fix: omit User-Agent from anonymous OpenViking identity probes

Anonymous probes (_anonymous_json) are designed to probe server identity
before disclosing credentials. Sending the Hermes version on these probes
would fingerprint the exact version to an untrusted/MITM endpoint.

Keep User-Agent on authenticated requests (_headers) and multipart uploads
(_multipart_headers), which already send credentials.
This commit is contained in:
kshitijk4poor
2026-08-26 12:38:28 +05:30
committed by kshitij
parent 3db5267008
commit fab534b503
2 changed files with 5 additions and 26 deletions
+1 -4
View File
@@ -487,10 +487,7 @@ class _VikingClient:
"""Probe server identity without disclosing credentials or tenant IDs."""
resp = self._httpx.get(
self._url(path),
headers={
"Accept": "application/json",
"User-Agent": _OPENVIKING_USER_AGENT,
},
headers={"Accept": "application/json"},
timeout=3.0,
)
return self._parse_response(resp)
@@ -847,7 +847,6 @@ def test_openviking_identity_probes_are_anonymous_before_authenticated_requests(
]
expected_anonymous_headers = {
"Accept": "application/json",
"User-Agent": _EXPECTED_USER_AGENT,
}
assert calls[0][1] == expected_anonymous_headers
assert calls[1][1] == expected_anonymous_headers
@@ -881,14 +880,8 @@ def test_repeated_openviking_health_probes_never_send_credentials_or_tenant_head
assert client.health() is True
assert client.health() is True
assert captured_headers == [
{
"Accept": "application/json",
"User-Agent": _EXPECTED_USER_AGENT,
},
{
"Accept": "application/json",
"User-Agent": _EXPECTED_USER_AGENT,
},
{"Accept": "application/json"},
{"Accept": "application/json"},
]
@@ -925,7 +918,6 @@ def test_cloud_health_retries_with_api_key_after_anonymous_auth_error(monkeypatc
assert client.health() is True
assert calls[0] == {
"Accept": "application/json",
"User-Agent": _EXPECTED_USER_AGENT,
}
assert "Authorization" in calls[1]
assert calls[1]["Authorization"].startswith("Bearer account.user.")
@@ -960,12 +952,7 @@ def test_cloud_health_does_not_send_key_without_api_key(monkeypatch):
with pytest.raises(openviking_module._OpenVikingHTTPError):
client.health_payload()
assert calls == [
{
"Accept": "application/json",
"User-Agent": _EXPECTED_USER_AGENT,
}
]
assert calls == [{"Accept": "application/json"}]
def test_health_non_auth_errors_do_not_retry_with_credentials(monkeypatch):
@@ -988,12 +975,7 @@ def test_health_non_auth_errors_do_not_retry_with_credentials(monkeypatch):
with pytest.raises(openviking_module._OpenVikingHTTPError):
client.health_payload()
assert calls == [
{
"Accept": "application/json",
"User-Agent": _EXPECTED_USER_AGENT,
}
]
assert calls == [{"Accept": "application/json"}]
def test_modern_openviking_identity_does_not_probe_openapi():