headroom/tests/test_provider_registry.py
Abhay Singh 1e448b5503
fix(providers): route Claude requests to Copilot when the OpenAI target is a Copilot host (#3258)
## Description

Through `headroom wrap vscode` / `wrap copilot --subscription`, GitHub
Copilot **GPT** models work but **Claude** models fail with `Invalid
bearer token` (issue #3247). The logs tell the story:

```text
# GPT — works:
event=outbound_request  path=https://api.githubcopilot.com/chat/completions  status=200

# Claude — fails:
event=outbound_request  path=https://api.anthropic.com/v1/messages           status=401
```

GitHub Copilot serves **both** surfaces from the same host: its OpenAI
surface (`/chat/completions`, `/responses`) and its Anthropic surface
for Claude models (`/v1/messages`) — `build_copilot_upstream_url`
already documents and handles this. But `resolve_api_targets` resolves
each provider target independently: when the Copilot flow points the
**OpenAI** target at a Copilot host (so GPT works), the **Anthropic**
target is left at its default `https://api.anthropic.com`. Claude-model
requests are therefore forwarded to the real Anthropic API carrying the
GitHub Copilot bearer, which Anthropic rejects with `Invalid bearer
token`.

## Fix

In `resolve_api_targets`, when the resolved OpenAI target is a Copilot
upstream host **and no explicit Anthropic target was configured**,
default the Anthropic target to that same Copilot host. Claude requests
then reach `https://api.githubcopilot.com/v1/messages` — the surface
that serves them, where the Copilot bearer is valid. An explicit
`ANTHROPIC_TARGET_API_URL` always wins (only a `None` override is filled
in), and non-Copilot OpenAI targets are untouched, so direct-Anthropic
setups are unaffected.

Reproduction:

```python
resolve_api_targets(ProviderApiOverrides(openai="https://api.githubcopilot.com", anthropic=None, ...))
# BEFORE: targets.anthropic == "https://api.anthropic.com"   -> Copilot bearer 401s there
# AFTER:  targets.anthropic == "https://api.githubcopilot.com"
```

## Type of Change

- [x] Bug fix (non-breaking change that fixes an issue)
- [ ] New feature (non-breaking change that adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [ ] Documentation update
- [ ] Performance improvement
- [ ] Code refactoring (no functional changes)

## Changes Made

- `headroom/providers/registry.py`: `resolve_api_targets` now fills a
`None` Anthropic override with the OpenAI target when that target is a
Copilot host (`is_copilot_upstream_url`). Explicit overrides and
non-Copilot targets are unchanged.
- `tests/test_provider_registry.py`: added three tests — Copilot OpenAI
target routes Anthropic to Copilot; an explicit Anthropic override wins;
a non-Copilot OpenAI target leaves the Anthropic default alone.

## Testing

- [x] Unit tests pass (`pytest`)
- [x] Linting passes (`ruff check`)
- [x] Type checking passes (`mypy headroom`)
- [x] New tests added for new functionality

### Test Output

```text
tests/test_provider_registry.py tests/test_provider_registry_extended.py tests/test_banner_upstream_targets.py  ->  37 passed in 12.11s
(the new Copilot test FAILS on pre-fix code — verified via git stash)
uvx ruff@0.16.2 check headroom/providers/registry.py tests/test_provider_registry.py  ->  All checks passed!
uvx mypy@1.20.2 headroom/providers/registry.py  ->  Success: no issues found in 1 source file
```

## Real Behavior Proof

- Environment: Windows 11, Python 3.12.11, project venv, pytest 9.1.1,
ruff 0.16.2 and mypy 1.20.2 via uvx.
- Exact command / steps: `resolve_api_targets` with
`openai="https://api.githubcopilot.com"` (and the
`api.business.githubcopilot.com` variant) and `anthropic=None` returned
`anthropic="https://api.anthropic.com"` before the fix and the Copilot
host after; an explicit `anthropic="https://api.anthropic.com"` is
preserved; `openai="https://api.openai.com"` leaves `anthropic` at the
default.
- Observed result: Claude-model requests now resolve to the Copilot host
that serves them; OpenAI/direct-Anthropic behavior is unchanged.
- Not tested: no live macOS/VS Code Copilot round trip
(environment-specific); the target-resolution seam that decides the
upstream host is exercised directly. `is_copilot_upstream_url` already
recognizes the github.com Copilot hosts (verified).

## Runtime Rollout Safety

- Rollout-managed feature(s): none. This is upstream target resolution
in the provider registry, not a rollout-channel-gated runtime feature.
- Minimum rollout channel: N/A.
- Stable/default behavior changed: only the broken case changes — a
Copilot OpenAI target with no Anthropic override now sends Claude to
Copilot instead of 401ing against api.anthropic.com. Explicit Anthropic
targets and non-Copilot OpenAI targets are byte-for-byte unchanged.
- Kill switch / disable path: set `ANTHROPIC_TARGET_API_URL` explicitly
to opt out of the default.
- Unsafe override required: no.
- Qualification impact: none for non-Copilot deployments.
- Rollback path: revert this PR.

## Review Readiness

- [x] I have performed a self-review
- [x] This PR is ready for human review

## Checklist

- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [x] I have commented my code, particularly in hard-to-understand areas
- [ ] I have made corresponding changes to the documentation (N/A:
internal behavior)
- [x] My changes generate no new warnings
- [x] I have added tests that prove my fix is effective or that my
feature works
- [x] New and existing unit tests pass locally with my changes
- [x] I did **not** edit `CHANGELOG.md`

## Additional Notes

Fixes the routing/auth mismatch at the resolution layer so it applies
uniformly across the Copilot config paths (`wrap vscode`, `wrap copilot
--subscription`) that set the OpenAI target to a Copilot host. If a
specific deploy sets neither target to a Copilot host (relying solely on
path-based passthrough routing for OpenAI), configuring
`ANTHROPIC_TARGET_API_URL` to the Copilot host remains the explicit
escape hatch.
2026-08-26 22:43:11 +05:30

504 lines
17 KiB
Python

from __future__ import annotations
import logging
import pytest
from headroom.providers.registry import (
ProviderApiOverrides,
build_proxy_provider_runtime,
create_proxy_backend,
format_backend_status,
resolve_api_overrides,
resolve_api_targets,
resolve_extra_headers,
)
from headroom.proxy.models import ProxyConfig
def test_resolve_api_overrides_prefers_explicit_values_over_environment(monkeypatch) -> None:
monkeypatch.setenv("ANTHROPIC_TARGET_API_URL", "https://env.anthropic.example/v1")
monkeypatch.setenv("OPENAI_TARGET_API_URL", "https://env.openai.example/v1")
monkeypatch.setenv("VERTEX_TARGET_API_URL", "https://env-vertex-aiplatform.example/v1")
overrides = resolve_api_overrides(
anthropic_api_url="https://cli.anthropic.example/v1",
openai_api_url=None,
gemini_api_url=None,
cloudcode_api_url=None,
vertex_api_url="https://cli-vertex-aiplatform.example/v1",
)
assert overrides == ProviderApiOverrides(
anthropic="https://cli.anthropic.example/v1",
openai="https://env.openai.example/v1",
gemini=None,
cloudcode=None,
vertex="https://cli-vertex-aiplatform.example/v1",
)
def test_resolve_api_targets_normalizes_trailing_v1() -> None:
targets = resolve_api_targets(
ProviderApiOverrides(
anthropic="https://anthropic.example/v1/",
openai="https://openai.example/v1",
gemini="https://gemini.example/v1",
cloudcode="https://cloudcode.example/v1/",
vertex="https://vertex.example/v1/",
)
)
assert targets.anthropic == "https://anthropic.example"
assert targets.openai == "https://openai.example"
assert targets.gemini == "https://gemini.example"
assert targets.cloudcode == "https://cloudcode.example"
assert targets.vertex == "https://vertex.example"
def test_copilot_openai_target_routes_anthropic_to_copilot() -> None:
"""When the OpenAI target is a Copilot host and no Anthropic override is set,
the Anthropic target must default to the same Copilot host.
Copilot serves Claude models via its Anthropic surface (``/v1/messages``) on
the same host. Without this, Claude requests fell back to api.anthropic.com
and 401'd with the Copilot bearer ("Invalid bearer token", #3247).
"""
targets = resolve_api_targets(
ProviderApiOverrides(
anthropic=None,
openai="https://api.githubcopilot.com",
gemini=None,
cloudcode=None,
vertex=None,
)
)
assert targets.openai == "https://api.githubcopilot.com"
assert targets.anthropic == "https://api.githubcopilot.com"
def test_explicit_anthropic_override_wins_over_copilot_default() -> None:
"""An explicit Anthropic target is never overridden by the Copilot default."""
targets = resolve_api_targets(
ProviderApiOverrides(
anthropic="https://api.anthropic.com",
openai="https://api.githubcopilot.com",
gemini=None,
cloudcode=None,
vertex=None,
)
)
assert targets.anthropic == "https://api.anthropic.com"
def test_non_copilot_openai_target_leaves_anthropic_default() -> None:
"""A non-Copilot OpenAI target must not touch the Anthropic default."""
targets = resolve_api_targets(
ProviderApiOverrides(
anthropic=None,
openai="https://api.openai.com",
gemini=None,
cloudcode=None,
vertex=None,
)
)
assert targets.anthropic == "https://api.anthropic.com"
def test_proxy_config_exposes_provider_api_overrides() -> None:
config = ProxyConfig(
anthropic_api_url="https://anthropic.example",
openai_api_url="https://openai.example",
gemini_api_url=None,
cloudcode_api_url="https://cloudcode.example",
vertex_api_url="https://vertex.example",
)
assert config.provider_api_overrides == ProviderApiOverrides(
anthropic="https://anthropic.example",
openai="https://openai.example",
gemini=None,
cloudcode="https://cloudcode.example",
vertex="https://vertex.example",
)
def test_format_backend_status_for_anyllm() -> None:
assert (
format_backend_status(
backend="anyllm",
anyllm_provider="groq",
bedrock_region="us-central1",
)
== "Groq via any-llm"
)
def test_format_backend_status_for_anthropic_direct() -> None:
assert (
format_backend_status(
backend="anthropic",
anyllm_provider="ignored",
bedrock_region=None,
)
== "ANTHROPIC (direct API)"
)
def test_proxy_provider_runtime_routes_model_metadata_and_passthrough() -> None:
runtime = build_proxy_provider_runtime(ProxyConfig())
assert runtime.model_metadata_provider({"x-api-key": "test"}) == "anthropic"
assert runtime.model_metadata_provider({}) == "openai"
assert (
runtime.select_passthrough_base_url({"x-api-key": "test"}) == runtime.api_targets.anthropic
)
assert (
runtime.select_passthrough_base_url({"x-goog-api-key": "test"})
== runtime.api_targets.gemini
)
assert runtime.select_passthrough_base_url({"api-key": "azure", "x-headroom-base-url": ""}) == (
runtime.api_targets.openai
)
def test_create_proxy_backend_handles_missing_litellm_backend(caplog) -> None:
logger = logging.getLogger("test")
with caplog.at_level(logging.WARNING):
missing = create_proxy_backend(
backend="bedrock",
anyllm_provider="ignored",
bedrock_region="us-east-1",
logger=logger,
litellm_backend_cls=lambda provider, region, profile_name=None: (_ for _ in ()).throw(
ImportError("missing")
),
)
assert missing is None
assert "LiteLLM backend not available" in caplog.text
def test_create_proxy_backend_logs_structured_failure_details(caplog) -> None:
logger = logging.getLogger("test")
with caplog.at_level(logging.ERROR):
missing = create_proxy_backend(
backend="bedrock",
anyllm_provider="ignored",
bedrock_region="us-east-1",
logger=logger,
litellm_backend_cls=lambda provider, region, profile_name=None: (_ for _ in ()).throw(
RuntimeError("boom")
),
)
assert missing is None
assert "backend initialization failed: backend=litellm-bedrock provider=bedrock error=boom" in (
caplog.text
)
def test_proxy_provider_runtime_loaders_cache_backend_types(monkeypatch) -> None:
import headroom.providers.registry as registry
anyllm_loads = 0
litellm_loads = 0
class FakeAnyLLMBackend:
pass
class FakeLiteLLMBackend:
pass
def fake_import(name, globals=None, locals=None, fromlist=(), level=0):
nonlocal anyllm_loads, litellm_loads
if name == "headroom.backends.anyllm":
anyllm_loads += 1
return type("Module", (), {"AnyLLMBackend": FakeAnyLLMBackend})()
if name == "headroom.backends.litellm":
litellm_loads += 1
return type("Module", (), {"LiteLLMBackend": FakeLiteLLMBackend})()
raise AssertionError(name)
monkeypatch.setattr(registry, "AnyLLMBackendType", None)
monkeypatch.setattr(registry, "LiteLLMBackendType", None)
monkeypatch.setattr("builtins.__import__", fake_import)
assert registry._load_anyllm_backend() is FakeAnyLLMBackend
assert registry._load_anyllm_backend() is FakeAnyLLMBackend
assert registry._load_litellm_backend() is FakeLiteLLMBackend
assert registry._load_litellm_backend() is FakeLiteLLMBackend
assert anyllm_loads == 1
assert litellm_loads == 1
def test_proxy_provider_runtime_transport_helpers_handle_missing_usage() -> None:
import headroom.providers.registry as registry
class Storage:
def __init__(self) -> None:
self.saved = []
def save(self, metrics) -> None:
self.saved.append(metrics)
client = type(
"Client",
(),
{
"_storage": Storage(),
"_original": type(
"Original",
(),
{
"chat": type(
"Chat",
(),
{
"completions": type(
"Completions",
(),
{
"create": staticmethod(
lambda **kwargs: type("Resp", (), {"usage": None})()
)
},
)()
},
)(),
"messages": type(
"Messages",
(),
{
"create": staticmethod(
lambda **kwargs: type("Resp", (), {"usage": None})()
)
},
)(),
},
)(),
},
)()
openai_metrics = type("Metrics", (), {"tokens_output": 0, "cached_tokens": 0})()
anthropic_metrics = type("Metrics", (), {"tokens_output": 0, "cached_tokens": 0})()
registry._call_openai_transport(
client,
model="gpt-4o",
messages=[],
stream=False,
metrics=openai_metrics,
)
registry._call_anthropic_transport(
client,
model="claude",
messages=[],
stream=False,
metrics=anthropic_metrics,
)
assert openai_metrics.tokens_output == 0
assert openai_metrics.cached_tokens == 0
assert anthropic_metrics.tokens_output == 0
assert anthropic_metrics.cached_tokens == 0
assert len(client._storage.saved) == 2
def test_proxy_provider_runtime_transport_helpers_handle_usage_without_optional_cache_fields() -> (
None
):
import headroom.providers.registry as registry
class Storage:
def __init__(self) -> None:
self.saved = []
def save(self, metrics) -> None:
self.saved.append(metrics)
client = type(
"Client",
(),
{
"_storage": Storage(),
"_original": type(
"Original",
(),
{
"chat": type(
"Chat",
(),
{
"completions": type(
"Completions",
(),
{
"create": staticmethod(
lambda **kwargs: type(
"Resp",
(),
{
"usage": type(
"Usage",
(),
{"completion_tokens": 7},
)()
},
)()
)
},
)()
},
)(),
"messages": type(
"Messages",
(),
{
"create": staticmethod(
lambda **kwargs: type(
"Resp",
(),
{
"usage": type(
"Usage",
(),
{"output_tokens": 5},
)()
},
)()
)
},
)(),
},
)(),
},
)()
openai_metrics = type("Metrics", (), {"tokens_output": 0, "cached_tokens": 0})()
anthropic_metrics = type("Metrics", (), {"tokens_output": 0, "cached_tokens": 0})()
registry._call_openai_transport(
client,
model="gpt-4o",
messages=[],
stream=False,
metrics=openai_metrics,
)
registry._call_anthropic_transport(
client,
model="claude",
messages=[],
stream=False,
metrics=anthropic_metrics,
)
assert openai_metrics.tokens_output == 7
assert openai_metrics.cached_tokens == 0
assert anthropic_metrics.tokens_output == 5
assert anthropic_metrics.cached_tokens == 0
assert len(client._storage.saved) == 2
def test_proxy_provider_runtime_openai_transport_handles_prompt_details_without_cached_tokens() -> (
None
):
import headroom.providers.registry as registry
class Storage:
def __init__(self) -> None:
self.saved = []
def save(self, metrics) -> None:
self.saved.append(metrics)
client = type(
"Client",
(),
{
"_storage": Storage(),
"_original": type(
"Original",
(),
{
"chat": type(
"Chat",
(),
{
"completions": type(
"Completions",
(),
{
"create": staticmethod(
lambda **kwargs: type(
"Resp",
(),
{
"usage": type(
"Usage",
(),
{
"completion_tokens": 9,
"prompt_tokens_details": type(
"Details",
(),
{},
)(),
},
)()
},
)()
)
},
)()
},
)()
},
)(),
},
)()
metrics = type("Metrics", (), {"tokens_output": 0, "cached_tokens": 0})()
registry._call_openai_transport(
client,
model="gpt-4o",
messages=[],
stream=False,
metrics=metrics,
)
assert metrics.tokens_output == 9
assert metrics.cached_tokens == 0
assert len(client._storage.saved) == 1
def test_resolve_extra_headers_cli_wins_over_env(monkeypatch) -> None:
monkeypatch.setenv("ANTHROPIC_TARGET_API_HEADERS", '{"Env-Header": "env-value"}')
result = resolve_extra_headers('{"Cli-Header": "cli-value"}', "ANTHROPIC_TARGET_API_HEADERS")
assert result == {"Cli-Header": "cli-value"}
def test_resolve_extra_headers_falls_back_to_env(monkeypatch) -> None:
monkeypatch.setenv("OPENAI_TARGET_API_HEADERS", '{"Env-Header": "env-value"}')
result = resolve_extra_headers(None, "OPENAI_TARGET_API_HEADERS")
assert result == {"Env-Header": "env-value"}
def test_resolve_extra_headers_unset_returns_none(monkeypatch) -> None:
monkeypatch.delenv("ANTHROPIC_TARGET_API_HEADERS", raising=False)
assert resolve_extra_headers(None, "ANTHROPIC_TARGET_API_HEADERS") is None
def test_resolve_extra_headers_invalid_json_raises(monkeypatch) -> None:
with pytest.raises(ValueError):
resolve_extra_headers("not json", "ANTHROPIC_TARGET_API_HEADERS")
def test_resolve_extra_headers_non_object_raises(monkeypatch) -> None:
with pytest.raises(ValueError):
resolve_extra_headers('["a", "b"]', "ANTHROPIC_TARGET_API_HEADERS")
def test_resolve_extra_headers_non_string_value_raises(monkeypatch) -> None:
with pytest.raises(ValueError):
resolve_extra_headers('{"Key": 123}', "ANTHROPIC_TARGET_API_HEADERS")