{"record":{"id":"e0fec8c25dac5b78","repo":"JuliusBrussee/caveman","slug":"compat-upstream-q-forward-headers-w","errorCode":null,"errorMessage":"compat upstream %q: forward_headers: %w","messagePattern":"compat upstream %q: forward_headers: %w","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"proxy/internal/config/config.go","lineNumber":464,"sourceCode":"\tif configured := c.BaseURL(\"bedrock\", \"\"); configured != \"\" {\n\t\treturn configured\n\t}\n\treturn fmt.Sprintf(\"https://bedrock-runtime.%s.amazonaws.com\", c.BedrockRegion())\n}\n\nfunc (c Config) validateCompat() error {\n\tfor name, upstream := range c.Compat {\n\t\tif err := openaicompat.ValidateName(name); err != nil {\n\t\t\treturn fmt.Errorf(\"compat upstream %q: %w\", name, err)\n\t\t}\n\t\tif strings.TrimSpace(upstream.BaseURL) == \"\" {\n\t\t\treturn fmt.Errorf(\"compat upstream %q: base_url is required\", name)\n\t\t}\n\t\tif err := openaicompat.ValidateBaseURL(upstream.BaseURL); err != nil {\n\t\t\treturn fmt.Errorf(\"compat upstream %q: base_url: %w\", name, err)\n\t\t}\n\t\tif err := openaicompat.ValidateForwardHeaders(upstream.ForwardHeaders); err != nil {\n\t\t\treturn fmt.Errorf(\"compat upstream %q: forward_headers: %w\", name, err)\n\t\t}\n\t\tif err := openaicompat.ValidateWireDialect(upstream.WireDialect); err != nil {\n\t\t\treturn fmt.Errorf(\"compat upstream %q: %w\", name, err)\n\t\t}\n\t}\n\treturn nil\n}\n\n// providerEnvKey maps a provider name to the BYOK environment variable that\n// holds its API key.\nvar providerEnvKey = map[string]string{\n\t\"anthropic\":         \"ANTHROPIC_API_KEY\",\n\t\"openai\":            \"OPENAI_API_KEY\",\n\t\"gemini\":            \"GEMINI_API_KEY\",\n\t\"azure_openai\":      \"AZURE_OPENAI_API_KEY\",\n\t\"openai_compatible\": \"OPENAI_COMPAT_API_KEY\",\n}\n","sourceCodeStart":446,"sourceCodeEnd":482,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/proxy/internal/config/config.go#L446-L482","documentation":"The compat upstream's forward_headers list failed openaicompat.ValidateForwardHeaders, wrapped after the \"forward_headers: \" prefix. Forward headers are passed through to the upstream verbatim, so names/values must satisfy the validator's rules (e.g. valid header names, no forbidden headers).","triggerScenarios":"Configuring forward_headers on a compat upstream with an entry that openaicompat.ValidateForwardHeaders rejects — e.g. an invalid header name, a forbidden/hop-by-hop header, or a malformed list element — then calling Load.","commonSituations":"Forwarding headers like Authorization or Host that are handled internally; header names with spaces or non-token characters; YAML/TOML list accidentally containing empty strings.","solutions":["Remove or correct the offending header named in the wrapped error.","Keep only safe, custom headers (e.g. \"X-Request-Id\") in forward_headers.","Consult openaicompat.ValidateForwardHeaders for the exact allowed header-name rules."],"exampleFix":"// before\nforward_headers = [\"Authorization\", \"X-Tenant\"]\n// after\nforward_headers = [\"X-Tenant\"]","handlingStrategy":"validation","validationCode":"if err := openaicompat.ValidateForwardHeaders(upstream.ForwardHeaders); err != nil {\n    return fmt.Errorf(\"compat upstream %q forward_headers invalid: %w\", name, err)\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Only forward custom application headers (X-*), never Authorization/Host/Cookie.","Ensure header names are valid HTTP tokens (no spaces).","Keep the forward_headers list minimal and reviewed."],"tags":["config","compat","headers"],"backgroundTag":"invalid-config-value","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}