Repository navigation
fix(bedrock): forward anthropic-beta headers verbatim on the Claude platform messages path - #42275
Conversation
…latform messages path
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit e51ccbc. Configure here.
TLDR
Problem this solves:
mainCI is red: two tests say this route stripsanthropic-betavaluesHow it solves it:
User Flow
Before: a developer calling Claude Platform on AWS through the gateway with a beta feature gets a 200 today, but the tests describing this route say the gateway should strip that beta, and the CI fix that follows those tests (#42260) turns the same call into a 400
bedrock/claude_platform/claude-haiku-4-5-20251001with their AWS credentials andworkspace_idto the proxy configanthropic-beta: mcp-client-2025-11-20and anmcp_serversentry in the bodymainshows two failing tests about this route, both expecting the gateway to strip betas Bedrock does not knowmcp_servers: this parameter requires anthropic-beta: mcp-client-2026-09-15 (or mcp-client-2025-11-20), and acache_controlwithscope: globalreturns HTTP 400system.0.cache_control.ephemeral.scope: Extra inputs are not permittedAfter: the same call keeps working, CI is green, and a change that starts stripping betas on this route fails CI
bedrock/claude_platform/claude-haiku-4-5-20251001with their AWS credentials andworkspace_idto the proxy configanthropic-beta: mcp-client-2025-11-20and anmcp_serversentry in the bodyanthropic-betaheader reaching the gateway exactly as sentmainis green: the two tests now check the stripping against a route that really strips (Azure AI)Relevant issues
Supersedes #42260
Affected release
Linear ticket
Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
uv run pytest tests/test_litellm/<your_test_file>.py -v. Leave the suites (make test-unit-*,make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more@greptileaito re-request a review after pushing changes)Delays in PR merge?
If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).
Screenshots / Proof of Fix
Setup shared by every leg. One proxy process per side, each booted from its own worktree and venv with
--num_workers 2on its own port, the same config on all of them, real SigV4 calls toaws-external-anthropic.us-west-2.api.aws(the Claude Platform on AWS gateway), real spendThe four requests, run in this order on every side (
<port>is that side's port):Before (36b8be7)
The two contrast tests on main
uv run pytest tests/unit/llms/github_copilot/messages/test_github_copilot_messages_transformation.py::test_github_copilot_config_disables_anthropic_beta_filtering tests/unit/llms/openai_like/messages/test_openai_like_anthropic_messages_transformation.py::test_passthrough_disables_anthropic_beta_filteringcache_control scope=global with the prompt-caching-scope beta
mainalready passes the beta through, nothing guards it):mcp_servers with the mcp-client beta
Anthropic Python SDK, mcp_servers with the mcp-client beta
HTTP 200 ok input_tokens 828Control, no beta
After (e51ccbc)
The two contrast tests on main
uv run pytest tests/unit/llms/github_copilot/messages/test_github_copilot_messages_transformation.py::test_github_copilot_config_disables_anthropic_beta_filtering tests/unit/llms/openai_like/messages/test_openai_like_anthropic_messages_transformation.py::test_passthrough_disables_anthropic_beta_filtering tests/test_litellm/llms/bedrock/test_claude_platform_provider.py::test_anthropic_messages_bedrock_claude_platform_forwards_anthropic_beta_verbatim3 passed, 1 warning in 0.72s(the third is the new request-level regression test; it fails when this route's filter is switched on, which is what fix(bedrock): keep filtering anthropic-beta headers on the Claude platform messages path #42260 did)cache_control scope=global with the prompt-caching-scope beta
mcp_servers with the mcp-client beta
Anthropic Python SDK, mcp_servers with the mcp-client beta
HTTP 200 ok input_tokens 828Control, no beta
Contrast: the same four requests at #42260's head (cac3628)
This is what the new regression test guards against. Same config, same two-worker boot, same order
HTTP 400withsystem.0.cache_control.ephemeral.scope: Extra inputs are not permitted(theprompt-caching-scope-2026-01-05beta was stripped while the body keptscope)HTTP 400withmcp_servers: this parameter requires anthropic-beta: mcp-client-2026-09-15 (or mcp-client-2025-11-20)(themcp-client-2025-11-20beta was stripped)HTTP 400 Error code: 400 ... mcp_servers: this parameter requires anthropic-beta: mcp-client-2026-09-15 (or mcp-client-2025-11-20)HTTP 200Observations from the run:
/v1/chat/completionson this deployment 400s on both sides:workspace_idlands in the body (LIT-8279)main; this PR leaves it alonerun-ciadds nothing hereType
🐛 Bug Fix
✅ Test
Caveats (if any)
Low
mainalready passed these betas; the override makes it explicit instead of inherited, so the before leg's failure is the CI red, not a live 4xx/v1/chat/completionson the same deployment 400s onmainand here alike (LIT-8279)anthropic-betavalues, so "verbatim" is the set, not the order; pre-existing and left aloneAsyncHTTPHandler.postlike its five siblings in the file instead of injecting a client; rewriting the file's capture pattern is out of scope for a three-line fixLive PR risk
/v1/messagescase and a/v1/chat/completionsparity case with the same status and body shapeanthropic-betaheader was not read off the wire, since SigV4 signs the Host header and a forwarding recorder cannot sit in front of the gateway. The gateway's own beta-gated 400 vs 200 answers, plus the new test's capture of the outbound headers, stand in for itbedrock/claude_platform/model;mainmoved 17 commits since the merge base, none touching this surface/v1/chat/completionson this route filters betas (every request on it 400s onworkspace_idfirst, see caveats)Final Attestation
The tests check the right things, including the edge cases, and regressions in the respective real-world customer use-cases are not possible after this PR
e51ccbc passes /live-pr-risk