Skip to content

fix(tenancy): record tenant source and set Vary (#367) - #384

Open
antosubash wants to merge 2 commits into
mainfrom
fix/367-tenant-source-vary
Open

antosubash wants to merge 2 commits into
mainfrom
fix/367-tenant-source-vary

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Closes #367

TenantMiddleware now records where the bound tenant came from and tells caches what the answer depended on.

  • request.state.tenant_source: fixed, subdomain, header, session, claim, anon_header, resolver, or None.
  • Resolver seam extended backward-compatibly: may return str | None (source resolver), a (tenant_id, source) pair, or the new TenantResolution(tenant_id, source, vary).
  • Middleware merges Vary into the response (existing entries kept, case-insensitive dedupe, Vary: * untouched). Tenants resolver reports Host when subdomains are enabled and the tenant header when configured; the anonymous header fallback reports its header.
  • Docs: docs/framework/multi-tenancy.md.

Tests: new framework/hosting/tests/test_tenant_source.py and modules/tenants/tests/test_resolver_source.py. pytest framework modules/tenants: 1528 passed; make test-py: 3311 passed. make lint: ruff, ty, biome, tsc, file-size pass; the only failure is the pre-existing hardcoded-strings check on modules/tenants/tenants/module.py:38 (depends_on=["Auth", "Settings"]), which also fails on main.

https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T10:22:24.783119Z bfb0853 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9276f06
Status: ✅  Deploy successful!
Preview URL: https://70368353.simple-module-python.pages.dev
Branch Preview URL: https://fix-367-tenant-source-vary.simple-module-python.pages.dev

View logs

@antosubash antosubash added pi-ready Approved for the headless Pi worker pi-working The headless Pi worker is implementing this issue and removed pi-ready Approved for the headless Pi worker labels Oct 2, 2026
@antosubash

Copy link
Copy Markdown
Owner Author

🤖 Claimed existing pull request. I am creating an isolated worktree from origin/fix/367-tenant-source-vary and starting automatic conflict, feedback, and CI handling.

@antosubash antosubash added pi-pr-open The headless Pi worker opened a draft pull request pi-blocked The headless Pi worker needs human help and removed pi-working The headless Pi worker is implementing this issue labels Oct 2, 2026
@antosubash

Copy link
Copy Markdown
Owner Author

⛔ Blocked.

Pi CI repair failed: Encountered invalidated oauth token for user, failing request

QA evidence upload failed: ENOENT: no such file or directory, realpath '/home/anto/.local/share/pi-issue-worker/simple-module-python/worktrees/pr-384/.qa/issues/384/pr-384/runs/20261002T151330Z'

@antosubash

Copy link
Copy Markdown
Owner Author

⛔ Automatic CI repair could not continue. Add a new /pi retry comment after resolving the blocker.

Pi CI repair failed: Encountered invalidated oauth token for user, failing request

QA evidence upload failed: ENOENT: no such file or directory, realpath '/home/anto/.local/share/pi-issue-worker/simple-module-python/worktrees/pr-384/.qa/issues/384/pr-384/runs/20261002T151330Z'

@antosubash antosubash added pi-ready Approved for the headless Pi worker pi-working The headless Pi worker is implementing this issue and removed pi-blocked The headless Pi worker needs human help pi-ready Approved for the headless Pi worker labels Oct 5, 2026
@antosubash

Copy link
Copy Markdown
Owner Author

🤖 Claimed existing pull request. I am creating an isolated worktree from origin/fix/367-tenant-source-vary and starting automatic conflict, feedback, and CI handling.

@antosubash antosubash added pi-blocked The headless Pi worker needs human help and removed pi-working The headless Pi worker is implementing this issue labels Oct 5, 2026
@antosubash

Copy link
Copy Markdown
Owner Author

⛔ Blocked.

Independent QA gate: Independent QA FAILED: Tenant-source tests pass, but independent runtime checks found two Vary regressions. No browser QA was needed for this backend-only change. Evidence: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/evidence/report.md. Local report: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/result.json

@antosubash

Copy link
Copy Markdown
Owner Author

⛔ Automatic CI repair could not continue. Add a new /pi retry comment after resolving the blocker.

Independent QA gate: Independent QA FAILED: Tenant-source tests pass, but independent runtime checks found two Vary regressions. No browser QA was needed for this backend-only change. Evidence: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/evidence/report.md. Local report: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/result.json

antosubash added a commit that referenced this pull request Oct 5, 2026
@antosubash

Copy link
Copy Markdown
Owner Author

Recovered pending QA evidence publication.

Attached QA evidence

desktop.png

mobile.png

switched.png

Omitted evidence:

  • workflow.gif — Sanitized QA attachment exceeds 10 MiB: workflow.gif

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pi-blocked The headless Pi worker needs human help pi-pr-open The headless Pi worker opened a draft pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TenantMiddleware does not say whether the tenant came from the user or the header, so a cacheable anonymous read cannot set Vary correctly

1 participant