fix(auth): enforce requireApiKey on GET /v1/models - #3085
Closed
thatssoheil wants to merge 1 commit into
Closed
thatssoheil wants to merge 1 commit into
thatssoheil wants to merge 1 commit into
Conversation
When requireApiKey is enabled, /v1/chat and the other SSE handlers reject requests without a valid Bearer key, but GET /v1/models served the full model catalog to anyone who could reach the server, leaking provider/model names and IDs. Apply the same guard (extractApiKey + isValidApiKey) to the models list endpoint. Part of #2834
Contributor
|
Fixed: GET /v1/models now enforces |
afandiaziz
pushed a commit
to afandiaziz/9router
that referenced
this pull request
Aug 8, 2026
Cherry-picked from open upstream PRs (none merged upstream as of 2026-08-09): decolua#3078 /api/pxpipe -> LOCAL_ONLY_PATHS (defense in depth) decolua#3085 enforce requireApiKey on GET /v1/models decolua#3063 SSRF guard on search baseUrl + block default-password remote login decolua#3081 inject stream_options.include_usage for OpenAI-compatible upstreams decolua#3083 read cached_tokens from nested prompt_tokens_details Verified: no test regressions vs v0.5.50 baseline (88 pre-existing failures unchanged); +21 new passing tests.
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Enforces requireApiKey on GET /v1/models (Bearer key check via extractApiKey/isValidApiKey), closing the model-catalog leak when auth is enabled. Internal cross-instance INTERNAL_MODEL header still skips.
Closes #2834