From fab534b5033a678ca0416713f617690486d528e7 Mon Sep 17 00:00:00 2001 From: kshitijk4poor <82637225+kshitijk4poor@users.noreply.github.com> Date: Wed, 26 Aug 2026 12:38:28 +0530 Subject: [PATCH] fix: omit User-Agent from anonymous OpenViking identity probes Anonymous probes (_anonymous_json) are designed to probe server identity before disclosing credentials. Sending the Hermes version on these probes would fingerprint the exact version to an untrusted/MITM endpoint. Keep User-Agent on authenticated requests (_headers) and multipart uploads (_multipart_headers), which already send credentials. --- plugins/memory/openviking/__init__.py | 5 +--- .../memory/test_openviking_provider.py | 26 +++---------------- 2 files changed, 5 insertions(+), 26 deletions(-) diff --git a/plugins/memory/openviking/__init__.py b/plugins/memory/openviking/__init__.py index 996928d32b..de29838187 100644 --- a/plugins/memory/openviking/__init__.py +++ b/plugins/memory/openviking/__init__.py @@ -487,10 +487,7 @@ class _VikingClient: """Probe server identity without disclosing credentials or tenant IDs.""" resp = self._httpx.get( self._url(path), - headers={ - "Accept": "application/json", - "User-Agent": _OPENVIKING_USER_AGENT, - }, + headers={"Accept": "application/json"}, timeout=3.0, ) return self._parse_response(resp) diff --git a/tests/plugins/memory/test_openviking_provider.py b/tests/plugins/memory/test_openviking_provider.py index 3c6d03143e..29acdc00ee 100644 --- a/tests/plugins/memory/test_openviking_provider.py +++ b/tests/plugins/memory/test_openviking_provider.py @@ -847,7 +847,6 @@ def test_openviking_identity_probes_are_anonymous_before_authenticated_requests( ] expected_anonymous_headers = { "Accept": "application/json", - "User-Agent": _EXPECTED_USER_AGENT, } assert calls[0][1] == expected_anonymous_headers assert calls[1][1] == expected_anonymous_headers @@ -881,14 +880,8 @@ def test_repeated_openviking_health_probes_never_send_credentials_or_tenant_head assert client.health() is True assert client.health() is True assert captured_headers == [ - { - "Accept": "application/json", - "User-Agent": _EXPECTED_USER_AGENT, - }, - { - "Accept": "application/json", - "User-Agent": _EXPECTED_USER_AGENT, - }, + {"Accept": "application/json"}, + {"Accept": "application/json"}, ] @@ -925,7 +918,6 @@ def test_cloud_health_retries_with_api_key_after_anonymous_auth_error(monkeypatc assert client.health() is True assert calls[0] == { "Accept": "application/json", - "User-Agent": _EXPECTED_USER_AGENT, } assert "Authorization" in calls[1] assert calls[1]["Authorization"].startswith("Bearer account.user.") @@ -960,12 +952,7 @@ def test_cloud_health_does_not_send_key_without_api_key(monkeypatch): with pytest.raises(openviking_module._OpenVikingHTTPError): client.health_payload() - assert calls == [ - { - "Accept": "application/json", - "User-Agent": _EXPECTED_USER_AGENT, - } - ] + assert calls == [{"Accept": "application/json"}] def test_health_non_auth_errors_do_not_retry_with_credentials(monkeypatch): @@ -988,12 +975,7 @@ def test_health_non_auth_errors_do_not_retry_with_credentials(monkeypatch): with pytest.raises(openviking_module._OpenVikingHTTPError): client.health_payload() - assert calls == [ - { - "Accept": "application/json", - "User-Agent": _EXPECTED_USER_AGENT, - } - ] + assert calls == [{"Accept": "application/json"}] def test_modern_openviking_identity_does_not_probe_openapi():