refactor(skills): collapse the pooled-else-fresh branches of _ssrf_safe_http_get

`_ssrf_safe_http_get` re-implemented the "active pool client else fresh
client" split that `_skills_hub_http_get` introduced, with two separate
`.get(...)` calls. Pick the context manager once (`nullcontext(pooled)`
or a fresh `create_ssrf_safe_client(...)`) and issue a single GET. The
fallbacks stay distinct on purpose: this helper builds a guarded client,
`_skills_hub_http_get` falls back to bare `httpx.get`.

PROOF: behaviour-preserving; 345 tests across the 21 hub/skills test
files (tests/hermes_cli + tests/tools matching skills_hub /
_ssrf_safe_http_get) pass, 0 failed, including the pool-reuse test that
asserts exactly one client is created during inspect.
This commit is contained in:
kshitijk4poor
2026-09-22 15:17:23 +05:30
committed by kshitij
parent 4036ba8c17
commit 8f4db9396f

View File

@@ -15,7 +15,7 @@ import json
import logging
import time
from contextvars import ContextVar
from contextlib import ExitStack, contextmanager
from contextlib import ExitStack, contextmanager, nullcontext
from datetime import datetime, timezone
from pathlib import Path
from typing import Any, Dict, Iterator, List, Optional
@@ -120,11 +120,13 @@ def _skills_hub_http_get(url: str, **kwargs: Any) -> httpx.Response:
def _ssrf_safe_http_get(url: str, *, timeout: int = _DEFAULT_HTTP_TIMEOUT,
headers: Optional[Dict[str, str]] = None) -> httpx.Response:
"""Fetch one URL with connect-time SSRF validation and no automatic redirects."""
client = _skills_hub_http_client.get()
if client is not None:
return client.get(url, timeout=timeout, headers=headers)
with create_ssrf_safe_client(timeout=timeout, follow_redirects=False) as client:
return client.get(url, headers=headers)
cm = (
nullcontext(client)
if (client := _skills_hub_http_client.get()) is not None
else create_ssrf_safe_client(timeout=timeout, follow_redirects=False)
)
with cm as c:
return c.get(url, timeout=timeout, headers=headers)
def _guarded_http_get(url: str, *, timeout: int = 20,