Skip to content

fix(auth): enforce requireApiKey on GET /v1/models - #3085

Closed
thatssoheil wants to merge 1 commit into
decolua:masterfrom
thatssoheil:fix/2834-v1-models-auth
Closed

thatssoheil wants to merge 1 commit into
decolua:masterfrom
thatssoheil:fix/2834-v1-models-auth

Conversation

@thatssoheil

@thatssoheil thatssoheil commented Aug 6, 2026 •

Copy link
Copy Markdown

What

Enforces requireApiKey on GET /v1/models (Bearer key check via extractApiKey/isValidApiKey), closing the model-catalog leak when auth is enabled. Internal cross-instance INTERNAL_MODEL header still skips.

Closes #2834

When requireApiKey is enabled, /v1/chat and the other SSE handlers
reject requests without a valid Bearer key, but GET /v1/models served
the full model catalog to anyone who could reach the server, leaking
provider/model names and IDs. Apply the same guard (extractApiKey +
isValidApiKey) to the models list endpoint.

Part of #2834
Copilot AI lite review requested due to automatic review settings August 6, 2026 13:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@claytontavaresdan

Copy link
Copy Markdown
Contributor

Fixed: GET /v1/models now enforces requireApiKey when enabled in settings. Returns 401 with authentication_error for missing/invalid API keys. Internal cross-instance fetches (via x-9r-internal-models-fetch header) bypass the check to prevent recursive loops.

afandiaziz pushed a commit to afandiaziz/9router that referenced this pull request Aug 8, 2026
Cherry-picked from open upstream PRs (none merged upstream as of 2026-08-09):
  decolua#3078 /api/pxpipe -> LOCAL_ONLY_PATHS (defense in depth)
  decolua#3085 enforce requireApiKey on GET /v1/models
  decolua#3063 SSRF guard on search baseUrl + block default-password remote login
  decolua#3081 inject stream_options.include_usage for OpenAI-compatible upstreams
  decolua#3083 read cached_tokens from nested prompt_tokens_details

Verified: no test regressions vs v0.5.50 baseline (88 pre-existing
failures unchanged); +21 new passing tests.
@thatssoheil

Copy link
Copy Markdown
Author

Closing as superseded: maintainer claytontavaresdan already enforced requireApiKey on GET /v1/models in #3166, with a richer extractApiKey (Bearer, x-api-key, x-goog-api-key, ?key=) plus the #3115 enabled-models fix. No action needed on this one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

REQUIRE_API_KEY documented in README is never read — no enforcement on internet-exposed deploys

3 participants