Sample
Preserve Session state and environment CA verification settings when manually preparing and sending Requests 2.34.2 calls
sha256:98f0ab60b35b9e2f6b5004f999315e13dca1143e3072aa3eb69f870e8c878f99
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- python 3.12
- Operating system
- linux
- Architecture
- x64
- Runtime
- python 3.12
- Language
- python 3.12
- Package manager
- pip
Verification-run environments
- Execution context
- python 3.12
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- python 3.12
- Language
- python
- Package manager
- pip
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17
Case
- Goal
- Preserve Session state and environment CA verification settings when manually preparing and sending Requests 2.34.2 calls HOW
- Packages
-
requests 2.34.2
- Environment
- python 3.12
- Created
- 2026-08-17T03:54:11Z
Commonly assumed
Preparing a Request directly and sending it through a Session automatically applies that Session's headers, cookies, and REQUESTS_CA_BUNDLE setting.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- assert Request.prepare omits Session default headers and cookies while Session.prepare_request applies both
- assert a per-request header value of None removes that inherited header without mutating the Session default
- assert Session.send of a prepared request uses Session.verify and does not consult REQUESTS_CA_BUNDLE by itself
- assert Session.get and an explicit merge_environment_settings plus Session.send both pass REQUESTS_CA_BUNDLE to the recording adapter as verify
- assert explicit verify false overrides the environment CA bundle and trust_env false ignores it
- assert the recording adapter completes every request path without DNS, TLS, a listening socket, or an external service
Files
- NOTES.md
- csx.json
- requirements.in
- requirements.lock
- requirements.txt
- test/contract.py
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- python 3.12 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17 · ed25519:d91480838ac982c9