Skip to content

fix(client): validate bearer auth for async web search and fetch - #745

Open
makiaveli1 wants to merge 1 commit into
ollama:mainfrom
makiaveli1:fix/async-web-auth-parity
Open

makiaveli1 wants to merge 1 commit into
ollama:mainfrom
makiaveli1:fix/async-web-auth-parity

Conversation

@makiaveli1

Copy link
Copy Markdown

Client.web_search and Client.web_fetch raise a ValueError when no Bearer token is configured:

if not self._client.headers.get('authorization', '').startswith('Bearer '):
  raise ValueError('Authorization header with Bearer token is required for web search')

The AsyncClient versions of both methods omitted that check (and the matching Raises: docstring line), so an async caller without OLLAMA_API_KEY does not get the documented error. The request goes out and comes back as a ResponseError instead:

ollama._types.ResponseError: Unauthorized (status code: 401)

The async methods now perform the same check as their sync counterparts.

Verification:

  • python -m pytest tests/ -q -> 99 passed
  • Two new tests, test_async_client_web_search_requires_bearer_auth_header and test_async_client_web_fetch_requires_bearer_auth_header, mirror the existing sync tests. Both fail against the current code with the 401 above, and pass with this change.
  • ruff check and ruff format --check -> clean

AI assistance: the analysis, fix and tests were prepared with an AI coding agent at my direction. I reproduced the behaviour locally, reviewed the change, and ran the checks above.

Client.web_search and Client.web_fetch raise a ValueError when no Bearer
token is configured, but the AsyncClient methods skipped that check, so
async callers without an API key sent a request that failed later with a
401 ResponseError instead of the documented ValueError.

Add the same check, and the matching docstring line, to the async methods.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant