Stage 8 · L35
Prepare authorized values and share an HTTP client
Core · original Session 8
Provider preparation is an authorization boundary. A caller selects a rental UUID; prepare_lookup obtains current identity and queries only allowed rental rows. Ordinary users cannot prepare another owner's reference. The client never supplies the outbound provider URL, a foreign owner or the provider's equipment identifier directly.
The result is Reference(rental_id, equipment_id), a frozen dataclass of primitive identifiers. It is safe to pass across the await boundary because it cannot lazily load a relationship. The session closes at the end of the synchronous dependency. The real TCP fixture patches equipment.api.SessionLocal where it is actually used and observes zero live sessions when the provider receives the request.
This snapshot accepts only a loopback teaching provider origin and constructs the /status/{rental_id} path itself. It disables inherited proxy settings and redirect following. The outbound request does not forward the inbound Authorization token or arbitrary headers. The real fixture records the request and proves Authorization is absent.
A provider observation is read-only supplementary information. It does not change rental state, stock, price or ownership. Local capacity remains governed by the database service even if the provider says available=True. A stale external response must never manufacture a successful reservation.
The existing v1 Equipment /quotes example is public and has no record-specific preparation. This separate v2 path adds that scoped boundary deliberately. It does not imply a live provider is configured or that public v1 behavior was deployed differently. Tests use synthetic owned records and one local server.
Follow the running code
Focused lesson example; see the end-of-stage capstone for the cumulative app · stage 08
Authorized local read → copy rental/equipment identifiers → close session
Then async HTTP uses those plain identifiers.
async with httpx.AsyncClient(base_url=trusted_origin,
trust_env=False, follow_redirects=False) as client:
response = await client.get('/status/' + str(rental_id))Predict and observe this focused example using the concepts explained above. Its boundary is stated in the focused answer.
Guided lab
- Read the explanation and predict the focused example’s outcome.
- Identify where authorization finishes and why neither an ORM row, request session nor bearer token belongs in the provider request.
- Compare the observed outcome with the focused answer and state its boundary.
From the extracted stage starter root, after completing its README setup:
python run_checks.py --stage 08 --role starter --walkthrough provider
Expected: The local scoped query finishes and closes before await; frozen/plain identifiers cross the boundary. The lifespan owns and closes the shared HTTP client. trust_env=False/no redirects avoids inherited proxy/auth forwarding. The local walkthrough starts its own provider; no commercial service or API key is assumed.
- A caller-selected URL risks an uncontrolled boundary; closing a session after awaiting still holds it during network time.
Focused exercise and answer
Complete this focused exercise before reading its answer. The full native transfer is introduced only at the end of the stage.
Your transfer task: Identify where authorization finishes and why neither an ORM row, request session nor bearer token belongs in the provider request.
- Identify where authorization finishes and why neither an ORM row, request session nor bearer token belongs in the provider request.
Inspect the matching answer
This answer addresses the focused exercise above; the cumulative implementation is shown only after the stage prerequisites.
The local scoped query finishes and closes before await; frozen/plain identifiers cross the boundary. The lifespan owns and closes the shared HTTP client. trust_env=False/no redirects avoids inherited proxy/auth forwarding. The local walkthrough starts its own provider; no commercial service or API key is assumed.Check your reasoning
Which data may cross the await boundary here?
Show the explanation
Frozen primitive identifiers from an authorized query; no open session, lazy ORM object or inbound credential.
Reading progress
54 lessons remain open to guests. Marking a lesson read records reading only; it does not award assessment credit or a certificate.
Device reading marks require browser storage. Reading is always available.
Sign in or create an account to save separate account progress. Your current page is kept.
Your earlier place on this device suggests these lessons. No new lesson is marked read.