INNER CODE UNIT · Python

_validate_startup_settings

caura-ai/caura · core-api/src/core_api/app.py:164

def _validate_startup_settings(app_settings) -> None:  # type: ignore[no-untyped-def]
    """Refuse to boot when a required safety control is missing.

    Extracted from ``lifespan`` so these guards are reachable by tests. Buried in
    the lifespan they were untestable in practice, which is why a block whose
    entire job is to prevent unsafe production boots had no tests of its own.

    Storage authentication is required in every environment because the storage
    service enforces it unconditionally. Standalone mode and a missing perimeter
    are refused in every hosted environment, ``sandbox`` included. The remaining
    guards are production-only.
    """
    if _blank_secret(app_settings.core_storage_shared_secret):
        raise RuntimeError("CORE_STORAGE_SHARED_SECRET is required for core-api")
    if app_settings.environment == "development":
        return
    # Hosted from here: production, and ``sandbox``, which staging and every
    # sandbox deployment run as (M-78). Both are reachable like production, so

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…