Repository navigation
fix: billing_client.py 404s against the real billing-service route - #82
Merged
Merged
Conversation
…te without its /billing router prefix
organization_has_active_plan() called
http://billing-service:8005/organizations/{id}/subscription, but
billing-service's own router is mounted at /billing
(app/routers/billing.py's APIRouter(prefix="/billing")) -- the real
path is /billing/organizations/{id}/subscription. Every call this
function ever made 404'd against the real service, which the fail-
closed-on-404 branch then correctly (but wrongly, given the actual
cause) treated as "no subscription at all" -- blocking self-service
API key creation for every organization, always, regardless of real
subscription status.
Caught via a live-stack smoke test, not this module's own unit suite:
every test here mocks httpx.get directly, so none of them ever
exercised the real URL against the real billing-service router. The
one test that came closest (asserting the URL) used .endswith(), which
is satisfied by both the correct and the broken path -- tightened to
an exact match so this exact bug class can't silently recur.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
organization_has_active_plan()calledhttp://billing-service:8005/organizations/{id}/subscription, but billing-service's own router is mounted at/billing(app/routers/billing.py'sAPIRouter(prefix="/billing")) -- the real path is/billing/organizations/{id}/subscription.Impact: every call this function ever made 404'd against the real service in a real deployment. The fail-closed-on-404 branch then correctly (but for the wrong reason) treated that as "no subscription at all," blocking self-service API key creation for every organization, always, regardless of actual subscription status -- found while testing a brand-new non-admin account's "Create key" flow against a live stack.
Why the unit suite never caught it: every test in
test_billing_client.pymockshttpx.getdirectly, so none of them ever exercised the real URL against the real billing-service router. The one test that came closest (asserting the URL) used.endswith(...), which is satisfied by both the correct and the broken path -- tightened to an exact-match assertion so this exact bug class can't silently recur.Test plan
pytest tests/test_billing_client.py -q-- 9 passed🤖 Generated with Claude Code