fix(tenancy): record tenant source and set Vary (#367) - #384
antosubash wants to merge 2 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Deploying simple-module-python with
|
| Latest commit: |
9276f06
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://70368353.simple-module-python.pages.dev |
| Branch Preview URL: | https://fix-367-tenant-source-vary.simple-module-python.pages.dev |
|
🤖 Claimed existing pull request. I am creating an isolated worktree from |
|
⛔ Blocked. Pi CI repair failed: Encountered invalidated oauth token for user, failing request QA evidence upload failed: ENOENT: no such file or directory, realpath '/home/anto/.local/share/pi-issue-worker/simple-module-python/worktrees/pr-384/.qa/issues/384/pr-384/runs/20261002T151330Z' |
|
⛔ Automatic CI repair could not continue. Add a new Pi CI repair failed: Encountered invalidated oauth token for user, failing request QA evidence upload failed: ENOENT: no such file or directory, realpath '/home/anto/.local/share/pi-issue-worker/simple-module-python/worktrees/pr-384/.qa/issues/384/pr-384/runs/20261002T151330Z' |
|
🤖 Claimed existing pull request. I am creating an isolated worktree from |
|
⛔ Blocked. Independent QA gate: Independent QA FAILED: Tenant-source tests pass, but independent runtime checks found two Vary regressions. No browser QA was needed for this backend-only change. Evidence: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/evidence/report.md. Local report: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/result.json |
|
⛔ Automatic CI repair could not continue. Add a new Independent QA gate: Independent QA FAILED: Tenant-source tests pass, but independent runtime checks found two Vary regressions. No browser QA was needed for this backend-only change. Evidence: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/evidence/report.md. Local report: /home/anto/.local/share/pi-issue-worker/antosubash-simple-module-python-5242ec3307a6/verification/issue-384/09f5005b-5380-4b7d-aaf5-8b318e012bcc/result.json |
|
Recovered pending QA evidence publication. Attached QA evidenceOmitted evidence:
|



Closes #367
TenantMiddleware now records where the bound tenant came from and tells caches what the answer depended on.
request.state.tenant_source:fixed,subdomain,header,session,claim,anon_header,resolver, orNone.str | None(sourceresolver), a(tenant_id, source)pair, or the newTenantResolution(tenant_id, source, vary).Varyinto the response (existing entries kept, case-insensitive dedupe,Vary: *untouched). Tenants resolver reportsHostwhen subdomains are enabled and the tenant header when configured; the anonymous header fallback reports its header.Tests: new framework/hosting/tests/test_tenant_source.py and modules/tenants/tests/test_resolver_source.py.
pytest framework modules/tenants: 1528 passed;make test-py: 3311 passed.make lint: ruff, ty, biome, tsc, file-size pass; the only failure is the pre-existing hardcoded-strings check on modules/tenants/tenants/module.py:38 (depends_on=["Auth", "Settings"]), which also fails on main.https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV