feat(ai-gateway): list and route virtual models in providers snapshot - #6738
Conversation
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commit adds Files Reviewed (6 files)
Previous Review Summaries (4 snapshots, latest commit 9fb5d00)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 9fb5d00)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commit routes virtual routers through the organization's allowed real providers and strips the snapshot-only Files Reviewed (6 files)
Previous review (commit 091c204)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commit adds Files Reviewed (3 files)
Previous review (commit 9f744f8)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commit resolves the prior alias-prefix finding by gating the alias branch on Files Reviewed (4 files)
Previous review (commit 2ef5df6)Status: 3 Issues Found | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (4 files)
Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
…-models # Conflicts: # apps/web/src/app/api/openrouter/[...path]/route.ts
| : [...decision.eligibleProviderRoutes]; | ||
| const only = withoutVirtualProvider( | ||
| currentOnly | ||
| ? currentOnly.filter(route => decision.eligibleProviderRoutes?.has(route)) |
There was a problem hiding this comment.
bot: Member-granted providers outside the organization list are filtered out
Suggested fix: When an effective member-policy decision supplies eligible routes, do not intersect those routes with the legacy Enterprise providerConfig.only list. This handler currently narrows the member grant to that list and returns a denial when the two sets do not overlap, although the PR says member provider grants may exceed the organization ceiling. Apply the same correction to the TypeSafe handler while preserving the provider privacy settings.
There was a problem hiding this comment.
I will consider this
There was a problem hiding this comment.
Summary
The Providers & Models snapshot (
models_by_provider.data) is built from OpenRouter's per-provider model lists. Models without a provider of their own therefore never made it in, even though/api/openrouter/modelslists them. That covers latest aliases such as~anthropic/claude-sonnet-latestand routers such astypesafe/jev-routerandopenrouter/auto. The result was that Enterprise orgs could not see them on the Providers & Models page, and requests for them were always denied as "not in current snapshot".Snapshot. During sync,
injectVirtualModels(virtual-models.ts) adds every OpenRouter catalog model that no provider lists:~ids with analias_target) go under each provider that serves the standard variant of the target. They copy that provider's pricing and data policy, so provider allow lists, routing and data-collection checks treat an alias like its target.virtualprovider with display name "Virtual". It uses catalog pricing; free routers are marked as potentially training.formatPricenow renders the-1router price asVaries.Model access. A router picks a real provider per request. When an allow list (the org provider ceiling, or a member provider grant) includes
virtual, a router's eligible routes arevirtualplus the real providers on that same list (getEligibleProviderRoutesinmodel-access.server.ts).organization_provider.Upstream.
virtualis a Kilo-only slug and is never forwarded.withoutVirtualProviderstrips it at every point where Kilo buildsprovider.only:checkOrganizationModelRestrictions, which is used by the embeddings, transcription, TypeSafe, FIM and edit handlers;onlylists inllm-proxy,embeddingsand the TypeSafe handler.A router therefore only reaches providers the org allows.
Live data today gives 18 aliases placed under real providers. These routers go to "Virtual":
typesafe/jev-router,openrouter/auto,openrouter/auto-beta,openrouter/free,openrouter/pareto-code,openrouter/fusion,openrouter/bodybuilder.kilo-auto/*stays out of the snapshot because it is already exempt from model restrictions.Verification
Visual Changes
N/A (new rows appear on the Providers & Models page; no layout changes).
Reviewer Notes
provider.data_collection, which the gateway sets from org settings.