Repository navigation
fix: async APIHub 페이지네이션 절단 경고·검증 누락 (2인 적대적 리뷰 재검증) - #28
Merged
Merged
Conversation
…dation Two independent adversarial-review subagents (concurrency/resource- management angle, security/data-integrity angle) re-verified the existing asyncio conversion of src/kma and both converged on the same bug: ApiHubClient.aiter_pages() (also exposed as AsyncApiHubClient.iter_pages()) hand-rolled its own pagination loop instead of delegating to the shared pagination.aiter_pages() helper, unlike DataGoKrClient.aiter_pages() which already follows that pattern. As a result it silently dropped PaginationLimitWarning when max_pages was hit with more data upstream, and skipped start_page/max_pages/max_items validation, causing silent truncation for async APIHub consumers with zero test coverage. Rewired aiter_pages to delegate to pagination.aiter_pages the same way the sync/datagokr paths do, dropped the now-dead local _body_item_count helper and unused _has_next_page import, and added sync/async pagination test coverage (PagingFakeSession / AsyncPagingFakeSession) that fails against the pre-fix code. The security/data-integrity review pass found no real bugs elsewhere — credential masking, result-code mapping, and retry/backoff are shared functions used identically by sync and async paths. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01VMed8e6u2BBD5CuokBQRhv
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
배경
src/kma의 asyncio 전환은 이전 PR #25에서 이미 완료·머지되었다. 이번 작업은 그 전환이실제로 안전한지 독립된 서브에이전트 2명(동시성/자원관리 관점, 보안/데이터 무결성 관점)으로
다시 적대적 리뷰를 받아 재검증한 결과다.
발견 및 수정
두 리뷰어가 독립적으로 동일한 버그에 수렴했다:
ApiHubClient.aiter_pages()(
AsyncApiHubClient.iter_pages()로도 노출)가 공용pagination.aiter_pages()헬퍼에위임하지 않고
for offset in range(max_pages)루프를 직접 구현하고 있었다.DataGoKrClient.aiter_pages()는 이미 공용 헬퍼에 위임하는데(동기/비동기 대칭 원칙,AGENTS.md) APIHub 쪽만 예외였다.
결과적으로:
max_pages에 도달했는데 더 가져올 페이지가 남아있어도, 동기iter_pages()와 달리PaginationLimitWarning을 내지 않고 조용히 데이터를 잘랐다.start_page/max_pages/max_items입력값 검증이 아예 없었다 (max_pages=0이 에러 없이빈 결과를 반환).
tests/*.py에aiter_pages테스트가 전무해 CI로는 잡히지 않았다.변경 사항
src/kma/apihub.py:aiter_pages()를pagination.aiter_pages()에 위임하도록 재작성(
datagokr.py와 동일 패턴). 더 이상 쓰이지 않는_body_item_count()/_has_next_pageimport 제거.tests/test_apihub.py:PagingFakeSession/AsyncPagingFakeSessionfixture + 4개 테스트추가 (동기/비동기 페이지 수집 대칭성, 경고 발생 대칭성, 인자 검증 대칭성). 수정 전 코드로
되돌려 새 테스트 2개가 실제로 실패함을 확인했다 (회귀 방지 검증됨).
CHANGELOG.md/docs/journal.md/docs/resume.md갱신.보안/데이터 무결성 관점 리뷰에서는 실제 버그 없음 — 자격증명 마스킹,
resultCode예외 매핑,재시도/백오프 로직이 동기/비동기 경로에서 동일한 공용 함수를 공유함을 확인했다. (informational로
보고된 completeness gap —
DataGoKrClient의 타입화 helper 다수가 async facade에 대응 메서드가없음 — 은 버그/취약점이 아니라 이번 PR 범위에서 다루지 않았다.)
검증
Live e2e (실 API):
🤖 Generated with Claude Code
https://claude.ai/code/session_01VMed8e6u2BBD5CuokBQRhv