Skip to content

fix: reject authorization in every quirk header field - #25

Merged
TheGreatAxios merged 1 commit into
mainfrom
cl-9433-openai-responses-reject-authorization-in-every-quirk-header
Sep 27, 2026
Merged

TheGreatAxios merged 1 commit into
mainfrom
cl-9433-openai-responses-reject-authorization-in-every-quirk-header

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Contributor

Closes CL-9433

Follow-up to CL-9425, which only covered headers.static.

  • headers.modelHeader, headers.fromOption[].header and sessionIdHeader are now lowercased when quirks are parsed, the same as headers.static.
  • Setting any of the four to authorization, in any case, throws invalid quirks: <field> must not set authorization. Before, fromOption or sessionIdHeader let a caller's providerOptions replace the credential sentinel.

Unit tests cover each field in lowercase and capitalised form, plus lowercasing of the three dynamic header names.

@TheGreatAxios
TheGreatAxios merged commit 97e3127 into main Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant