The global claudeHeaderCache singleton overlaid the last-seen Claude Code client's identity headers onto every subsequent request, leaking one client's headers (anthropic-beta, user-agent, x-stainless-*, etc.) onto another client/account sharing the same server. Removed the singleton and the claudeOverlay hook entirely, falling back to static per-provider headers. anthropic-beta is now computed per-request from the requested model, gating heavy-agent flags (advanced-tool-use, effort) to opus/sonnet only. |
||
|---|---|---|
| .. | ||
| bypassHandler.js | ||
| claudeCloaking.js | ||
| claudeSignature.js | ||
| clientDetector.js | ||
| cursorChecksum.js | ||
| cursorProtobuf.js | ||
| debugLog.js | ||
| error.js | ||
| kiroSessionReplay.js | ||
| ollamaTransform.js | ||
| proxyFetch.js | ||
| reasoningContentInjector.js | ||
| requestLogger.js | ||
| responsesStreamHelpers.js | ||
| sessionManager.js | ||
| sse.js | ||
| sseConstants.js | ||
| stream.js | ||
| streamHandler.js | ||
| streamHelpers.js | ||
| toolDeduper.js | ||
| usageTracking.js | ||