_content_not_enabled","errorMessage":"remote_content_not_enabled","messagePattern":"remote_content_not_enabled","errorType":"error_code","errorClass":"MiddlewareError","httpStatus":null,"severity":"error","filePath":"packages/sdk/python/caveman_cloud/middleware/runtime.py","lineNumber":69,"sourceCode":"                           caps.get(\"policy_revision\"), caps.get(\"persistent\"), caps.get(\"recovery\"), PREFLIGHT_ACTIONS[reason])\n\n\ndef _json(value: Any) -> str:\n    return json.dumps(value, ensure_ascii=False, separators=(\",\", \":\"), allow_nan=False)\n\n\nclass MiddlewareRuntime:\n    def __init__(self, *, endpoint: str = \"http://127.0.0.1:8787\", token: str | None = None,\n                 allow_remote_content: bool = False, mode: str = \"compress\", deadline_ms: int = 100,\n                 retrieve_deadline_ms: int = 5000,\n                 strict: bool = False, on_diagnostic: Callable[[dict], None] | None = None,\n                 on_report: Callable[[CallReport], None] | None = None):\n        url = urlsplit(endpoint)\n        local = url.hostname in (\"127.0.0.1\", \"::1\", \"localhost\")\n        if url.scheme not in (\"http\", \"https\") or not url.hostname or url.username or url.password or url.query or url.fragment or url.path not in (\"\", \"/\"):\n            raise MiddlewareError(\"invalid_endpoint\")\n        if not local and (not allow_remote_content or url.scheme != \"https\"):\n            raise MiddlewareError(\"remote_content_not_enabled\")\n        if type(deadline_ms) is not int or deadline_ms <= 0 or mode not in (\"off\", \"record\", \"compress\"):\n            raise MiddlewareError(\"invalid_configuration\")\n        # A model asking to see an original is waiting on a page of stored text,\n        # not on the optimizer in front of a provider call. Separate budget.\n        if type(retrieve_deadline_ms) is not int or retrieve_deadline_ms <= 0:\n            raise MiddlewareError(\"invalid_configuration\")\n        self.endpoint = f\"{url.scheme}://{url.netloc}\"\n        self.mode, self.deadline_ms, self.strict = mode, deadline_ms, strict\n        self.retrieve_deadline_ms = retrieve_deadline_ms\n        self._token, self._diagnostic = token, on_diagnostic\n        self._report_sink, self._last_report = on_report, None\n        self._url = url\n        self._connections: set[http.client.HTTPConnection] = set()\n        self._caps: dict | None = None\n        self._bindings: weakref.WeakKeyDictionary[RecoveryBinding, tuple] = weakref.WeakKeyDictionary()\n        self._lock = threading.RLock()\n        self._slots = threading.BoundedSemaphore(16)\n        self._closed = False","sourceCodeStart":51,"sourceCodeEnd":87,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/packages/sdk/python/caveman_cloud/middleware/runtime.py#L51-L87","documentation":"For non-local (remote) endpoints the runtime requires allow_remote_content=True AND an https scheme; otherwise it raises MiddlewareError(\"remote_content_not_enabled\"). This is a safety guard preventing original prompt/response content from traveling to remote hosts unencrypted or without explicit opt-in.","triggerScenarios":"Constructing the runtime with a remote hostname (not 127.0.0.1/::1/localhost) while either allow_remote_content is left at its default False, or the endpoint uses plain http.","commonSituations":"Pointing the middleware at a staging/production proxy over http; forgetting the allow_remote_content flag when moving from local dev to a remote gateway; TLS terminated in front so the app uses http internally.","solutions":["Set allow_remote_content=True and use an https:// endpoint","For local development, keep the endpoint on 127.0.0.1/localhost (http is allowed for local hosts)","If TLS terminates at a proxy, use https end-to-end or run the runtime locally","Catch MiddlewareError(\"remote_content_not_enabled\") in bootstrap code to surface the misconfiguration clearly"],"exampleFix":"// before\nRuntime(endpoint=\"http://proxy.example.com\")  # remote + http\n// after\nRuntime(endpoint=\"https://proxy.example.com\", allow_remote_content=True)","handlingStrategy":"validation","validationCode":"from urllib.parse import urlsplit\ndef remote_endpoint_ready(endpoint: str, allow_remote_content: bool) -> bool:\n    u = urlsplit(endpoint)\n    local = u.hostname in ('127.0.0.1', '::1', 'localhost')\n    return local or (allow_remote_content and u.scheme == 'https')","typeGuard":null,"tryCatchPattern":"try:\n    runtime = Runtime(endpoint=ep, allow_remote_content=allow_remote)\nexcept MiddlewareError as e:\n    if str(e) == 'remote_content_not_enabled':\n        raise ConfigError('remote endpoints require allow_remote_content=True and https') from e\n    raise","preventionTips":["Use https:// for every non-localhost endpoint","Set allow_remote_content=True explicitly (never rely on defaults) when going remote","Keep local development on 127.0.0.1/localhost where http is permitted","Add an env-specific config assertion: remote configs must be https + opt-in"],"tags":["python","security","https","middleware"],"backgroundTag":"invalid-config-value","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}