harness: zipline's readback logs in with the right password first (its login limit answered 429 after the wrong-password control; R-742)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -826,13 +826,20 @@ class Zipline:
|
||||
return w.app_curl(sub, "/api/auth/login", "-H", "Content-Type: application/json",
|
||||
data=json.dumps({"username": t["user"], "password": p}),
|
||||
method="POST")
|
||||
rc, code, _ = login("wrong-" + secrets.token_hex(6))
|
||||
if code == "200":
|
||||
say(" zipline: READBACK UNUSABLE — a wrong password authenticated")
|
||||
return False
|
||||
rc, code, body = login(t["pw"])
|
||||
# The RIGHT password first (2026-09-30): zipline rate-limits logins, and a wrong attempt first made the
|
||||
# right one answer 429 on the bench and on 9202. The wrong one after — any non-200 (401/429) is a refusal.
|
||||
code = None
|
||||
for _ in range(6):
|
||||
rc, code, body = login(t["pw"])
|
||||
if code != "429":
|
||||
break
|
||||
time.sleep(20)
|
||||
ok = code == "200"
|
||||
say(f" zipline: login as the seeded user http={code} ok={ok}")
|
||||
rc, bad, _ = login("wrong-" + secrets.token_hex(6))
|
||||
if bad == "200":
|
||||
say(" zipline: READBACK UNUSABLE — a wrong password authenticated")
|
||||
return False
|
||||
return ok
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user