fix(api): alias-backed models leak raw node UUID prefix in /v1/models (#8958) - #8961
Merged
diegosouzapw merged 2 commits intoAug 6, 2026
Conversation
…diegosouzapw#8958) The alias-backed models loop in catalog.ts built its display prefix as `providerIdToAlias[canonicalProviderId] || providerKey` and never consulted `providerIdToPrefix`, unlike the synced-models and custom-models loops. For an openai-/anthropic-compatible provider node (whose id is a UUID) the alias fell through to the raw UUID `providerKey`, so `/v1/models` published a duplicate `<node-uuid>/model` entry alongside the correct `prefix/model` one — even under MODELS_CATALOG_PREFIX_MODE=alias, because the dedupe only compared UUID-prefixed ids. Fix: resolve the display prefix through `providerIdToPrefix` first, and skip the canonical (`includeCanonical`) emit when the node has a configured prefix — mirroring the `&& !prefix` guard already used by the synced/custom loops (catalog.ts:896,1245). `owned_by` was already masked via resolvePublicOwnerId (diegosouzapw#8327); only the id leaked. Adds tests/unit/8958-alias-backed-node-prefix.test.ts covering alias, default and dual prefix modes.
Rahulsharma0810
force-pushed
the
fix/alias-backed-models-node-prefix
branch
from
July 30, 2026 07:45
106320c to
0d050a3
Compare
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
diegosouzapw
merged commit Aug 6, 2026
a9b4c3e
into
diegosouzapw:release/v3.8.50
4 of 5 checks passed
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…diegosouzapw#8958) (diegosouzapw#8961) Validated in local merge-train T5 (base49+contributors+pacocartones)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #8958. For an OpenAI-/Anthropic-compatible provider node with a custom
prefix(node id is a UUID),GET /v1/modelslisted every alias-backed model twice: the correctprefix/modelid and a duplicate raw<node-uuid>/modelid — even underMODELS_CATALOG_PREFIX_MODE=alias.Root cause
The alias-backed models loop (added in #4630) in
src/app/api/v1/models/catalog.tsbuilt its display prefix without consultingproviderIdToPrefix:For a compatible node,
canonicalProviderIdis the UUID andproviderIdToAlias[<uuid>]is undefined, soaliasfell through to the raw UUIDproviderKey. The dedupe only comparedalias/modelandproviderKey/model(both UUID-prefixed), so it never matched the correctprefix/modelrow already emitted by the synced-models loop. Additionally, theincludeCanonicalbranch pushed${canonicalProviderId}/${modelId}(=<uuid>/model) in default/dual modes — a second leak.The synced-models (
catalog.ts:896) and custom-models (catalog.ts:1245) loops already handle this correctly viaconst prefix = providerIdToPrefix[...]and a&& !prefixguard on their canonical push.owned_bywas also already masked byresolvePublicOwnerId(#8327) — only the published id leaked.Fix
Mirror the sibling loops in the alias-backed block:
and add
&& !nodePrefixto theincludeCanonicalemit guard. The id collapses toprefix/model, which the existing dedupe skips; the canonical UUID row is no longer emitted for prefixed nodes.Tests
Adds
tests/unit/8958-alias-backed-node-prefix.test.ts(real-DB harness, same style as the #8327 test):prefix/model, no UUID-prefixed id anywhereprefix/modelpresent, no<node-uuid>/…idVerified locally:
8327-models-owned-by-prefix.test.ts: 3/3 passmodels-catalog-route,models-catalog-hide-paid,catalog-helpers-extraction,cc-compatible-model-catalog,model-alias-provider-resolution: 69/69 passAlso validated against a live instance running the equivalent patch:
?prefix=aliasand default/dual drop the duplicate UUID entries while retaining the correctprefix/rows;?prefix=canonicalis unchanged; routing via both the alias and theprefix/…id is unaffected.