Repository navigation
fix: isolate request headers and generated idempotency keys - #136
Shubham-Padkonde wants to merge 1 commit into
Conversation
|
Warning Review limit reachedThis review ran on the open-source allowance, not this organization's plan, because the pull request author doesn't have an assigned seat. Waiting won't change this — ask an organization admin to assign them a seat, or add seats in Billing if every seat is already assigned, then retry. Next included review available in 48 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Comment |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Passing the same nonempty headers dictionary to separate requests causes the SDK to write its generated idempotency key back into that dictionary. Later POSTs reuse the key instead of receiving independent keys. Authorization, content type, and retry headers also leak into caller-owned state.
Copy headers at the request boundary. Retries within a request continue sharing their generated key; explicit keys remain unchanged.
Validation: all 62 unittest tests pass. Sync/async repeated-call regressions and caller-header preservation fail before the fix. An additional 503-to-200 test confirms retries retain their key and add the retry-attempt header without mutating caller input. git diff --check passes. Independent of #134 and #135.