Skip to content
Aabha AI Academy

Stage 8 · L36

Validate provider payloads and bound the whole lookup

Core · original Session 8

A successful HTTP status is not enough to trust a provider body. ProviderStatus requires a UUID rental_id, positive equipment_id, a timezone-aware observed_at and a strict boolean available. Extra keys are forbidden. parse_status checks both identifiers against the prepared reference rather than accepting whichever record the provider returned.

Time describes the observation, not merely when this server received it. A naive timestamp lacks an agreed timezone. An observation older than five minutes or more than thirty seconds in the future is rejected under this teaching freshness policy. These numbers are explicit fixture assumptions, not a commercial provider SLA.

The gateway accumulates at most8192 accepted body bytes and rejects an oversized response. It validates the model before returning it. Unknown fields, string booleans, malformed identifiers, stale/future time and mismatched records all produce a safe502 unusable-observation error. Raw upstream content never becomes a public error message.

Per-attempt HTTP timeouts cover connection/pool/read work; asyncio.timeout wraps the whole logical lookup. That outer deadline includes admission and retry sleeps, preventing three individually bounded attempts from silently extending total latency. The fixture uses a sleeping transport to prove the logical operation ends within the declared budget.

PoolTimeout is local connection-pool pressure and does not count as provider failure. A read/connect timeout can be retried for this idempotent GET within its total budget. An unexpected protocol or malformed-success response is rejected. Keep these categories visible in tests and error codes, rather than calling every exception a provider outage.

Match both identifiers; Require typed available boolean; Require aware fresh observed_at; Reject oversized accepted body; Return validated observation
Match both identifiers; Require typed available boolean; Require aware fresh observed_at; Reject oversized accepted body; Return validated observation

Follow the running code

Focused lesson example; see the end-of-stage capstone for the cumulative app · stage 08

async with asyncio.timeout(budget):
    async with client.stream('GET', path) as response:
        body = bytearray()
        async for chunk in response.aiter_bytes():
            if len(body) + len(chunk) > 8192:
                raise ValueError('Unusable provider payload')
            body.extend(chunk)
# Validate identifiers, strict bool and aware timestamp before use.

Predict and observe this focused example using the concepts explained above. Its boundary is stated in the focused answer.

Guided lab

  1. Read the explanation and predict the focused example’s outcome.
  2. Reject wrong rental/item, naive/old/future timestamp, text boolean and more than8192 bytes. Distinguish local admission/pool pressure from a remote outage.
  3. Compare the observed outcome with the focused answer and state its boundary.

Expected: Every listed value fails the declared observation contract; a200 transport response alone is insufficient. Time must be aware and within the stated freshness/future allowance. The total budget includes admission and reading, not only each phase. Local capacity pressure is503 without counting the provider down. No retry or recovery algorithm is implemented by this focused exercise.

  • HTTP200 alone is not trusted data; a naive timestamp or string boolean violates the explicit contract.

Focused exercise and answer

Complete this focused exercise before reading its answer. The full native transfer is introduced only at the end of the stage.

Your transfer task: Reject wrong rental/item, naive/old/future timestamp, text boolean and more than8192 bytes. Distinguish local admission/pool pressure from a remote outage.

  1. Reject wrong rental/item, naive/old/future timestamp, text boolean and more than8192 bytes. Distinguish local admission/pool pressure from a remote outage.
Inspect the matching answer

This answer addresses the focused exercise above; the cumulative implementation is shown only after the stage prerequisites.

Every listed value fails the declared observation contract; a200 transport response alone is insufficient. Time must be aware and within the stated freshness/future allowance. The total budget includes admission and reading, not only each phase. Local capacity pressure is503 without counting the provider down. No retry or recovery algorithm is implemented by this focused exercise.

Check your reasoning

Why match the payload identifiers to Reference?

Show the explanation

A valid-shaped observation for a different rental/equipment is still the wrong answer to this authorized lookup.

Reading progress

54 lessons remain open to guests. Marking a lesson read records reading only; it does not award assessment credit or a certificate.

Device reading marks require browser storage. Reading is always available.

Sign in or create an account to save separate account progress. Your current page is kept.