Skip to content

fix(claude): scope CLAUDE_CC_ENTRYPOINT to OAuth call sites only - #9

Open
TechNickAI wants to merge 2 commits into
mainfrom
fix/claude-oauth-ua-scope
Open

TechNickAI wants to merge 2 commits into
mainfrom
fix/claude-oauth-ua-scope

Conversation

@TechNickAI

@TechNickAI TechNickAI commented Aug 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

Follow-up to PR #7 addressing two defects identified by bot review (comments 3707863231, 3707900072):

  • Static registry UA leaked OAuth billing identity: CLAUDE_CLI_USER_AGENT was computed via claudeCliUserAgent() at module load, snapshotting CLAUDE_CC_ENTRYPOINT into a constant used by getClaudeCliHeaders() for all API-key connections. With CLAUDE_CC_ENTRYPOINT=sdk-cli, non-OAuth credential surfaces would send claude-cli/X.Y.Z (external, sdk-cli) — incorrect since the env var is documented as OAuth-only. Fix: hardcode the static constant to always use "cli"; dynamic entrypoint stays in OAuth call sites only.

  • Preserve explicit OAuth User-Agent overrides: The native Claude OAuth path uses claudeCliUserAgent(CLAUDE_CODE_VERSION) as its default. mergeUpstreamExtraHeaders remains the documented last-writer-wins operator override, so custom User-Agent settings are preserved instead of being silently replaced.

Changes

  • open-sse/config/anthropicHeaders.ts: CLAUDE_CLI_USER_AGENT hardcoded to cli (was claudeCliUserAgent(CLAUDE_CLI_VERSION))
  • open-sse/executors/base.ts: preserve explicit User-Agent overrides after the native Claude OAuth default is set
  • tests/unit/claude-entrypoint.test.ts: Two regression guards added

Test plan

  • node --import tsx/esm --test tests/unit/claude-entrypoint.test.ts — 7/7 tests pass
  • Pre-commit hooks clean (lint, any-budget, docs-sync, tracked-artifacts)
  • Verify CLAUDE_CLI_USER_AGENT is stable when CLAUDE_CC_ENTRYPOINT=sdk-cli
  • Verify OAuth requests with custom User-Agent in extra headers preserve the explicit operator override

Two defects introduced when CLAUDE_CLI_USER_AGENT was made dynamic in #7:

1. CLAUDE_CLI_USER_AGENT was computed via claudeCliUserAgent() at module load,
   snapshotting CLAUDE_CC_ENTRYPOINT into the static registry constant used by
   getClaudeCliHeaders(). API-key connections (not OAuth) would then carry the
   sdk-cli User-Agent even though CLAUDE_CC_ENTRYPOINT is documented as OAuth-only.
   Fix: hardcode the static constant to always use "cli"; dynamic entrypoint stays
   in the OAuth call sites only.

2. mergeUpstreamExtraHeaders runs after the OAuth ccHeaders block sets User-Agent via
   claudeCliUserAgent(). Operator-configured upstream extra headers can include a
   custom User-Agent that overrides it, desynchronising cc_entrypoint from the actual
   wire value. Fix: reassert claudeCliUserAgent(CLAUDE_CODE_VERSION) after the merge
   for native Claude OAuth requests (provider=claude + hasClaudeOAuthToken).

Tests: two new regression guards in claude-entrypoint.test.ts — one asserting
CLAUDE_CLI_USER_AGENT is always "cli" regardless of env, one documenting the
mergeUpstreamExtraHeaders override mechanism and the reassertion fix.
@TechNickAI TechNickAI added the review-sweep Follow-up from automated PR review sweep label Aug 4, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aa25dca27c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread open-sse/executors/base.ts Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review-sweep Follow-up from automated PR review sweep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant