Skip to content

fix: isolate request headers and generated idempotency keys - #136

Open
Shubham-Padkonde wants to merge 1 commit into
chargebee:masterfrom
Shubham-Padkonde:fix/isolate-request-headers
Open

Shubham-Padkonde wants to merge 1 commit into
chargebee:masterfrom
Shubham-Padkonde:fix/isolate-request-headers

Conversation

@Shubham-Padkonde

Copy link
Copy Markdown

Passing the same nonempty headers dictionary to separate requests causes the SDK to write its generated idempotency key back into that dictionary. Later POSTs reuse the key instead of receiving independent keys. Authorization, content type, and retry headers also leak into caller-owned state.

Copy headers at the request boundary. Retries within a request continue sharing their generated key; explicit keys remain unchanged.

Validation: all 62 unittest tests pass. Sync/async repeated-call regressions and caller-header preservation fail before the fix. An additional 503-to-200 test confirms retries retain their key and add the retry-attempt header without mutating caller input. git diff --check passes. Independent of #134 and #135.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Warning

Review limit reached

This review ran on the open-source allowance, not this organization's plan, because the pull request author doesn't have an assigned seat. Waiting won't change this — ask an organization admin to assign them a seat, or add seats in Billing if every seat is already assigned, then retry.

Next included review available in 48 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 348314d1-4aa6-4865-bd5a-6b882a89f093

📥 Commits

Reviewing files that changed from the base of the PR and between f1fbfde and bc10266.

📒 Files selected for processing (2)
  • chargebee/http_request.py
  • tests/test_http_request.py
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@snyk-io

snyk-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues
✅ Secrets 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant