Files
OpenMAIC/lib
d3e882241c fix(web-search): stop leaking Brave's HTML challenge page into errors (#1553)
* fix(web-search): stop leaking Brave's HTML challenge page into errors

Both Brave error paths echoed the upstream response body verbatim, so a
throttled or blocked request surfaced a full HTML page as Error.message
and a transient 429 was indistinguishable from a real outage.

Route both paths through formatBraveError, which gives 429 a dedicated
actionable message, drops markup and over-long bodies in favour of the
HTTP status text, and keeps short plain-text details.

Closes #1552

* fix(web-search): cancel Brave's HTML error body instead of reading it

Deciding whether an error body is worth surfacing still meant pulling the
whole challenge page into memory first. Check the content type up front and
cancel the stream when it is markup, so the large body is never read.

* fix(web-search): give Brave API-key 429 plan-specific guidance

The API-key path already sends a subscription token, so its 429 message
should not suggest configuring a Brave API key. Point it at the plan's
rate limit instead, keep the API-key suggestion for the keyless scrape
path, and add a test for the API-key 429.

---------

Co-authored-by: zhentang2 <zhentang2@iflytek.com>
Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>
2026-09-23 12:17:15 +08:00
..