Conversation
Fill the PR number after GitHub assigned diegosouzapw#14053. Signed-off-by: Minxi Hou <houminxi@gmail.com>
|
CI on this branch matches the inherited set on pristine Unique tests: 50/50 locally ( Default stays off ( |
…aves (diegosouzapw#13065) PR diegosouzapw#14053 wired isClaudePassthrough into handleChatCore's three execute sites. This branch already moved send into executeProviderRequest.ts, so those sites would vanish on a later re-extract. Thread the marker from translateAndDedup through sendDeps into the leaf executes and the leftover credential-retry execute, and keep the proxy native fallback + dashboard toggle. Also drop client CLI-emulation headers (x-app / x-stainless-* / anthropic-dangerous-direct-browser-access) during the final header merge. Related to diegosouzapw#13893. diegosouzapw#13893 stays open. Signed-off-by: Minxi Hou <houminxi@gmail.com>
|
Thinned this PR to the plan on issue 13893. The hatch is now a small resolver next to Removed the standalone 177-line helper, the hop-by-hop / Connection header sanitizer, and the proxy-executor bypass. Those were extra surface. Fingerprint leftovers from On the two open questions: the flag hard-requires Unique tests 20/20 after the cut. Head |
|
Holding this behind the chatCore re-extract (#13065). Unique diff includes |
9346e0c to
75161fa
Compare
Fill the PR number after GitHub assigned diegosouzapw#14053. Signed-off-by: Minxi Hou <houminxi@gmail.com>
|
Rebased onto current The five locale files that conflicted kept the reviewed translations and the three raw-passthrough keys. Unit tests 20/20. |
75161fa to
b99c611
Compare
Fill the PR number after GitHub assigned diegosouzapw#14053. Signed-off-by: Minxi Hou <houminxi@gmail.com>
|
Rebased onto current |
Fill the PR number after GitHub assigned diegosouzapw#14053. Signed-off-by: Minxi Hou <houminxi@gmail.com>
a53c8c9 to
1a1bd58
Compare
Fill the PR number after GitHub assigned diegosouzapw#14053. Signed-off-by: Minxi Hou <houminxi@gmail.com>
bc07bdb to
13c74d5
Compare
Fill the PR number after GitHub assigned diegosouzapw#14053. Signed-off-by: Minxi Hou <houminxi@gmail.com>
13c74d5 to
3406f5b
Compare
|
Re-homed to |
Per-connection opt-in flag reader for the Claude OAuth raw passthrough escape hatch. Precedence: explicit top-level boolean wins (including false); nested legacy aliases passthrough.raw / passthrough.rawPassthrough are consulted only when no explicit top-level boolean is present; malformed input resolves to false. Object.hasOwn guards keep prototype-inherited values from arming the hatch. TDD: 7 cases (TC-04/04b/04c/04d, TC-07, TC-11/11b); injection-proven (explicit-false override and hasOwn guard both go red when removed). Forge LOCAL review: 3 consecutive clean rounds on the final diff. Signed-off-by: Minxi Hou <houminxi@gmail.com>
…iegosouzapw#13893) Server-side validation for the raw passthrough flag: boolean accepted, non-boolean (string/number/null) rejected, consistent with the sibling boolean keys that share the same guard shape. TC-15/TC-15b pin both arms; injection-proven (removing the validator block turns TC-15b red). The create-schema arm is covered transitively — sibling tests pin it against the same shared validator, and an apiKey line in the excerpt region gets credential-redacted by review tooling, breaking receipt fidelity. Forge LOCAL review: 3 consecutive clean rounds (threshold pinned to 3). Signed-off-by: Minxi Hou <houminxi@gmail.com>
…gosouzapw#13893) Add applyFinalClaudeRawPassthroughHeaders: strips CLI-emulation markers (x-app, anthropic-dangerous-direct-browser-access, x-stainless-*), RFC hop-by-hop fields (static set + client Connection nominations), and merges client business headers with case-variant dedupe. The gatewayAuthHeaders set (authorization/x-api-key/x-goog-api-key/api-key/cookie) is anchored so a client Connection header cannot strip gateway credentials (spec §3.3 rule 1, R5 hardening D-01). Tests: TC-06/06b/12/14/14b/14c, 13/13 green. Defect injection: removing the gatewayAuthHeaders guard turns TC-14b red; removing the case-variant dedupe loop turns TC-12 and TC-06b red; both restored green. Review: 5 local rounds on agnes-cn-3; all semantic findings dismissed or adjudicated false with file:line evidence; sole recurring CONFIRMED is a deterministic excerpt-fidelity defect of the review backend (filename mistyped as claRawPassthrough.ts). Oscillation waiver approved by operator; adjudication at .planning/reviews/task3-adjudication-20260917.md. Signed-off-by: Minxi Hou <houminxi@gmail.com>
… rawPassthrough (diegosouzapw#13893) - ExecuteInput gains isClaudePassthrough; four-condition AND gate (native format + claude provider + official OAuth token + per-connection rawPassthrough flag) computes isRawPassthrough in execute() - Rule 2: skip the cloak block (billing line, sentinel, tool remap, identity synthesis, CLI headers) when raw passthrough is active - Rule 3: shouldFingerprint gated on !isRawPassthrough - Rule 4: shouldSignBody unified across first send and all five retry branches, gated on !isRawPassthrough - Rule 1: applyFinalClaudeRawPassthroughHeaders runs after mergeUpstreamExtraHeaders in raw mode - Tests: TC-01/02/03/10 executor-level with stubbed upstream fetch; dual-arm injection proof (cloak guard removal reds TC-02+TC-10, sign guard removal reds TC-10); neighboring suites 170/170 green - Forge LOCAL review: PASS, converged, 3 consecutive clean rounds Signed-off-by: Minxi Hou <houminxi@gmail.com>
…pass proxy executors (diegosouzapw#13893) Raw passthrough must survive two extra hops after the executor gate: retry bodies still skip CCH signing, and proxy executors (CLIProxyAPI / Dario) must not swallow an OAuth connection that opted out of rewriting. Pass the flag into all three handleChatCore execute() call sites and short-circuit resolveExecutorWithProxy to the native claude executor when the connection flag is on. Tests: 23/23 (TC-05/08/09/13/15a/15b added). Adjacent suites 143/143. Signed-off-by: Minxi Hou <houminxi@gmail.com>
…ons (diegosouzapw#13893) Operators can opt a Claude OAuth connection out of CLI emulation from the edit-connection modal. The toggle reuses isConnectionRawPassthrough so the form matches executor semantics, and save strips nested passthrough.raw / passthrough.rawPassthrough aliases so a later import cannot re-arm the hatch. i18n: en + zh-CN copy from spec F-05; remaining locales filled from en. Tests: 27/27 (TC-11 save round-trip). Forge LOCAL PASS, 3 clean rounds. Signed-off-by: Minxi Hou <houminxi@gmail.com>
…osouzapw#13893) User-facing opt-in on Claude OAuth connections. PR number will be filled after GitHub assigns it. Signed-off-by: Minxi Hou <houminxi@gmail.com>
Fill the PR number after GitHub assigned diegosouzapw#14053. Signed-off-by: Minxi Hou <houminxi@gmail.com>
Issue 13893 asked for a small resolver next to resolveConnectionCacheOverride, a four-condition gate at the cloak block, and the existing dashboard toggle. The standalone header sanitizer, Connection hop-by-hop merge, and proxy-executor bypass were extra surface. Nested passthrough.raw aliases no longer arm the hatch. Signed-off-by: Minxi Hou <houminxi@gmail.com>
…raw passthrough In raw passthrough mode, omitting client headers left outbound requests with only Authorization and Accept, dropping anthropic-version, anthropic-beta, user-agent, and custom business headers. Anthropic rejects requests lacking anthropic-version with 400 Bad Request. Restore applyFinalClaudeRawPassthroughHeaders in cacheControlPolicy: - Strips CLI-emulation markers (x-app, anthropic-dangerous-direct-browser-access, x-stainless-*) - Strips RFC 9110 hop-by-hop headers (static list + client Connection nominations) - Anchors gateway auth headers so client Connection nominations cannot strip them - Merges client business headers with case-variant deduplication - Ensures anthropic-version defaults to 2023-06-01 if omitted Signed-off-by: Minxi Hou <houminxi@gmail.com>
…string header filtering Add TC-14d to verify client-supplied anthropic-version is preserved rather than overwritten by the default 2023-06-01 value, and TC-14e to assert non-string values in clientHeaders are ignored during merge. Signed-off-by: Minxi Hou <houminxi@gmail.com>
3406f5b to
1398a21
Compare
Summary
Claude OAuth traffic that is not Claude Code currently still gets the CLI
cloak, fingerprint rewrite, and CCH body signing. Anthropic then 400s
sk-ant-oattokens on extra-usage / cache-control for those clients(#13893).
This adds a per-connection opt-in,
providerSpecificData.rawPassthrough(boolean, default false, no migration). When on, a Claude OAuth connection:
signRequestBodynominates them
The dashboard toggle is limited to Claude OAuth. Save writes the top-level
boolean and drops nested
passthrough.raw/passthrough.rawPassthroughaliases so an import cannot re-arm the hatch after the operator turns it off.
API-key Claude connections keep the existing cloak even if the flag is set.
Related to #13893. #13893 stays open.
Test plan
node --import tsx/esm --test tests/unit/claude-oauth-raw-passthrough.test.ts(27/27)npm run typecheck:core65locales)non-CLI Chat Completions request, confirm Anthropic 200 and that
x-anthropic-billing/cch=are absent on the wire