fix(claude): gate CCH signing by upstream origin and validate fingerprint-profile
Claude Code 2.1.220 through 2.1.234 emit the cch attribution only for firstParty on api.anthropic.com and for vertex; every other backend sends the billing header unsigned. CPA had dropped its endpoint check, so an opted-in API key signed a per-request hash on any gateway and could bust that gateway's prompt cache. - Restore the endpoint gate in claudeCCHSigningEnabled: a real Claude OAuth credential still signs on every upstream, because a downstream Claude Code pointed at CPA cannot produce that value itself, while a claude-code-cli API key signs only on api.anthropic.com or Vertex - Drop the unused origin parameter from Claude fingerprint policy resolution and restore the original resolveClaudeWirePolicy signature; the wire profile follows the credential and only CCH follows the origin - Add config.NormalizeClaudeFingerprintProfile / ValidateClaudeFingerprintProfile as the single source of truth for fingerprint-profile values - Reject unknown fingerprint-profile values in the Management API, and warn once per distinct value at request time instead of on every resolution, which previously logged about four warnings per request for one typo - Preserve unrecognized values through config sanitization so rewriting a config file never discards operator input - Update config.example.yaml and tests for the origin-scoped CCH behavior
S
sususu committed
aec70dfec4ab5671aa3f0b09285e44b1a734d470
Parent: f1b0431