From 84de9a9254cf8c1949fa2c7ccb2c1484e6e8762d Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 30 Sep 2026 20:05:31 +0200 Subject: [PATCH] harness: zipline's readback logs in with the right password first (its login limit answered 429 after the wrong-password control; R-742) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- scripts/upgrade_fixtures_box.py | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/scripts/upgrade_fixtures_box.py b/scripts/upgrade_fixtures_box.py index 7f48142..1d13e78 100644 --- a/scripts/upgrade_fixtures_box.py +++ b/scripts/upgrade_fixtures_box.py @@ -826,13 +826,20 @@ class Zipline: return w.app_curl(sub, "/api/auth/login", "-H", "Content-Type: application/json", data=json.dumps({"username": t["user"], "password": p}), method="POST") - rc, code, _ = login("wrong-" + secrets.token_hex(6)) - if code == "200": - say(" zipline: READBACK UNUSABLE — a wrong password authenticated") - return False - rc, code, body = login(t["pw"]) + # The RIGHT password first (2026-09-30): zipline rate-limits logins, and a wrong attempt first made the + # right one answer 429 on the bench and on 9202. The wrong one after — any non-200 (401/429) is a refusal. + code = None + for _ in range(6): + rc, code, body = login(t["pw"]) + if code != "429": + break + time.sleep(20) ok = code == "200" say(f" zipline: login as the seeded user http={code} ok={ok}") + rc, bad, _ = login("wrong-" + secrets.token_hex(6)) + if bad == "200": + say(" zipline: READBACK UNUSABLE — a wrong password authenticated") + return False return ok