Skip to content

Ship platform.claude.com in bank/anthropic's allowlist - #113

Merged
lpezet merged 1 commit into
release/1.14.2from
fix/anthropic-platform-host
Aug 17, 2026
Merged

lpezet merged 1 commit into
release/1.14.2from
fix/anthropic-platform-host

Conversation

@lpezet

@lpezet lpezet commented Aug 17, 2026

Copy link
Copy Markdown
Owner

Closes #112.

What was wrong

bank/anthropic/allowlist permitted one destination. Claude Code 2.x calls
GET platform.claude.com/v1/oauth/hello at startup and treats failing it as
fatal — so installing the entry gave a lab where the credential was injected
correctly and the agent would not start.

Verified before changing anything

  • platform.claude.com is Anthropic-owned (cert CN = platform.claude.com) and
    /v1/oauth/hello returns 200 unauthenticated — checked directly. It is a
    reach-only destination, not a credentialed one.
  • bank/anthropic/proxy/anthropic.py gates on flow.request.host != "api.anthropic.com"
    — an exact comparison, in both request and responseheaders. Allowlisting
    this host therefore cannot cause injection, by construction rather than by
    convention. That is what makes "allowlist, not hosts" the right call and not
    just the conservative one.
  • Suite E enforces hosts ⊆ allowlist and never the reverse, so the addition is
    in the permitted direction. tests/run.sh: 17 suites, all pass.

The issue's other candidate

raw.githubusercontent.com needs no decision — it is already in
bank/github/allowlist:29 under OPTIONAL, alongside codeload and
objects.githubusercontent.com. That is its correct home: it is GitHub egress,
and it is multi-tenant, so it has no business in an Anthropic entry.

PLAYBOOK

"Three things belong in the allowlist that are not in hosts" becomes four. The
new category — the client's own startup checks, which are rarely on the API host
— is the one most likely to be missed, because the failure does not present as
an egress failure: the message names the proxy, so it reads as a credential or
TLS problem. The section now says to find these by running the client once and
reading the blocked lines out of the trail, rather than reasoning from the
vendor's API docs, which describe the API and not the client.

No new test

The regression this would guard against is "a vendor's client needs a host the
entry does not list", which is empirical, not structural — the lint derives
everything else from the manifests, and hardcoding a vendor hostname into the
suite would be the first exception to that. bank/anthropic/allowlist carries
the reasoning inline instead, including why editing the file is not enough on
its own (the proxy reads it once at startup, so it needs
up -d --force-recreate proxy).

Not affected

examples/claude-code mounts no allowlist — the line is commented out in its
compose.yaml, so it runs permissive.

🤖 Generated with Claude Code

https://claude.ai/code/session_01K7ZLAqx3456HP7BAY9gmqA

Claude Code 2.x makes a startup connectivity check against
platform.claude.com and treats failure as fatal, so an entry listing only
api.anthropic.com installs cleanly, injects its credential correctly, and
still leaves an agent that refuses to start.

Allowlist and not `hosts`: the endpoint answers 200 unauthenticated, so it
is a destination the agent must reach rather than one the credential should
be attached to. The addon compares `flow.request.host` to
"api.anthropic.com" exactly, so this cannot widen where a token is sent.

PLAYBOOK's "things that belong in the allowlist and not in `hosts`" gains
this as a fourth category — the client's own startup checks, which are
rarely on the API host and are the one category that does not look like an
egress failure when missed. What the user sees names the proxy, so it reads
as a credential or TLS problem; the `blocked` line in the trail is what says
otherwise.

raw.githubusercontent.com, the issue's other candidate, needs nothing: it is
already in bank/github/allowlist under OPTIONAL, which is its correct home.

Closes #112

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01K7ZLAqx3456HP7BAY9gmqA
@lpezet
lpezet merged commit 3947445 into release/1.14.2 Aug 17, 2026
4 checks passed
@lpezet lpezet mentioned this pull request Aug 17, 2026
@lpezet
lpezet deleted the fix/anthropic-platform-host branch August 17, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant