Skip to content

FIX HTTP targets store decoded response text and JSON keys may contain digits or hyphens - #2814

Merged
hannahwestra25 merged 12 commits into
microsoft:mainfrom
u7k4rs6:fix/http-target-response-text
Sep 29, 2026
Merged

hannahwestra25 merged 12 commits into
microsoft:mainfrom
u7k4rs6:fix/http-target-response-text

Conversation

@u7k4rs6

@u7k4rs6 Utkarsh Bahuguna (u7k4rs6) commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #2813.

Both HTTP targets now store response.text (callback results are untouched), and the regex callback searches response.text and falls back to it. _fetch_key takes any run of characters other than ., [ and ] as a key segment, so output2, generated-text and v2_answer work. Index syntax is the same. The callback type hints now say httpx.Response, which is what the targets actually pass.

Tests: new cases for non-ASCII and multi-line bodies, keys with digits and hyphens, and both targets storing decoded text with no callback (all 9 fail on main). I updated test_parse_regex_response_no_match, which was asserting the b'...' output, and switched a few mocks to real httpx.Response objects since the code reads .text now. tests/unit/prompt_target: 1352 passed.

@hannahwestra25 hannahwestra25 self-assigned this Sep 24, 2026
Comment thread pyrit/prompt_target/http_target/http_target_callback_functions.py Outdated
Comment thread pyrit/prompt_target/http_target/http_target_callback_functions.py Outdated
Comment thread pyrit/prompt_target/http_target/http_target_callback_functions.py Outdated

@hannahwestra25 hannahwestra25 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks for contributing!

@hannahwestra25
hannahwestra25 added this pull request to the merge queue Sep 29, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 29, 2026
@u7k4rs6

Copy link
Copy Markdown
Contributor Author

The merge queue run failed on one Windows test, tests/unit/infra/test_code_deployment.py::TestCodeDeployment::test_cancellation_keeps_public_access_disabled_until_connection_removal, where the bash subprocess timed out after 30s. This PR doesn't touch infra, and that test passed on the PR's own checks, so it looks like a runner flake. Could you requeue it?

@hannahwestra25
hannahwestra25 added this pull request to the merge queue Sep 29, 2026
Merged via the queue into microsoft:main with commit 97cf5d7 Sep 29, 2026
49 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

BUG HTTPTarget stores responses as str(bytes) and the JSON callback can't address keys with digits or hyphens

3 participants