Skip to content

fix(api): route provider-model handlers through management auth - #15479

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
lorenzozanee:fix/provider-model-management-auth
Oct 6, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
lorenzozanee:fix/provider-model-management-auth

Conversation

@lorenzozanee

Copy link
Copy Markdown
Contributor

Summary

All five /api/provider-models handlers now use requireManagementAuth before parsing request bodies or accessing model state. The reported admin-key 401 remains unverified: the same request passed on the base commit, so this change aligns the route with the centralized management guard but does not establish the deployment failure's cause.

Related Issues

Fixes #15405

Validation

  • Change type: provider
  • Focused tests and category gates from the golden path
  • npm run lint
  • Reconciled with the current active release base; focused checks rerun afterward
  • Production-code changes include a new or updated automated test in this PR
  • SonarQube is temporarily opt-in while the private project has no quota; it is not a PR gate.

Focused route/auth tests passed (61 tests), management-auth hardening passed (13 tests), API route typecheck passed against its frozen baseline, and formatting plus ESLint checks passed on the checked files. Full CI and the production deployment reproduction were not run.

Tests Added Or Updated

  • tests/unit/provider-models-management-auth-contract.test.mjs
  • tests/unit/provider-models-management-route.test.ts

Coverage Notes

Coverage change was not measured.

Reviewer Notes

The repository's bug-fix policy calls for a failing-then-passing test or a documented production test. Neither is available here because the admin-key request also passes on the base; the reported deployment-specific 401 and its cause remain unknown. The focused API typecheck reports 276 diagnostics within the upstream frozen baseline.

@diegosouzapw
diegosouzapw merged commit 4d470c7 into diegosouzapw:release/v3.8.52 Oct 6, 2026
43 of 51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(auth): accept management API keys on provider-model routes

2 participants