@@ -108,6 +108,17 @@ def test_managed_identity_refuses_non_azure_endpoint(self):
108108 be ._get_client ()
109109 self .assertIn ("openai_compatible" , str (ctx .exception ))
110110
111+ def test_managed_identity_refuses_insecure_azure_endpoint (self ):
112+ # A matching Azure hostname is insufficient: AAD bearer credentials
113+ # must never be sent over plaintext HTTP.
114+ env = {"AZURE_OPENAI_ENDPOINT" : "http://foo.openai.azure.com" }
115+ with mock .patch .dict (os .environ , env , clear = True ):
116+ be = AzureOpenAIBackend (deployment = "some-model" )
117+ self .assertFalse (be ._is_azure_host ())
118+ with self .assertRaises (ValueError ) as ctx :
119+ be ._get_client ()
120+ self .assertIn ("openai_compatible" , str (ctx .exception ))
121+
111122 def test_azure_host_detection (self ):
112123 with mock .patch .dict (os .environ , {}, clear = True ):
113124 be = AzureOpenAIBackend (deployment = "gpt-5.5" ) # table endpoint
@@ -189,6 +200,15 @@ def test_azure_mode_sends_max_completion_tokens(self):
189200 self .assertEqual (call ["max_completion_tokens" ], 16384 )
190201 self .assertNotIn ("max_tokens" , call )
191202
203+ def test_azure_mode_ignores_compat_extra_body (self ):
204+ body = {"thinking" : {"type" : "enabled" }}
205+ env = {"SKILLOPT_SLEEP_CHAT_EXTRA_BODY" : json .dumps (body )}
206+ be = _backend_with (["hi" ], env )
207+ with mock .patch .dict (os .environ , env , clear = True ):
208+ be ._call ("p" , retries = 1 )
209+ (call ,) = be ._client .chat .completions .calls
210+ self .assertNotIn ("extra_body" , call )
211+
192212
193213class TestErrorState (unittest .TestCase ):
194214 def test_recovered_retry_clears_last_call_error (self ):
0 commit comments