From ed2dd27e85df87d48b0c574e39edf697c3f2f106 Mon Sep 17 00:00:00 2001 From: kshitijk4poor <82637225+kshitijk4poor@users.noreply.github.com> Date: Fri, 11 Sep 2026 12:16:23 +0530 Subject: [PATCH] test(anthropic): portal bearer test asserts the wire headers, not the api_key attribute The bearer guard is now an Omit() default header (copy-safe), so the SDK attribute may still hold the env key while nothing reaches the wire. Assert on _build_headers for the client and a with_options() copy instead. --- tests/agent/test_nous_portal_anthropic_wire.py | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/tests/agent/test_nous_portal_anthropic_wire.py b/tests/agent/test_nous_portal_anthropic_wire.py index 32f9eb756e..bb2e378c8a 100644 --- a/tests/agent/test_nous_portal_anthropic_wire.py +++ b/tests/agent/test_nous_portal_anthropic_wire.py @@ -212,12 +212,16 @@ class TestClientShape: monkeypatch.setenv("ANTHROPIC_API_KEY", "sk-ant-should-not-leak") client = build_anthropic_client("portal-invoke-jwt", PORTAL_URL) + from anthropic._models import FinalRequestOptions + assert client.auth_token == "portal-invoke-jwt" - assert client.api_key is None - assert "X-Api-Key" not in client.auth_headers - assert client.auth_headers.get("Authorization", "").startswith( - "Bearer portal-invoke-jwt" - ) + # The guard is a copy-safe Omit() default header, so assert what reaches the wire — + # on the client and on a with_options() copy (which re-reads ANTHROPIC_API_KEY). + for wire_client in (client, client.with_options(timeout=30)): + headers = dict(wire_client._build_headers( + FinalRequestOptions(method="post", url="/v1/messages", json_data={}))) + assert "x-api-key" not in headers + assert headers.get("authorization", "").startswith("Bearer portal-invoke-jwt")