fix(skills): the pooled hub client carries a default timeout

skills_hub_http_session built its httpx.Client without a timeout, so any
pooled GET that omitted an explicit timeout fell back to httpx's 5 s
default instead of the 20 s every one-shot hub GET used. Name that
default once and hand it to the pooled client and _ssrf_safe_http_get.
This commit is contained in:
kshitijk4poor
2026-09-22 14:23:35 +05:30
committed by kshitij
parent 485e05d118
commit ee340ad29b

View File

@@ -84,6 +84,8 @@ def __getattr__(name: str):
_REDIRECT_STATUS_CODES = {301, 302, 303, 307, 308}
_MAX_SKILL_FETCH_REDIRECTS = 5
# Default per-request timeout every one-shot hub GET used before pooling existed.
_DEFAULT_HTTP_TIMEOUT = 20
# An inspect resolves metadata and then the preview bundle through the same
# source adapter. Keeping this context local to that operation lets httpx reuse
@@ -99,7 +101,7 @@ def skills_hub_http_session() -> Iterator[None]:
if _skills_hub_http_client.get() is not None:
yield
return
with create_ssrf_safe_client(follow_redirects=False) as client:
with create_ssrf_safe_client(timeout=_DEFAULT_HTTP_TIMEOUT, follow_redirects=False) as client:
token = _skills_hub_http_client.set(client)
try:
yield
@@ -115,7 +117,7 @@ def _skills_hub_http_get(url: str, **kwargs: Any) -> httpx.Response:
return httpx.get(url, **kwargs)
def _ssrf_safe_http_get(url: str, *, timeout: int = 20,
def _ssrf_safe_http_get(url: str, *, timeout: int = _DEFAULT_HTTP_TIMEOUT,
headers: Optional[Dict[str, str]] = None) -> httpx.Response:
"""Fetch one URL with connect-time SSRF validation and no automatic redirects."""
client = _skills_hub_http_client.get()