mirror of
https://github.com/github/spec-kit.git
synced 2026-08-03 06:26:30 +08:00
A bracketed-but-invalid IPv6 authority (e.g. "https://[not-an-ip]/c.json") parses cleanly under urlparse() on Python < 3.14 and only raises ValueError lazily on the first .hostname access. add_source read parsed.hostname outside the try/except ValueError guard, so on the interpreters spec-kit supports (>=3.11) that raw ValueError leaked past the CLI's `except BundlerError`, surfacing an uncaught traceback instead of the clean "Invalid catalog url" domain error. (The raise moved eager into urlparse() only in 3.14.) Read parsed.hostname inside the try and reuse the value for both the HTTPS/localhost check and the require-host check. This also protects the later _derive_id() call on the same URL. Regression tests: a bracketed-non-IP URL, plus a monkeypatched lazy-.hostname raiser that reproduces the pre-3.14 shape independently of the running interpreter (fails with a raw ValueError before the fix). Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>