fix(proxy): return Result from get_auth_headers to avoid panic on bad credentials

User-pasted API keys can contain control chars or CR/LF that make
HeaderValue::from_str return Err; the previous unwrap inside every
adapter turned such input into a process-wide panic instead of a request
error. The trait now returns Result<_, ProxyError>; Claude/Codex/Gemini
impls propagate ProxyError::AuthError so the client sees a 401 with the
underlying parse error instead of a crash. Adds a regression test that
pastes a CRLF-containing key and asserts AuthError.
This commit is contained in:
Jason
2026-05-13 23:12:00 +08:00
parent 58648a9c53
commit c9a6afc0b7
5 changed files with 65 additions and 43 deletions
+9 -4
View File
@@ -173,12 +173,17 @@ impl ProviderAdapter for CodexAdapter {
url
}
fn get_auth_headers(&self, auth: &AuthInfo) -> Vec<(http::HeaderName, http::HeaderValue)> {
fn get_auth_headers(
&self,
auth: &AuthInfo,
) -> Result<Vec<(http::HeaderName, http::HeaderValue)>, ProxyError> {
let bearer = format!("Bearer {}", auth.api_key);
vec![(
let value = http::HeaderValue::from_str(&bearer)
.map_err(|e| ProxyError::AuthError(format!("invalid auth header value: {e}")))?;
Ok(vec![(
http::HeaderName::from_static("authorization"),
http::HeaderValue::from_str(&bearer).unwrap(),
)]
value,
)])
}
}