# HTTP Flow Review

A contained, independent sample matching a three-step API debugging brief.
It prepares actual `requests` requests entirely offline, reproduces a third-step
session-context / content-type mismatch and generates a field-level comparison.
It does not contact a buyer's service or solve a buyer's real problem.

## Run

Python 3.11+ and `requests` are required.

```sh
python -m unittest -v
python flow_review.py
```

The report contains header names, cookie names, payload field names/types and
request paths. Credential values and payload values are excluded. Paths and field
names can themselves be sensitive: sanitize them before sharing any real traces.
This is a purpose-built demonstration, not a general HAR sanitizer.

The synthetic case has create, confirm and assessment steps. Its third step
intentionally uses a fresh preparation context and form data. The corrected
fixture retains the session and JSON body. A clean metadata comparison establishes
request parity only; it cannot prove a real API succeeds. A paid diagnosis needs
the actual script, an authorized working reference, redacted logs, a reproduction,
and agreed acceptance checks.

Official guidance reviewed:
- https://requests.readthedocs.io/en/stable/user/advanced/#prepared-requests
- https://requests.readthedocs.io/en/stable/user/advanced/#session-objects

Built for a portfolio in October 2026. No prior client experience is claimed.
