Skip to content

fix(api-manager): allow empty combo restrictions - #10066

Merged
diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.50from
xz-dev:fix/api-manager-empty-combo-allowlist
Aug 17, 2026
Merged

diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.50from
xz-dev:fix/api-manager-empty-combo-allowlist

Conversation

@xz-dev

@xz-dev xz-dev commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Let Dashboard → API Manager save Allowed Combos → Restrict with zero selected Combos.
  • Persist unrestricted Combo access explicitly as combo/*; an empty allowedCombos array now denies every Combo while leaving direct model requests unaffected.
  • Migrate legacy null/blank/malformed/empty Combo settings to combo/* so upgrades preserve their previous allow-all behavior.
  • Correct the API-key list badges: unrestricted keys show no Combo restriction badge, while deny-all keys show 0 combos.

Behavior

Saved value Meaning
["combo/*"] Allow every Combo
[] Deny every Combo
["fast-chat"] Allow only fast-chat

Validation

  • Focused unit, policy, routing-target, migration, and numbering tests: 64/64 passed
  • Focused Playwright API Manager acceptance test: 1/1 passed
  • npm run check:migration-numbering
  • git diff --check
  • Independent final review: approved after findings were repaired and re-reviewed
  • npm run typecheck:core — blocked by unchanged release-base error: open-sse/config/providers/registry/deepai/index.ts:1 TS2307 imports ../shared, while the module is at ../../shared
  • npm run check:dashboard-typecheck — same unchanged DeepAI baseline error, plus baseline-ratchet notices; no candidate-file TypeScript error

Migration numbering

Migration 149 is used because open PR #9313 reserves 147, while open PRs #10001 and #10047 reserve 148. The migration-numbering stale-gap check remains active so those temporary reservations are removed when their files land.

Tests added or updated

  • tests/e2e/api-keys-flow.spec.ts
  • tests/unit/api-key-policy.test.ts
  • tests/unit/api-manager-page-static.test.ts
  • tests/unit/migration-149-api-key-combo-access.test.ts
  • tests/unit/check-migration-numbering.test.ts

Represent unrestricted Combo access explicitly as combo/* so an empty Allowed Combos list can deny every Combo without affecting direct model routes. Preserve existing keys through migration 149 and cover Dashboard, policy, routing-target, and migration behavior.
@xz-dev
xz-dev requested a review from diegosouzapw as a code owner August 11, 2026 04:50
@diegosouzapw

Copy link
Copy Markdown
Owner

Good fix — empty combo restrictions now mean "no restriction". Could you confirm the real diff via merge-base (the +286 may include regeneration) and that a test covers the empty-allowlist case? Otherwise mergeable.

adevwithpurpose and others added 2 commits August 15, 2026 03:21
…nager-empty-combo-allowlist

# Conflicts:
#	scripts/check/check-migration-numbering.mjs
#	src/app/(dashboard)/dashboard/api-manager/ApiManagerPageClient.tsx
#	src/lib/db/apiKeys.ts
#	tests/unit/api-manager-page-static.test.ts
#	tests/unit/check-migration-numbering.test.ts
Merging release/v3.8.50 forward landed 149_api_key_combo_access.sql,
bumping the real migration count from 148 to 149. Updates README.md,
AGENTS.md, llm.txt (root + all 42 i18n mirrors, exact-copy requirement)
so the strict docs-counts-sync gate matches the live count again.

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
@diegosouzapw

Copy link
Copy Markdown
Owner

✅ Evidência de merge-train antes do merge

#10066 foi embarcada no train combinado 8ed587f50410665b2924b372e59f518e420a02bd, validado em root@192.168.0.113 (tomni-proxmox-113). O log é /srv/omniroute-train/.claude/worktrees/merge-train-20260817-085938-suite.log.

Modo FAST verde: typecheck, file-size, complexidade ciclomática e cognitiva, changelog integrity, testes alterados e Vitest. A suíte full da release continua sendo executada separadamente no tip acumulado.

Obrigado @xz-dev pela contribuição; o PR segue para merge serializado em release/v3.8.50 sob a autorização da campanha.

@diegosouzapw
diegosouzapw merged commit b082d07 into diegosouzapw:release/v3.8.50 Aug 17, 2026
26 of 27 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
* fix(api-manager): allow empty combo restrictions

Represent unrestricted Combo access explicitly as combo/* so an empty Allowed Combos list can deny every Combo without affecting direct model routes. Preserve existing keys through migration 149 and cover Dashboard, policy, routing-target, and migration behavior.

* docs: sync migration count to 149 after api-key combo-access migration

Merging release/v3.8.50 forward landed 149_api_key_combo_access.sql,
bumping the real migration count from 148 to 149. Updates README.md,
AGENTS.md, llm.txt (root + all 42 i18n mirrors, exact-copy requirement)
so the strict docs-counts-sync gate matches the live count again.

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

---------

Co-authored-by: adevwithpurpose <adevwithpurpose@users.noreply.github.com>
Co-authored-by: xz-dev <xz-dev@users.noreply.github.com>
Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants