fix(proxy): return Result from get_auth_headers to avoid panic on bad credentials

User-pasted API keys can contain control chars or CR/LF that make
HeaderValue::from_str return Err; the previous unwrap inside every
adapter turned such input into a process-wide panic instead of a request
error. The trait now returns Result<_, ProxyError>; Claude/Codex/Gemini
impls propagate ProxyError::AuthError so the client sees a 401 with the
underlying parse error instead of a crash. Adds a regression test that
pastes a CRLF-containing key and asserts AuthError.
This commit is contained in:
Jason
2026-05-13 23:12:00 +08:00
parent 58648a9c53
commit c9a6afc0b7
5 changed files with 65 additions and 43 deletions
+8 -1
View File
@@ -30,7 +30,14 @@ pub trait ProviderAdapter: Send + Sync {
///
/// The forwarder inserts these at the position of the original auth header
/// so that header order is preserved.
fn get_auth_headers(&self, auth: &AuthInfo) -> Vec<(http::HeaderName, http::HeaderValue)>;
///
/// Returns `ProxyError::AuthError` when the credential contains characters
/// that cannot be encoded as an HTTP header value (e.g. control chars,
/// CR/LF), which would otherwise panic inside `HeaderValue::from_str`.
fn get_auth_headers(
&self,
auth: &AuthInfo,
) -> Result<Vec<(http::HeaderName, http::HeaderValue)>, ProxyError>;
/// 是否需要格式转换
fn needs_transform(&self, _provider: &Provider) -> bool {