fix(runtime): handle synthetic requests without app scope and update env reference

- Narrowly guard _request_privileges() in routes/chat_routes.py against
  synthetic requests lacking scope['app'] or auth manager state, safely
  returning empty privileges without granting agent privileges.
- Add focused regression test in tests/test_context_resolution_route.py
  verifying that requests without app scope do not crash and cannot gain
  agent privileges or qualify for compact preview runtime.
- Regenerate website/configuration-reference.md mechanically to align with
  current source line numbers.
This commit is contained in:
Alexandre Teixeira
2026-10-01 23:38:45 +01:00
parent 57fe9946c2
commit cdbcb44cc9
3 changed files with 36 additions and 9 deletions
+6 -1
View File
@@ -148,7 +148,12 @@ def _turn_contract_enabled(*, exact_tool_approval, runtime_surface,
def _request_privileges(request, user) -> Dict[str, Any]:
"""Per-user privileges from the app's auth manager; empty when unmanaged."""
auth_manager = getattr(request.app.state, "auth_manager", None)
try:
app = getattr(request, "app", None)
except (AttributeError, KeyError):
app = None
state = getattr(app, "state", None) if app is not None else None
auth_manager = getattr(state, "auth_manager", None) if state is not None else None
if not user or not auth_manager:
return {}
return auth_manager.get_privileges(user) or {}