Merge pull request #875 from dalamudx/feat/claude-code-dynamic-client-profile

feat(claude-code): 统一各提供商的画像管理
This commit is contained in:
ZheFox
2026-10-06 22:15:03 +08:00
committed by GitHub
42 changed files with 1943 additions and 1263 deletions
@@ -0,0 +1,67 @@
//! Immutable client identity snapshots shared by provider adapters.
use std::sync::{Arc, RwLock};
/// Readers release the lock before constructing a request. Publishing never
/// changes snapshots already held by an in-flight request.
#[derive(Debug)]
pub struct ClientProfileStore<T> {
current: RwLock<Arc<T>>,
}
impl<T> ClientProfileStore<T> {
pub fn new(profile: T) -> Self {
Self {
current: RwLock::new(Arc::new(profile)),
}
}
pub fn snapshot(&self) -> Arc<T> {
self.current
.read()
.unwrap_or_else(std::sync::PoisonError::into_inner)
.clone()
}
pub fn publish(&self, profile: T) -> Arc<T> {
let mut current = self
.current
.write()
.unwrap_or_else(std::sync::PoisonError::into_inner);
std::mem::replace(&mut *current, Arc::new(profile))
}
}
/// Constructors validate wire safety; release adapters separately validate
/// official stable semantic versions before publishing them.
pub fn validate_client_version(version: &str) -> Result<&str, &'static str> {
let version = version.trim();
if version.is_empty() || version.len() > 64 || !version.bytes().all(|b| (33..=126).contains(&b))
{
return Err("invalid client version");
}
Ok(version)
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn publishing_does_not_mutate_inflight_snapshots() {
let store = ClientProfileStore::new(("1.0.0", "client/1.0.0"));
let inflight = store.snapshot();
let old = store.publish(("1.1.0", "client/1.1.0"));
assert_eq!(inflight, old);
assert_eq!(inflight.0, "1.0.0");
assert_eq!(store.snapshot().1, "client/1.1.0");
}
#[test]
fn rejects_header_injection_and_oversized_versions() {
for version in ["", "1.0\r\nx: y", "1.0 0", "é"] {
assert!(validate_client_version(version).is_err());
}
assert!(validate_client_version(&"1".repeat(65)).is_err());
assert_eq!(validate_client_version(" 1.0.0 ").unwrap(), "1.0.0");
}
}
+8 -12
View File
@@ -1,4 +1,6 @@
use std::sync::{LazyLock, OnceLock, RwLock};
use std::sync::{LazyLock, OnceLock};
use crate::client_profile::ClientProfileStore;
static OS_INFO: LazyLock<os_info::Info> = LazyLock::new(os_info::get);
@@ -59,26 +61,20 @@ impl Default for CodexClientProfile {
}
}
static ACTIVE_PROFILE: OnceLock<RwLock<CodexClientProfile>> = OnceLock::new();
static ACTIVE_PROFILE: OnceLock<ClientProfileStore<CodexClientProfile>> = OnceLock::new();
fn active_profile() -> &'static RwLock<CodexClientProfile> {
ACTIVE_PROFILE.get_or_init(|| RwLock::new(CodexClientProfile::default()))
fn active_profile() -> &'static ClientProfileStore<CodexClientProfile> {
ACTIVE_PROFILE.get_or_init(|| ClientProfileStore::new(CodexClientProfile::default()))
}
/// 返回当前画像的独立快照,调用方不会持有全局锁。
pub fn codex_client_profile() -> CodexClientProfile {
active_profile()
.read()
.unwrap_or_else(std::sync::PoisonError::into_inner)
.clone()
(*active_profile().snapshot()).clone()
}
/// 原子替换当前画像,并返回替换前的画像。
pub fn set_codex_client_profile(profile: CodexClientProfile) -> CodexClientProfile {
let mut current = active_profile()
.write()
.unwrap_or_else(std::sync::PoisonError::into_inner);
std::mem::replace(&mut *current, profile)
(*active_profile().publish(profile)).clone()
}
/// 发布一份新的 CLI 画像。
+1
View File
@@ -1,6 +1,7 @@
extern crate self as aether_ai_formats;
pub mod api;
pub mod client_profile;
pub mod codex_profile;
pub mod contracts;
pub mod formats;
+22 -7
View File
@@ -27,8 +27,6 @@ use crate::{
build_models_fetch_url_for_client_version, deepseek_anthropic_models_fetch_uses_openai_auth,
};
const CLAUDE_CLI_USER_AGENT: &str = "claude-code/1.0.1";
const GEMINI_CLI_USER_AGENT: &str = "GeminiCLI/0.1.5 (Windows; AMD64)";
const CLAUDE_VERSION_HEADER: &str = "2023-06-01";
const ANTIGRAVITY_FETCH_PROVIDER_API_FORMAT: &str = "antigravity:fetch_available_models";
const ANTIGRAVITY_LOAD_CODE_ASSIST_PROVIDER_API_FORMAT: &str = "antigravity:load_code_assist";
@@ -37,7 +35,7 @@ const KIRO_LIST_AVAILABLE_MODELS_PROVIDER_API_FORMAT: &str = "kiro:list_availabl
const WINDSURF_MODEL_CONFIGS_PROVIDER_API_FORMAT: &str = "windsurf:model_configs";
const WINDSURF_MODEL_CONFIGS_PATH: &str =
"/exa.api_server_pb.ApiServerService/GetCascadeModelConfigs";
const WINDSURF_IDE_VERSION: &str = "1.9600.41";
const WINDSURF_IDE_VERSION: &str = aether_provider_transport::client_identity::WINDSURF.version;
const BROWSER_FINGERPRINT_HEADERS: &[(&str, &str)] = &[
(
@@ -319,7 +317,10 @@ pub async fn build_gemini_cli_load_code_assist_plan(
.ok_or_else(|| "GeminiCLI loadCodeAssist requires bearer or OAuth auth".to_string())?;
let mut headers = BTreeMap::from([
("user-agent".to_string(), GEMINI_CLI_USER_AGENT.to_string()),
(
"user-agent".to_string(),
aether_provider_transport::gemini_cli::gemini_cli_client_user_agent(),
),
("accept-encoding".to_string(), "identity".to_string()),
("content-type".to_string(), "application/json".to_string()),
]);
@@ -662,8 +663,19 @@ fn standard_models_fetch_headers(
"anthropic-version".to_string(),
CLAUDE_VERSION_HEADER.to_string(),
)]);
if matches!(provider_type.as_str(), "claude_code" | "kiro") {
headers.insert("user-agent".to_string(), CLAUDE_CLI_USER_AGENT.to_string());
if provider_type == "claude_code" {
headers.insert(
"user-agent".to_string(),
aether_provider_transport::claude_code::claude_code_client_profile()
.user_agent
.clone(),
);
} else if provider_type == "kiro" {
headers.insert(
"user-agent".to_string(),
aether_provider_transport::client_identity::KIRO_MODELS_LEGACY_USER_AGENT
.to_string(),
);
}
headers
}
@@ -673,7 +685,10 @@ fn standard_models_fetch_headers(
.map(|(key, value)| (key.to_string(), value.to_string()))
.collect::<BTreeMap<_, _>>();
if provider_type == "gemini_cli" {
headers.insert("user-agent".to_string(), GEMINI_CLI_USER_AGENT.to_string());
headers.insert(
"user-agent".to_string(),
aether_provider_transport::gemini_cli::gemini_cli_client_user_agent(),
);
}
headers
}
@@ -20,11 +20,10 @@ use crate::quota_refresh::ProviderPoolQuotaRequestSpec;
pub const CHATGPT_WEB_DEFAULT_BASE_URL: &str = "https://chatgpt.com";
pub const CHATGPT_WEB_CONVERSATION_INIT_PATH: &str = "/backend-api/conversation/init";
const CHATGPT_WEB_USER_AGENT: &str = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36 Edg/143.0.0.0";
const CHATGPT_WEB_CLIENT_VERSION: &str = "prod-be885abbfcfe7b1f511e88b3003d9ee44757fbad";
const CHATGPT_WEB_BUILD_NUMBER: &str = "5955942";
const CHATGPT_WEB_SEC_CH_UA: &str =
r#""Microsoft Edge";v="143", "Chromium";v="143", "Not A(Brand";v="24""#;
use aether_provider_transport::client_identity::{
CHATGPT_WEB_BUILD_NUMBER, CHATGPT_WEB_CLIENT_VERSION, CHATGPT_WEB_SEC_CH_UA,
CHATGPT_WEB_USER_AGENT,
};
#[derive(Debug, Clone, Default)]
pub struct ChatGptWebProviderPoolAdapter;
@@ -11,7 +11,6 @@ use crate::quota_refresh::ProviderPoolQuotaRequestSpec;
pub const CLAUDE_CODE_OAUTH_USAGE_URL: &str =
"https://api.anthropic.com/api/oauth/usage?cedar_ember=1&skip_spend=1";
pub const CLAUDE_CODE_OAUTH_BETA: &str = "oauth-2025-04-20";
pub const CLAUDE_CODE_USAGE_USER_AGENT: &str = "claude-cli/2.1.284 (external, cli)";
#[derive(Debug, Clone, Default)]
pub struct ClaudeCodeProviderPoolAdapter;
@@ -62,7 +61,7 @@ pub fn build_claude_code_pool_quota_request(
("x-app".to_string(), "cli".to_string()),
(
"user-agent".to_string(),
CLAUDE_CODE_USAGE_USER_AGENT.to_string(),
aether_provider_transport::claude_code::claude_code_client_user_agent(),
),
]);
@@ -10,7 +10,7 @@ use crate::provider::{
use crate::quota_refresh::ProviderPoolQuotaRequestSpec;
pub const GEMINI_CLI_RETRIEVE_USER_QUOTA_PATH: &str = "/v1internal:retrieveUserQuota";
pub const GEMINI_CLI_USER_AGENT: &str = "GeminiCLI/0.1.5 (Windows; AMD64)";
pub use aether_provider_transport::gemini_cli::GEMINI_CLI_USER_AGENT;
#[derive(Debug, Clone, Default)]
pub struct GeminiCliProviderPoolAdapter;
@@ -52,7 +52,10 @@ pub fn build_gemini_cli_pool_quota_request(
("authorization".to_string(), authorization.1),
("content-type".to_string(), "application/json".to_string()),
("accept".to_string(), "application/json".to_string()),
("user-agent".to_string(), GEMINI_CLI_USER_AGENT.to_string()),
(
"user-agent".to_string(),
aether_provider_transport::gemini_cli::gemini_cli_client_user_agent(),
),
]);
ProviderPoolQuotaRequestSpec {
@@ -158,7 +158,7 @@ fn normalize_region(value: &str) -> &str {
fn normalize_kiro_version(value: &str) -> &str {
let value = value.trim();
if value.is_empty() {
"0.3.210"
aether_provider_transport::client_identity::DEFAULT_KIRO_VERSION
} else {
value
}
@@ -24,7 +24,6 @@ pub use chatgpt_web::{
pub use claude_code::ClaudeCodeProviderPoolAdapter;
pub use claude_code::{
build_claude_code_pool_quota_request, CLAUDE_CODE_OAUTH_BETA, CLAUDE_CODE_OAUTH_USAGE_URL,
CLAUDE_CODE_USAGE_USER_AGENT,
};
pub use codex::CodexProviderPoolAdapter;
pub use codex::{
@@ -177,7 +177,12 @@ fn build_windsurf_connect_rpc_request(
headers.insert("content-type".to_string(), "application/json".to_string());
headers.insert("accept".to_string(), "application/json".to_string());
headers.insert("connect-protocol-version".to_string(), "1".to_string());
headers.insert("user-agent".to_string(), "windsurf/1.9600.41".to_string());
headers.insert(
"user-agent".to_string(),
aether_provider_transport::client_identity::WINDSURF
.user_agent
.to_string(),
);
ProviderPoolQuotaRequestSpec {
request_id,
@@ -200,9 +205,9 @@ fn windsurf_metadata(api_key: &str) -> Value {
json!({
"apiKey": api_key,
"ideName": "windsurf",
"ideVersion": "1.9600.41",
"ideVersion": aether_provider_transport::client_identity::WINDSURF.version,
"extensionName": "windsurf",
"extensionVersion": "1.9600.41",
"extensionVersion": aether_provider_transport::client_identity::WINDSURF.version,
"locale": "en",
})
}
@@ -769,6 +769,7 @@ async fn register_codex_agent_identity_from_access_token_with_auth_api_base_url(
.map_err(|_| CodexAgentIdentityEnrollmentError::KeyGenerationFailed)?;
let agent_private_key = STANDARD.encode(private_key_der.as_bytes());
let agent_public_key = agent_identity_ssh_public_key(&signing_key);
let client_profile = aether_ai_formats::codex_client_profile();
let registration_url = agent_registration_url(auth_api_base_url)
.map_err(|_| CodexAgentIdentityEnrollmentError::RegistrationRequestFailed)?;
let mut headers = BTreeMap::from([
@@ -778,14 +779,8 @@ async fn register_codex_agent_identity_from_access_token_with_auth_api_base_url(
"authorization".to_string(),
format!("Bearer {access_token}"),
),
(
"user-agent".to_string(),
aether_ai_formats::codex_client_user_agent(),
),
(
"originator".to_string(),
aether_ai_formats::codex_client_originator(),
),
("user-agent".to_string(), client_profile.user_agent.clone()),
("originator".to_string(), client_profile.originator.clone()),
]);
if options.is_fedramp_account {
headers.insert("x-openai-fedramp".to_string(), "true".to_string());
@@ -799,7 +794,7 @@ async fn register_codex_agent_identity_from_access_token_with_auth_api_base_url(
content_type: Some("application/json".to_string()),
json_body: Some(json!({
"abom": {
"agent_version": aether_ai_formats::codex_client_version(),
"agent_version": client_profile.codex_version,
"agent_harness_id": CODEX_AGENT_IDENTITY_AGENT_HARNESS_ID,
"running_location": format!("cli-{}", std::env::consts::OS),
},
@@ -5,8 +5,8 @@ use serde_json::Value;
use super::super::snapshot::GatewayProviderTransportSnapshot;
pub const ANTIGRAVITY_PROVIDER_TYPE: &str = "antigravity";
pub const ANTIGRAVITY_CLIENT_VERSION: &str = "4.3.0";
pub const ANTIGRAVITY_REQUEST_USER_AGENT: &str = "vscode/1.X.X (Antigravity/4.3.0)";
pub const ANTIGRAVITY_CLIENT_VERSION: &str = crate::client_identity::ANTIGRAVITY.version;
pub const ANTIGRAVITY_REQUEST_USER_AGENT: &str = crate::client_identity::ANTIGRAVITY.user_agent;
const ANTIGRAVITY_CLIENT_NAME: &str = "antigravity";
const ANTIGRAVITY_GOOG_API_CLIENT: &str = "gl-node/18.18.2 fire/0.8.6 grpc/1.10.x";
@@ -14,7 +14,7 @@ pub fn generate_fingerprint(seed: &str) -> Value {
}
fn generate_header_fingerprint(seed: &str) -> Value {
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
let vscode_session_id = Uuid::new_v5(
&Uuid::NAMESPACE_URL,
format!("aether:fingerprint:{seed}").as_bytes(),
@@ -40,7 +40,7 @@ fn generate_header_fingerprint(seed: &str) -> Value {
}
fn wrap_header_fingerprint(header_fingerprint: Value) -> Value {
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
serde_json::json!({
"transport_profile": {
"profile_id": profile.transport_profile_id(),
@@ -103,7 +103,7 @@ pub fn apply_claude_code_body_mimicry(
return false;
}
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
let model = object
.get("model")
.and_then(Value::as_str)
@@ -20,12 +20,15 @@ pub use policy::{
supports_local_claude_code_transport_with_network,
};
pub use profile::{
current_claude_code_transport_identity_profile, ClaudeCodeBodyCapabilityGate,
claude_code_client_profile, claude_code_client_user_agent, claude_code_client_version,
current_claude_code_transport_identity_profile, set_claude_code_cli_version,
set_claude_code_client_profile, ClaudeCodeBodyCapabilityGate, ClaudeCodeClientProfile,
ClaudeCodeTransportIdentityProfile, ClaudeCodeTransportIdentityProfileVersion,
ClaudeCodeTransportIdentityTemplate, CLAUDE_CODE_BUILTIN_CLI_VERSION,
CLAUDE_CODE_CONTEXT_MANAGEMENT_BETA, CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04,
};
pub use request::{
build_claude_code_passthrough_headers, sanitize_claude_code_request_body,
sanitize_claude_code_request_body_for_beta_header,
build_claude_code_passthrough_headers, finalize_claude_code_request_identity,
sanitize_claude_code_request_body, sanitize_claude_code_request_body_for_beta_header,
};
pub use url::build_claude_code_messages_url;
@@ -1,9 +1,16 @@
use std::collections::{BTreeMap, BTreeSet};
use std::sync::{Arc, OnceLock};
use aether_ai_formats::client_profile::ClientProfileStore;
use aether_ai_formats::ApiOperation;
pub const CLAUDE_CODE_CONTEXT_MANAGEMENT_BETA: &str = "context-management-2025-06-27";
/// Built-in Claude Code CLI version used until the gateway publishes a newer
/// verified release (or when release checks are disabled / unavailable).
pub const CLAUDE_CODE_BUILTIN_CLI_VERSION: &str = "2.1.284";
const MESSAGE_BETAS_2026_04: &[&str] = &[
"claude-code-20250219",
"oauth-2025-04-20",
@@ -53,15 +60,89 @@ pub struct ClaudeCodeBodyCapabilityGate {
pub default_edit_type: Option<&'static str>,
}
/// Versioned upstream identity used when Aether is intentionally acting as a
/// Claude Code transport. Native Anthropic transports never resolve this
/// profile and therefore keep their original headers and body untouched.
/// Dynamic Claude Code CLI identity (version-derived wire values).
///
/// The gateway refreshes this from verified official releases in a background
/// task; request paths only read an immutable snapshot and never touch the
/// network.
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct ClaudeCodeClientProfile {
pub cli_version: String,
pub user_agent: String,
}
impl ClaudeCodeClientProfile {
/// Builds a CLI profile from a release version. Release verification is owned
/// by the release checker; the constructor only rejects clearly invalid values.
pub fn cli(version: &str) -> Result<Self, &'static str> {
let version = version.trim();
if version.is_empty()
|| version.len() > 64
|| !version.bytes().all(|byte| (33..=126).contains(&byte))
{
return Err("invalid Claude Code CLI version");
}
Ok(Self {
cli_version: version.to_owned(),
user_agent: format!("claude-cli/{version} (external, cli)"),
})
}
}
impl Default for ClaudeCodeClientProfile {
fn default() -> Self {
Self::cli(CLAUDE_CODE_BUILTIN_CLI_VERSION)
.expect("built-in Claude Code CLI profile must be valid")
}
}
static ACTIVE_CLIENT_PROFILE: OnceLock<ClientProfileStore<ClaudeCodeClientProfile>> =
OnceLock::new();
fn active_client_profile() -> &'static ClientProfileStore<ClaudeCodeClientProfile> {
ACTIVE_CLIENT_PROFILE
.get_or_init(|| ClientProfileStore::new(ClaudeCodeClientProfile::default()))
}
/// Returns a snapshot of the active CLI profile without holding the global lock.
pub fn claude_code_client_profile() -> Arc<ClaudeCodeClientProfile> {
active_client_profile().snapshot()
}
/// Atomically replaces the active CLI profile and returns the previous one.
pub fn set_claude_code_client_profile(
profile: ClaudeCodeClientProfile,
) -> Arc<ClaudeCodeClientProfile> {
active_client_profile().publish(profile)
}
/// Publishes a CLI profile for the given release version.
pub fn set_claude_code_cli_version(
version: &str,
) -> Result<Arc<ClaudeCodeClientProfile>, &'static str> {
let profile = ClaudeCodeClientProfile::cli(version)?;
Ok(set_claude_code_client_profile(profile))
}
/// Returns the active Claude Code CLI version.
pub fn claude_code_client_version() -> String {
claude_code_client_profile().cli_version.clone()
}
/// Returns the active Claude Code CLI User-Agent.
pub fn claude_code_client_user_agent() -> String {
claude_code_client_profile().user_agent.clone()
}
/// Versioned, static part of the Claude Code transport identity: Stainless SDK
/// and runtime values, beta policy and body capability gates. These values are
/// calibrated together and change only with a new template version; the CLI
/// version itself is supplied by the dynamic [`ClaudeCodeClientProfile`].
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub struct ClaudeCodeTransportIdentityProfile {
pub struct ClaudeCodeTransportIdentityTemplate {
version: ClaudeCodeTransportIdentityProfileVersion,
transport_profile_id: &'static str,
anthropic_version: &'static str,
cli_version: &'static str,
stainless_lang: &'static str,
stainless_package_version: &'static str,
stainless_os: &'static str,
@@ -77,12 +158,11 @@ pub struct ClaudeCodeTransportIdentityProfile {
body_capability_gates: &'static [ClaudeCodeBodyCapabilityGate],
}
pub const CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04: ClaudeCodeTransportIdentityProfile =
ClaudeCodeTransportIdentityProfile {
pub const CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04: ClaudeCodeTransportIdentityTemplate =
ClaudeCodeTransportIdentityTemplate {
version: ClaudeCodeTransportIdentityProfileVersion::V2026_04,
transport_profile_id: "claude_code_nodejs",
anthropic_version: "2023-06-01",
cli_version: "2.1.284",
stainless_lang: "js",
stainless_package_version: "0.112.1",
stainless_os: "Linux",
@@ -98,115 +178,144 @@ pub const CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04: ClaudeCodeTransportIdentityPro
body_capability_gates: BODY_CAPABILITY_GATES_2026_04,
};
pub const fn current_claude_code_transport_identity_profile(
) -> &'static ClaudeCodeTransportIdentityProfile {
&CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04
/// Upstream identity used when Aether is intentionally acting as a Claude Code
/// transport. Native Anthropic transports never resolve this profile and
/// therefore keep their original headers and body untouched.
///
/// Each value is one coherent snapshot of the static template plus the active
/// CLI profile, so headers and billing attribution derived from the same
/// snapshot always agree on the CLI version.
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct ClaudeCodeTransportIdentityProfile {
template: &'static ClaudeCodeTransportIdentityTemplate,
client: Arc<ClaudeCodeClientProfile>,
}
pub fn current_claude_code_transport_identity_profile() -> ClaudeCodeTransportIdentityProfile {
ClaudeCodeTransportIdentityProfile::new(
&CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04,
claude_code_client_profile(),
)
}
impl ClaudeCodeTransportIdentityProfile {
pub const fn version(self) -> ClaudeCodeTransportIdentityProfileVersion {
self.version
pub fn new(
template: &'static ClaudeCodeTransportIdentityTemplate,
client: Arc<ClaudeCodeClientProfile>,
) -> Self {
Self { template, client }
}
pub const fn transport_profile_id(self) -> &'static str {
self.transport_profile_id
pub fn version(&self) -> ClaudeCodeTransportIdentityProfileVersion {
self.template.version
}
pub const fn cli_version(self) -> &'static str {
self.cli_version
pub fn transport_profile_id(&self) -> &'static str {
self.template.transport_profile_id
}
pub const fn billing_cli_version(self) -> &'static str {
self.cli_version
pub fn cli_version(&self) -> &str {
&self.client.cli_version
}
pub fn user_agent(self) -> String {
format!("claude-cli/{} (external, cli)", self.cli_version)
pub fn billing_cli_version(&self) -> &str {
&self.client.cli_version
}
pub const fn stainless_package_version(self) -> &'static str {
self.stainless_package_version
pub fn user_agent(&self) -> &str {
&self.client.user_agent
}
pub const fn stainless_lang(self) -> &'static str {
self.stainless_lang
pub fn stainless_package_version(&self) -> &'static str {
self.template.stainless_package_version
}
pub const fn stainless_os(self) -> &'static str {
self.stainless_os
pub fn stainless_lang(&self) -> &'static str {
self.template.stainless_lang
}
pub const fn stainless_arch(self) -> &'static str {
self.stainless_arch
pub fn stainless_os(&self) -> &'static str {
self.template.stainless_os
}
pub const fn stainless_runtime(self) -> &'static str {
self.stainless_runtime
pub fn stainless_arch(&self) -> &'static str {
self.template.stainless_arch
}
pub const fn stainless_runtime_version(self) -> &'static str {
self.stainless_runtime_version
pub fn stainless_runtime(&self) -> &'static str {
self.template.stainless_runtime
}
pub const fn stainless_retry_count(self) -> &'static str {
self.stainless_retry_count
pub fn stainless_runtime_version(&self) -> &'static str {
self.template.stainless_runtime_version
}
pub const fn stainless_timeout(self) -> &'static str {
self.stainless_timeout
pub fn stainless_retry_count(&self) -> &'static str {
self.template.stainless_retry_count
}
pub fn required_beta_tokens(self, operation: Option<ApiOperation>) -> &'static [&'static str] {
pub fn stainless_timeout(&self) -> &'static str {
self.template.stainless_timeout
}
pub fn required_beta_tokens(&self, operation: Option<ApiOperation>) -> &'static [&'static str] {
if operation == Some(ApiOperation::ClaudeCountTokens) {
self.count_tokens_required_betas
self.template.count_tokens_required_betas
} else {
self.message_required_betas
self.template.message_required_betas
}
}
pub const fn preserves_incoming_betas(self) -> bool {
self.preserve_incoming_betas
pub fn preserves_incoming_betas(&self) -> bool {
self.template.preserve_incoming_betas
}
pub const fn dropped_beta_tokens(self) -> &'static [&'static str] {
self.dropped_betas
pub fn dropped_beta_tokens(&self) -> &'static [&'static str] {
self.template.dropped_betas
}
pub const fn body_capability_gates(self) -> &'static [ClaudeCodeBodyCapabilityGate] {
self.body_capability_gates
pub fn body_capability_gates(&self) -> &'static [ClaudeCodeBodyCapabilityGate] {
self.template.body_capability_gates
}
pub fn body_capability_gate(self, field: &str) -> Option<ClaudeCodeBodyCapabilityGate> {
self.body_capability_gates
pub fn body_capability_gate(&self, field: &str) -> Option<ClaudeCodeBodyCapabilityGate> {
self.template
.body_capability_gates
.iter()
.copied()
.find(|gate| gate.body_field == field)
}
pub fn apply_fixed_headers(self, headers: &mut BTreeMap<String, String>, stream: bool) {
pub fn apply_fixed_headers(&self, headers: &mut BTreeMap<String, String>, stream: bool) {
let template = self.template;
for (name, value) in [
("accept", "application/json"),
("anthropic-version", self.anthropic_version),
("anthropic-version", template.anthropic_version),
("anthropic-dangerous-direct-browser-access", "true"),
("x-app", "cli"),
("x-stainless-lang", self.stainless_lang),
("x-stainless-lang", template.stainless_lang),
(
"x-stainless-package-version",
self.stainless_package_version,
template.stainless_package_version,
),
("x-stainless-os", self.stainless_os),
("x-stainless-arch", self.stainless_arch),
("x-stainless-runtime", self.stainless_runtime),
("x-stainless-os", template.stainless_os),
("x-stainless-arch", template.stainless_arch),
("x-stainless-runtime", template.stainless_runtime),
(
"x-stainless-runtime-version",
self.stainless_runtime_version,
template.stainless_runtime_version,
),
("x-stainless-retry-count", self.stainless_retry_count),
("x-stainless-timeout", self.stainless_timeout),
("x-stainless-retry-count", template.stainless_retry_count),
("x-stainless-timeout", template.stainless_timeout),
] {
headers.retain(|existing, _| !existing.eq_ignore_ascii_case(name));
headers.insert(name.to_string(), value.to_string());
}
headers.insert("user-agent".to_string(), self.user_agent());
headers.retain(|name, _| {
!name.eq_ignore_ascii_case("user-agent")
&& !name.eq_ignore_ascii_case("x-stainless-helper-method")
});
headers.insert("user-agent".to_string(), self.user_agent().to_string());
if stream {
headers.insert(
"x-stainless-helper-method".to_string(),
@@ -218,12 +327,18 @@ impl ClaudeCodeTransportIdentityProfile {
}
pub fn apply_beta_policy(
self,
&self,
headers: &mut BTreeMap<String, String>,
operation: Option<ApiOperation>,
) {
let incoming = headers.get("anthropic-beta").map(String::as_str);
let merged = self.merge_beta_tokens(incoming, operation);
let incoming = headers
.iter()
.filter(|(name, _)| name.eq_ignore_ascii_case("anthropic-beta"))
.map(|(_, value)| value.as_str())
.collect::<Vec<_>>()
.join(",");
let merged = self.merge_beta_tokens(Some(&incoming), operation);
headers.retain(|name, _| !name.eq_ignore_ascii_case("anthropic-beta"));
if merged.is_empty() {
headers.remove("anthropic-beta");
} else {
@@ -232,7 +347,7 @@ impl ClaudeCodeTransportIdentityProfile {
}
pub fn merge_beta_tokens(
self,
&self,
incoming: Option<&str>,
operation: Option<ApiOperation>,
) -> String {
@@ -242,7 +357,7 @@ impl ClaudeCodeTransportIdentityProfile {
for token in self.required_beta_tokens(operation) {
self.append_beta_token(&mut seen, &mut merged, token);
}
if self.preserve_incoming_betas {
if self.template.preserve_incoming_betas {
for token in incoming.unwrap_or_default().split(',') {
self.append_beta_token(&mut seen, &mut merged, token);
}
@@ -250,7 +365,7 @@ impl ClaudeCodeTransportIdentityProfile {
merged.join(",")
}
pub fn beta_header_enables_body_field(self, beta_header: &str, field: &str) -> bool {
pub fn beta_header_enables_body_field(&self, beta_header: &str, field: &str) -> bool {
let Some(gate) = self.body_capability_gate(field) else {
return true;
};
@@ -260,10 +375,16 @@ impl ClaudeCodeTransportIdentityProfile {
.any(|token| token.eq_ignore_ascii_case(gate.beta_token))
}
fn append_beta_token(self, seen: &mut BTreeSet<String>, merged: &mut Vec<String>, token: &str) {
fn append_beta_token(
&self,
seen: &mut BTreeSet<String>,
merged: &mut Vec<String>,
token: &str,
) {
let token = token.trim();
if token.is_empty()
|| self
.template
.dropped_betas
.iter()
.any(|dropped| token.eq_ignore_ascii_case(dropped))
@@ -278,12 +399,17 @@ impl ClaudeCodeTransportIdentityProfile {
#[cfg(test)]
mod tests {
use super::current_claude_code_transport_identity_profile;
use std::sync::Arc;
use super::{
current_claude_code_transport_identity_profile, ClaudeCodeClientProfile,
ClaudeCodeTransportIdentityProfile, CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04,
};
use aether_ai_formats::ApiOperation;
#[test]
fn profile_versions_cli_user_agent_stainless_and_billing_together() {
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
assert_eq!(profile.version().as_str(), "2026-04");
assert_eq!(profile.cli_version(), "2.1.284");
@@ -296,9 +422,43 @@ mod tests {
assert_eq!(profile.stainless_runtime_version(), "v26.3.0");
}
#[test]
fn cli_profile_derives_wire_identity_from_version() {
let client = ClaudeCodeClientProfile::cli(" 2.1.300 ").expect("valid version");
assert_eq!(client.cli_version, "2.1.300");
assert_eq!(client.user_agent, "claude-cli/2.1.300 (external, cli)");
// A snapshot keeps headers and billing attribution on the same CLI version
// without mutating the process-wide active profile.
let profile = ClaudeCodeTransportIdentityProfile::new(
&CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04,
Arc::new(client),
);
let mut headers = std::collections::BTreeMap::new();
profile.apply_fixed_headers(&mut headers, false);
assert_eq!(
headers.get("user-agent").map(String::as_str),
Some("claude-cli/2.1.300 (external, cli)")
);
assert_eq!(profile.billing_cli_version(), "2.1.300");
assert_eq!(
headers
.get("x-stainless-package-version")
.map(String::as_str),
Some("0.112.1")
);
}
#[test]
fn cli_profile_rejects_empty_or_control_values() {
assert!(ClaudeCodeClientProfile::cli("").is_err());
assert!(ClaudeCodeClientProfile::cli("2.1.0\nspoof").is_err());
assert!(ClaudeCodeClientProfile::cli("2.1.0 spoof").is_err());
}
#[test]
fn profile_preserves_context_1m_and_adds_operation_specific_betas() {
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
let messages = profile.merge_beta_tokens(Some("context-1m-2025-08-07,custom"), None);
assert!(messages
@@ -49,23 +49,50 @@ pub fn build_claude_code_passthrough_headers(
out.insert("anthropic-beta".to_string(), incoming_beta_values.join(","));
}
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
profile.apply_fixed_headers(&mut out, stream);
profile.apply_beta_policy(&mut out, None);
out
}
/// Reconcile header/body identity using one immutable profile at the common
/// outbound boundary. Preserve the planner's content negotiation and count-token contract.
pub fn finalize_claude_code_request_identity(
headers: &mut BTreeMap<String, String>,
body: &mut Value,
profile: &ClaudeCodeTransportIdentityProfile,
operation: Option<aether_ai_formats::ApiOperation>,
) {
let accept = headers.get("accept").cloned();
let stream = body.get("stream").and_then(Value::as_bool).unwrap_or(false)
|| accept
.as_deref()
.is_some_and(|v| v.contains("text/event-stream"));
profile.apply_fixed_headers(headers, stream);
if stream {
crate::headers::force_identity_accept_encoding(headers);
}
profile.apply_beta_policy(headers, operation);
if let Some(accept) = accept {
headers.insert("accept".to_string(), accept);
}
if operation != Some(aether_ai_formats::ApiOperation::ClaudeCountTokens) {
let beta = headers.get("anthropic-beta").cloned().unwrap_or_default();
sanitize_claude_code_request_body_for_beta_header(body, &beta, profile);
}
}
pub fn sanitize_claude_code_request_body(body: &mut Value) {
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
let beta_header = profile.merge_beta_tokens(None, None);
sanitize_claude_code_request_body_for_beta_header(body, &beta_header, profile);
sanitize_claude_code_request_body_for_beta_header(body, &beta_header, &profile);
}
pub fn sanitize_claude_code_request_body_for_beta_header(
body: &mut Value,
beta_header: &str,
profile: ClaudeCodeTransportIdentityProfile,
profile: &ClaudeCodeTransportIdentityProfile,
) {
let Some(body_object) = body.as_object_mut() else {
return;
@@ -303,7 +330,7 @@ mod tests {
#[test]
fn context_management_body_is_gated_by_the_matching_beta_token() {
let profile = *current_claude_code_transport_identity_profile();
let profile = current_claude_code_transport_identity_profile();
let original = json!({
"context_management": {
"edits": [{"type":"clear_thinking_20251015", "keep":"all"}]
@@ -315,7 +342,7 @@ mod tests {
sanitize_claude_code_request_body_for_beta_header(
&mut without_beta,
"oauth-2025-04-20",
profile,
&profile,
);
assert!(without_beta.get("context_management").is_none());
@@ -323,7 +350,7 @@ mod tests {
sanitize_claude_code_request_body_for_beta_header(
&mut with_beta,
"oauth-2025-04-20, context-management-2025-06-27",
profile,
&profile,
);
assert_eq!(with_beta, original);
}
@@ -371,3 +398,55 @@ mod tests {
);
}
}
#[cfg(test)]
mod final_identity_tests {
use super::*;
use crate::claude_code::{ClaudeCodeClientProfile, CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04};
use std::sync::Arc;
fn profile() -> ClaudeCodeTransportIdentityProfile {
ClaudeCodeTransportIdentityProfile::new(
&CLAUDE_CODE_TRANSPORT_IDENTITY_2026_04,
Arc::new(ClaudeCodeClientProfile::cli("2.1.286").unwrap()),
)
}
#[test]
fn terminal_snapshot_reconciles_billing_and_headers_without_changing_negotiation() {
let mut headers = BTreeMap::from([
("accept".into(), "text/event-stream".into()),
("User-Agent".into(), "old-client".into()),
("X-Stainless-Package-Version".into(), "old-sdk".into()),
("Anthropic-Beta".into(), "custom-beta".into()),
]);
let mut body = serde_json::json!({"stream":true, "system":[{"type":"text", "text":"x-anthropic-billing-header: cc_version=2.1.280.abc; cc_entrypoint=cli;"}]});
finalize_claude_code_request_identity(&mut headers, &mut body, &profile(), None);
assert_eq!(headers["user-agent"], "claude-cli/2.1.286 (external, cli)");
assert_eq!(headers["accept"], "text/event-stream");
assert_eq!(headers["accept-encoding"], "identity");
assert_eq!(headers["x-stainless-package-version"], "0.112.1");
assert!(!headers.contains_key("User-Agent"));
assert!(!headers.contains_key("X-Stainless-Package-Version"));
assert!(!headers.contains_key("Anthropic-Beta"));
assert!(headers["anthropic-beta"].contains("custom-beta"));
assert!(body["system"][0]["text"]
.as_str()
.unwrap()
.contains("cc_version=2.1.286.abc;"));
let before = body.clone();
finalize_claude_code_request_identity(&mut headers, &mut body, &profile(), None);
assert_eq!(body, before);
}
#[test]
fn count_token_body_remains_untouched() {
let mut headers = BTreeMap::new();
let mut body = serde_json::json!({"model":"claude-test", "messages":[], "thinking":{"type":"enabled"}});
let before = body.clone();
finalize_claude_code_request_identity(
&mut headers,
&mut body,
&profile(),
Some(aether_ai_formats::ApiOperation::ClaudeCountTokens),
);
assert_eq!(body, before);
assert_eq!(headers["user-agent"], "claude-cli/2.1.286 (external, cli)");
}
}
@@ -0,0 +1,65 @@
//! Provider wire templates. Dynamic CLI versions are independent of SDK and
//! browser fingerprints; pinned templates are changed only after verification.
use aether_ai_formats::client_profile::validate_client_version;
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct VersionedClientIdentity {
pub version: String,
pub user_agent: String,
}
impl VersionedClientIdentity {
pub fn new(version: &str, agent: &str, suffix: &str) -> Result<Self, &'static str> {
let version = validate_client_version(version)?;
Ok(Self {
version: version.to_owned(),
user_agent: format!("{agent}/{version}{suffix}"),
})
}
}
#[derive(Debug, Clone, Copy)]
pub struct PinnedClientIdentity {
pub version: &'static str,
pub user_agent: &'static str,
}
pub const GEMINI_CLI: PinnedClientIdentity = PinnedClientIdentity {
version: "0.1.5",
user_agent: "GeminiCLI/0.1.5 (Windows; AMD64)",
};
// Legacy standard-models fallback; dedicated Kiro requests use OAuth SDK identity.
pub const KIRO_MODELS_LEGACY_USER_AGENT: &str = "claude-code/1.0.1";
pub const ANTIGRAVITY: PinnedClientIdentity = PinnedClientIdentity {
version: "4.3.0",
user_agent: "vscode/1.X.X (Antigravity/4.3.0)",
};
pub const WINDSURF: PinnedClientIdentity = PinnedClientIdentity {
version: "1.9600.41",
user_agent: "windsurf/1.9600.41",
};
// Verified browser release tuple, shared by inference and quota requests.
// Do not update these independently or derive a web build from a CLI release.
pub const CHATGPT_WEB_USER_AGENT: &str = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36 Edg/143.0.0.0";
pub const CHATGPT_WEB_CLIENT_VERSION: &str = "prod-be885abbfcfe7b1f511e88b3003d9ee44757fbad";
pub const CHATGPT_WEB_BUILD_NUMBER: &str = "5955942";
pub const CHATGPT_WEB_SEC_CH_UA: &str =
r#""Microsoft Edge";v="143", "Chromium";v="143", "Not A(Brand";v="24""#;
pub const CHATGPT_WEB_BROWSER_PROFILE: &str = "chrome143";
// Kiro authentication and request adapters already share the OAuth model.
pub use aether_oauth::provider::providers::{
DEFAULT_KIRO_VERSION, DEFAULT_NODE_VERSION, DEFAULT_SYSTEM_VERSION,
};
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn pinned_headers_and_body_versions_are_calibrated_together() {
for identity in [ANTIGRAVITY, WINDSURF] {
assert!(identity.user_agent.contains(identity.version));
}
}
}
@@ -1,5 +1,9 @@
mod auth;
mod policy;
mod profile;
pub use profile::{
gemini_cli_client_user_agent, gemini_cli_client_version, set_gemini_cli_client_version,
};
mod request;
mod url;
@@ -0,0 +1,41 @@
use crate::client_identity::VersionedClientIdentity;
use aether_ai_formats::client_profile::ClientProfileStore;
use std::sync::OnceLock;
pub const GEMINI_CLI_BUILTIN_VERSION: &str = crate::client_identity::GEMINI_CLI.version;
// Keep the established template; a version release does not change platform identity.
fn identity(version: &str) -> Result<VersionedClientIdentity, &'static str> {
VersionedClientIdentity::new(version, "GeminiCLI", " (Windows; AMD64)")
}
static ACTIVE: OnceLock<ClientProfileStore<VersionedClientIdentity>> = OnceLock::new();
fn active() -> &'static ClientProfileStore<VersionedClientIdentity> {
ACTIVE.get_or_init(|| {
ClientProfileStore::new(
identity(GEMINI_CLI_BUILTIN_VERSION).expect("valid built-in Gemini identity"),
)
})
}
pub fn gemini_cli_client_version() -> String {
active().snapshot().version.clone()
}
pub fn gemini_cli_client_user_agent() -> String {
active().snapshot().user_agent.clone()
}
pub fn set_gemini_cli_client_version(version: &str) -> Result<String, &'static str> {
Ok(active().publish(identity(version)?).version.clone())
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn version_updates_preserve_the_existing_platform_template() {
let profile = identity("0.62.0").unwrap();
assert_eq!(profile.user_agent, "GeminiCLI/0.62.0 (Windows; AMD64)");
assert!(identity("0.62.0\nx: y").is_err());
assert_eq!(
identity(GEMINI_CLI_BUILTIN_VERSION).unwrap().user_agent,
super::super::GEMINI_CLI_USER_AGENT
);
}
}
@@ -2,7 +2,7 @@ use std::collections::BTreeMap;
use url::form_urlencoded;
pub const GEMINI_CLI_USER_AGENT: &str = "GeminiCLI/0.1.5 (Windows; AMD64)";
pub const GEMINI_CLI_USER_AGENT: &str = crate::client_identity::GEMINI_CLI.user_agent;
pub const GEMINI_CLI_V1INTERNAL_PATH_TEMPLATE: &str = "/v1internal:{action}";
pub const GEMINI_CLI_RETRIEVE_USER_QUOTA_PATH: &str = "/v1internal:retrieveUserQuota";
@@ -81,7 +81,7 @@ pub fn should_skip_request_header(name: &str) -> bool {
}
fn is_untrusted_forwarding_metadata_header(normalized_name: &str) -> bool {
matches!(normalized_name, "forwarded" | "via")
matches!(normalized_name, "forwarded" | "via" | "x-envoy-internal")
|| normalized_name.starts_with("x-forwarded-")
|| normalized_name.starts_with("x_forwarded_")
|| normalized_name.starts_with("x-real-")
@@ -186,6 +186,7 @@ pub(crate) fn remove_declared_connection_headers(
));
headers.retain(|name, _| {
!name.eq_ignore_ascii_case("connection")
&& !name.eq_ignore_ascii_case("x-envoy-internal")
&& !is_declared_connection_header(name, &all_declared)
});
}
@@ -455,6 +456,7 @@ mod tests {
"X-Rewrite-URL",
"X-Override-URL",
"X-Envoy-Original-Path",
"X-Envoy-Internal",
] {
assert!(should_skip_request_header(header));
assert!(should_skip_upstream_passthrough_header(header));
@@ -5,6 +5,7 @@ pub mod auth;
mod auth_config;
mod cache;
pub mod claude_code;
pub mod client_identity;
mod codex_fingerprint;
pub mod conversion;
mod diagnostics;
@@ -177,7 +177,7 @@ fn resolve_claude_code_transport_profile(
return None;
}
let identity_profile = *current_claude_code_transport_identity_profile();
let identity_profile = current_claude_code_transport_identity_profile();
Some(ResolvedTransportProfile {
profile_id: identity_profile.transport_profile_id().to_string(),
backend: TRANSPORT_BACKEND_REQWEST_RUSTLS.to_string(),
@@ -199,6 +199,23 @@ pub fn apply_provider_outbound_request_policies(
provider_request_headers: &mut BTreeMap<String, String>,
provider_request_body: &mut Value,
) -> Vec<ProviderOutboundRequestPolicyResult> {
// This is the common boundary after planner rules and before transport.
provider_request_headers.retain(|name, _| !name.eq_ignore_ascii_case("x-envoy-internal"));
if transport
.provider
.provider_type
.trim()
.eq_ignore_ascii_case("claude_code")
&& aether_ai_formats::normalize_api_format_alias(provider_api_format) == "claude:messages"
{
let profile = crate::claude_code::current_claude_code_transport_identity_profile();
crate::claude_code::finalize_claude_code_request_identity(
provider_request_headers,
provider_request_body,
&profile,
context.api_operation(),
);
}
if !transport
.provider
.provider_type
@@ -848,7 +848,7 @@ pub fn build_same_format_provider_headers(
} else {
replace_upstream_auth_headers(&mut provider_request_headers, "", "");
}
let claude_code_profile = *current_claude_code_transport_identity_profile();
let claude_code_profile = current_claude_code_transport_identity_profile();
if input.behavior.is_claude_code_transport {
claude_code_profile.apply_fixed_headers(
&mut provider_request_headers,
@@ -23,7 +23,7 @@ pub mod proto;
pub const PROVIDER_TYPE: &str = "windsurf";
pub const WINDSURF_ENVELOPE_NAME: &str = "windsurf:GetChatMessage";
pub const GET_CHAT_MESSAGE_PATH: &str = "/exa.api_server_pb.ApiServerService/GetChatMessage";
const DEFAULT_IDE_VERSION: &str = "1.9600.41";
pub const DEFAULT_IDE_VERSION: &str = crate::client_identity::WINDSURF.version;
const PLACEHOLDER_API_KEY: &str = "__placeholder__";
pub fn is_windsurf_provider_transport(transport: &GatewayProviderTransportSnapshot) -> bool {
+19 -22
View File
@@ -1,7 +1,10 @@
pub mod video;
use std::collections::BTreeMap;
use std::sync::{OnceLock, RwLock};
use std::sync::OnceLock;
use crate::client_identity::VersionedClientIdentity;
use aether_ai_formats::client_profile::ClientProfileStore;
use aether_ai_formats::normalize_api_format_alias;
use serde_json::Value;
@@ -23,37 +26,31 @@ pub const XAI_CLIENT_IDENTIFIER_VALUE: &str = "grok-shell";
pub const XAI_AUTHENTICATE_RESPONSE_HEADER: &str = "x-authenticateresponse";
pub const XAI_AUTHENTICATE_RESPONSE_VALUE: &str = "authenticate-response";
static ACTIVE_CLIENT_VERSION: OnceLock<RwLock<String>> = OnceLock::new();
static ACTIVE_CLIENT_VERSION: OnceLock<ClientProfileStore<VersionedClientIdentity>> =
OnceLock::new();
fn active_client_version() -> &'static RwLock<String> {
ACTIVE_CLIENT_VERSION.get_or_init(|| RwLock::new(XAI_DEFAULT_CLIENT_VERSION.to_owned()))
fn active_client_version() -> &'static ClientProfileStore<VersionedClientIdentity> {
ACTIVE_CLIENT_VERSION.get_or_init(|| {
ClientProfileStore::new(
VersionedClientIdentity::new(XAI_DEFAULT_CLIENT_VERSION, "xai-grok-workspace", "")
.expect("valid built-in Grok identity"),
)
})
}
/// 返回当前发布的 Grok CLI 版本快照。
pub fn xai_client_version() -> String {
active_client_version()
.read()
.unwrap_or_else(std::sync::PoisonError::into_inner)
.clone()
active_client_version().snapshot().version.clone()
}
/// 原子替换当前 Grok CLI 版本,返回替换前的版本;版本校验由发布检查器负责,这里只拒绝明显非法值。
/// 原子替换当前 Grok CLI 身份,返回替换前的版本。
pub fn set_xai_client_version(version: &str) -> Result<String, &'static str> {
let version = version.trim();
if version.is_empty()
|| version.len() > 64
|| !version.bytes().all(|byte| (33..=126).contains(&byte))
{
return Err("invalid Grok CLI version");
}
let mut current = active_client_version()
.write()
.unwrap_or_else(std::sync::PoisonError::into_inner);
Ok(std::mem::replace(&mut *current, version.to_owned()))
let profile = VersionedClientIdentity::new(version, "xai-grok-workspace", "")?;
Ok(active_client_version().publish(profile).version.clone())
}
pub fn xai_cli_user_agent() -> String {
format!("xai-grok-workspace/{}", xai_client_version())
active_client_version().snapshot().user_agent.clone()
}
pub fn is_xai_provider_transport(transport: &GatewayProviderTransportSnapshot) -> bool {
@@ -125,7 +122,7 @@ pub fn should_attach_cli_identity_headers(
pub fn insert_cli_identity_headers(headers: &mut BTreeMap<String, String>) {
let client_version = xai_client_version();
let user_agent = xai_cli_user_agent();
let user_agent = format!("xai-grok-workspace/{client_version}");
for (name, value) in [
(XAI_TOKEN_AUTH_HEADER, XAI_TOKEN_AUTH_VALUE),
(XAI_CLIENT_VERSION_HEADER, client_version.as_str()),