Skip to content

fix: scrub canonical Anthropic headers from 3P shim requests - #1

Closed
ibaaaaal wants to merge 1 commit into
auriti:fix/anthropic-fields-leak-3pfrom
ibaaaaal:pr-268-validate-canonical
Closed

ibaaaaal wants to merge 1 commit into
auriti:fix/anthropic-fields-leak-3pfrom
ibaaaaal:pr-268-validate-canonical

Conversation

@ibaaaaal

@ibaaaaal ibaaaaal commented Apr 7, 2026

Copy link
Copy Markdown

Summary

Follow-up to Twigpine#268 and the remaining header-leak blocker from Twigpine#267.

The current scrubber already removes x-anthropic-*, x-claude-*, and auth headers, but canonical Anthropic headers like anthropic-version and anthropic-beta can still reach third-party OpenAI-compatible requests.

This patch closes that gap.

What changed

  • extend the shim scrubber to also remove canonical anthropic-* headers
  • keep the filtering centralized in openaiShim.ts
  • cover the same supported paths called out in review:
    • direct shim defaultHeaders
    • env-driven ANTHROPIC_CUSTOM_HEADERS
    • providerOverride
    • per-request options.headers

Tests

  • bun test src/services/api/openaiShim.test.ts src/services/api/client.test.ts src/utils/context.test.ts
  • bun run test:provider
  • bun run build && node dist/cli.mjs --version

The remaining blocker from PR Twigpine#268 was that canonical Anthropic headers such as
`anthropic-version` and `anthropic-beta` could still ride through supported 3P
paths even after the earlier x-anthropic/x-claude scrubber work. This tightens
header filtering inside the shim itself so direct defaultHeaders, env-driven
client setup, providerOverride routing, and per-request header injection all
share the same scrubber.

Constraint: Preserve non-Anthropic custom headers and provider auth while stripping only Anthropic/OpenClaude-internal headers from 3P requests
Rejected: Rely on client.ts filtering alone | direct shim construction and per-request headers would still leave gaps
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: Keep header scrubbing centralized in the shim so new call paths do not reopen 3P leakage bugs
Tested: bun test src/services/api/openaiShim.test.ts src/services/api/client.test.ts src/utils/context.test.ts
Tested: bun run test:provider
Tested: bun run build && node dist/cli.mjs --version
Not-tested: bun run typecheck (repository baseline currently fails in many unrelated files)
@ibaaaaal

ibaaaaal commented Apr 7, 2026

Copy link
Copy Markdown
Author

Closing this because it was opened against the wrong repository path. The follow-up will be opened against Gitlawb/openclaude instead.

@ibaaaaal ibaaaaal closed this Apr 7, 2026
@ibaaaaal
ibaaaaal deleted the pr-268-validate-canonical branch April 7, 2026 22:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant