fix(api-manager): allow empty combo restrictions - #10066
diegosouzapw merged 3 commits into
Conversation
Represent unrestricted Combo access explicitly as combo/* so an empty Allowed Combos list can deny every Combo without affecting direct model routes. Preserve existing keys through migration 149 and cover Dashboard, policy, routing-target, and migration behavior.
|
Good fix — empty combo restrictions now mean "no restriction". Could you confirm the real diff via merge-base (the +286 may include regeneration) and that a test covers the empty-allowlist case? Otherwise mergeable. |
…nager-empty-combo-allowlist # Conflicts: # scripts/check/check-migration-numbering.mjs # src/app/(dashboard)/dashboard/api-manager/ApiManagerPageClient.tsx # src/lib/db/apiKeys.ts # tests/unit/api-manager-page-static.test.ts # tests/unit/check-migration-numbering.test.ts
Merging release/v3.8.50 forward landed 149_api_key_combo_access.sql, bumping the real migration count from 148 to 149. Updates README.md, AGENTS.md, llm.txt (root + all 42 i18n mirrors, exact-copy requirement) so the strict docs-counts-sync gate matches the live count again. Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
|
✅ Evidência de merge-train antes do merge #10066 foi embarcada no train combinado Modo FAST verde: typecheck, file-size, complexidade ciclomática e cognitiva, changelog integrity, testes alterados e Vitest. A suíte full da release continua sendo executada separadamente no tip acumulado. Obrigado @xz-dev pela contribuição; o PR segue para merge serializado em |
b082d07
into
diegosouzapw:release/v3.8.50
* fix(api-manager): allow empty combo restrictions Represent unrestricted Combo access explicitly as combo/* so an empty Allowed Combos list can deny every Combo without affecting direct model routes. Preserve existing keys through migration 149 and cover Dashboard, policy, routing-target, and migration behavior. * docs: sync migration count to 149 after api-key combo-access migration Merging release/v3.8.50 forward landed 149_api_key_combo_access.sql, bumping the real migration count from 148 to 149. Updates README.md, AGENTS.md, llm.txt (root + all 42 i18n mirrors, exact-copy requirement) so the strict docs-counts-sync gate matches the live count again. Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com> --------- Co-authored-by: adevwithpurpose <adevwithpurpose@users.noreply.github.com> Co-authored-by: xz-dev <xz-dev@users.noreply.github.com> Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
Summary
combo/*; an emptyallowedCombosarray now denies every Combo while leaving direct model requests unaffected.combo/*so upgrades preserve their previous allow-all behavior.0 combos.Behavior
["combo/*"][]["fast-chat"]fast-chatValidation
npm run check:migration-numberinggit diff --checknpm run typecheck:core— blocked by unchanged release-base error:open-sse/config/providers/registry/deepai/index.ts:1 TS2307imports../shared, while the module is at../../sharednpm run check:dashboard-typecheck— same unchanged DeepAI baseline error, plus baseline-ratchet notices; no candidate-file TypeScript errorMigration numbering
Migration
149is used because open PR #9313 reserves147, while open PRs #10001 and #10047 reserve148. The migration-numbering stale-gap check remains active so those temporary reservations are removed when their files land.Tests added or updated
tests/e2e/api-keys-flow.spec.tstests/unit/api-key-policy.test.tstests/unit/api-manager-page-static.test.tstests/unit/migration-149-api-key-combo-access.test.tstests/unit/check-migration-numbering.test.ts