{"record":{"id":"83b42d49bf4c99c1","repo":"Hmbown/CodeWhale","slug":"expected-refusal-got-other","errorCode":null,"errorMessage":"expected refusal, got {other:?}","messagePattern":"expected refusal, got (.+?)","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/integrations/dsh/tests.rs","lineNumber":326,"sourceCode":"        mapped\n            .disclosures\n            .iter()\n            .any(|d| d.contains(\"Reasoning tier is not mapped\"))\n    );\n}\n\n#[test]\nfn credentialed_base_urls_are_refused_and_the_error_names_the_route() {\n    let id = identity(\n        \"custom\",\n        \"m\",\n        \"https://user:token@gateway/v1\",\n        WireProtocol::ChatCompletions,\n    );\n    let mapped = map_identity(&id, false);\n    match mapped.adapter {\n        DshAdapter::Unsupported { reason } => assert!(reason.contains(\"userinfo\")),\n        other => panic!(\"expected refusal, got {other:?}\"),\n    }\n    let id = identity(\n        \"custom\",\n        \"m\",\n        \"https://gateway/v1?key=abc\",\n        WireProtocol::ChatCompletions,\n    );\n    assert!(!map_identity(&id, false).mappable());\n    // A Responses-dialect route with a credentialed URL is still refused —\n    // carrying the dialect never relaxes the structural-URL guard.\n    let id = identity(\n        \"custom\",\n        \"m\",\n        \"https://user:token@gateway/v1\",\n        WireProtocol::Responses,\n    );\n    assert!(!map_identity(&id, false).mappable());\n","sourceCodeStart":308,"sourceCodeEnd":344,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/crates/tui/src/integrations/dsh/tests.rs#L308-L344","documentation":"Test-only panic in credentialed_base_urls_are_refused_and_the_error_names_the_route: map_identity did not return DshAdapter::Unsupported for a base URL containing userinfo credentials, so the security refusal for credentialed custom gateways did not fire.","triggerScenarios":"Thrown at crates/tui/src/integrations/dsh/tests.rs:326 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Make map_identity reject any base URL whose authority contains user:password userinfo","Return DshAdapter::Unsupported with a reason mentioning the credentialed URL","Verify URL parsing strips credentials before the check so the refusal still triggers"],"exampleFix":null,"handlingStrategy":"type-guard","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}