From 6b00c7ab258b4662c288029c47f6969a6f44a043 Mon Sep 17 00:00:00 2001 From: makiaveli1 Date: Mon, 21 Sep 2026 18:13:00 +0100 Subject: [PATCH] fix(client): validate bearer auth for async web search and fetch Client.web_search and Client.web_fetch raise a ValueError when no Bearer token is configured, but the AsyncClient methods skipped that check, so async callers without an API key sent a request that failed later with a 401 ResponseError instead of the documented ValueError. Add the same check, and the matching docstring line, to the async methods. --- ollama/_client.py | 8 ++++++++ tests/test_client.py | 18 ++++++++++++++++++ 2 files changed, 26 insertions(+) diff --git a/ollama/_client.py b/ollama/_client.py index 8dfce824..decfb660 100644 --- a/ollama/_client.py +++ b/ollama/_client.py @@ -801,7 +801,12 @@ async def web_search(self, query: str, max_results: int = 3) -> WebSearchRespons Returns: WebSearchResponse with the search results + Raises: + ValueError: If OLLAMA_API_KEY environment variable is not set """ + if not self._client.headers.get('authorization', '').startswith('Bearer '): + raise ValueError('Authorization header with Bearer token is required for web search') + return await self._request( WebSearchResponse, 'POST', @@ -822,6 +827,9 @@ async def web_fetch(self, url: str) -> WebFetchResponse: Returns: WebFetchResponse with the fetched result """ + if not self._client.headers.get('authorization', '').startswith('Bearer '): + raise ValueError('Authorization header with Bearer token is required for web fetch') + return await self._request( WebFetchResponse, 'POST', diff --git a/tests/test_client.py b/tests/test_client.py index 7b7ab38e..981b1aa9 100644 --- a/tests/test_client.py +++ b/tests/test_client.py @@ -1397,6 +1397,24 @@ def test_client_web_fetch_requires_bearer_auth_header(monkeypatch: pytest.Monkey client.web_fetch('https://example.com') +async def test_async_client_web_search_requires_bearer_auth_header(monkeypatch: pytest.MonkeyPatch): + monkeypatch.delenv('OLLAMA_API_KEY', raising=False) + + client = AsyncClient() + + with pytest.raises(ValueError, match='Authorization header with Bearer token is required for web search'): + await client.web_search('test query') + + +async def test_async_client_web_fetch_requires_bearer_auth_header(monkeypatch: pytest.MonkeyPatch): + monkeypatch.delenv('OLLAMA_API_KEY', raising=False) + + client = AsyncClient() + + with pytest.raises(ValueError, match='Authorization header with Bearer token is required for web fetch'): + await client.web_fetch('https://example.com') + + def _mock_request_web_search(self, cls, method, url, json=None, **kwargs): assert method == 'POST' assert url == 'https://ollama.com/api/web_search'