From e1d4211e9022c3a4e41ad805e259dc7a9ad3820a Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Thu, 3 Sep 2026 09:52:47 -0700 Subject: [PATCH] =?UTF-8?q?review-fix(suppress-audit):=20gateway/run=5Ftur?= =?UTF-8?q?n.py=20=E2=80=94=20restore=20BASE=20exception=20semantics=20(pr?= =?UTF-8?q?oxy=20key=20UnscopedSecretError-only=20fallback)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- gateway/run_turn.py | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/gateway/run_turn.py b/gateway/run_turn.py index eb65754aa0..69deeb40bd 100644 --- a/gateway/run_turn.py +++ b/gateway/run_turn.py @@ -2434,10 +2434,17 @@ class GatewayTurnMixin: return self._proxy_error_result("⚠️ Proxy URL not configured (GATEWAY_PROXY_URL or gateway.proxy_url)") # The proxy key is a per-profile credential: honor the installed secret scope under multiplex. - proxy_key = os.getenv("GATEWAY_PROXY_KEY", "").strip() - with suppress(Exception): # UnscopedSecretError and import failures fall back to the env - from agent.secret_scope import get_secret - proxy_key = (get_secret("GATEWAY_PROXY_KEY") or "").strip() + # Only UnscopedSecretError / import failures fall back to the env; any other get_secret() + # error propagates (same as BASE) rather than silently degrading to the ambient key. + try: + from agent.secret_scope import UnscopedSecretError, get_secret + + try: + proxy_key = (get_secret("GATEWAY_PROXY_KEY") or "").strip() + except UnscopedSecretError: + proxy_key = os.getenv("GATEWAY_PROXY_KEY", "").strip() + except Exception: + proxy_key = os.getenv("GATEWAY_PROXY_KEY", "").strip() _run_still_current = self._run_still_current_fn(session_key, run_generation)