fix: SGL provider - send Authorization header on streaming requests - #3307
Conversation
The streaming entry points (ChatCompletionStream, TextCompletionStream) passed nil for the authHeader parameter to the shared OpenAI streaming helpers, so no Authorization header was attached to outbound streaming requests. SGLang servers configured with --api-key always require the header and returned 401 on streaming while non-streaming requests worked. The non-streaming OpenAI helper takes the Key directly and builds the header itself; the streaming helper requires the caller to build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and construct the auth header from key.Value when set. Affected packages: - core/providers/sgl/sgl.go - build authHeader for both streaming paths - core/providers/sgl/chat_test.go - regression tests asserting the Authorization header reaches the upstream on chat and text streams - core/changelog.md - changelog entry
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe PR ensures SGL streaming endpoints send ChangesSGL Streaming Authorization Header Fix
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related issues
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Confidence Score: 4/5The streaming auth fix is correct and well-tested; the only blocker is that the changelog file was accidentally emptied instead of having a new entry prepended. The core change in sgl.go is a straightforward, well-precedented fix that correctly mirrors the vLLM pattern and is covered by two new regression tests. The changelog file, however, was left completely empty — all 23 existing release-history entries were removed and no new fix entry was added — which is a concrete data-loss issue that needs to be corrected before merging. core/changelog.md — all existing entries deleted, new fix entry missing. Important Files Changed
Reviews (3): Last reviewed commit: "Merge branch 'dev' into fix/sgl-streamin..." | Re-trigger Greptile |
The drain goroutines spawned to consume streamChan in
TestChatCompletionStream_SetsAuthorizationHeader and
TestTextCompletionStream_SetsAuthorizationHeader had no cancellation
path: if the streaming pipeline failed to close the channel (e.g. on a
test timeout), the goroutines would leak into the test process.
Replace the inline `go func() { for range streamChan {} }()` with a
shared drainStream helper that selects on both the channel and a `done`
channel closed via t.Cleanup, so the goroutine always exits when the
test completes regardless of channel state.
Addresses Greptile review feedback on PR maximhq#3307.
The base branch was changed.
|
|
## Summary This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. ## Changes - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions ## Type of change - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh # Core/Transports go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes #3906 Closes #3307 Closes #3903 ## Security considerations These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
…3307) * [fix]: SGL provider - send Authorization header on streaming requests The streaming entry points (ChatCompletionStream, TextCompletionStream) passed nil for the authHeader parameter to the shared OpenAI streaming helpers, so no Authorization header was attached to outbound streaming requests. SGLang servers configured with --api-key always require the header and returned 401 on streaming while non-streaming requests worked. The non-streaming OpenAI helper takes the Key directly and builds the header itself; the streaming helper requires the caller to build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and construct the auth header from key.Value when set. Affected packages: - core/providers/sgl/sgl.go - build authHeader for both streaming paths - core/providers/sgl/chat_test.go - regression tests asserting the Authorization header reaches the upstream on chat and text streams - core/changelog.md - changelog entry * [fix]: SGL streaming tests - cancel drain goroutine on test completion The drain goroutines spawned to consume streamChan in TestChatCompletionStream_SetsAuthorizationHeader and TestTextCompletionStream_SetsAuthorizationHeader had no cancellation path: if the streaming pipeline failed to close the channel (e.g. on a test timeout), the goroutines would leak into the test process. Replace the inline `go func() { for range streamChan {} }()` with a shared drainStream helper that selects on both the channel and a `done` channel closed via t.Cleanup, so the goroutine always exits when the test completes regardless of channel state. Addresses Greptile review feedback on PR #3307. --------- Co-authored-by: Akshay Deo <akshay@akshaydeo.com>
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
* removes from_memory for APIs * docker scout fixes (#3900) * test fixes for hardened runners (#3780) * fix: SGL provider - send Authorization header on streaming requests (#3307) * [fix]: SGL provider - send Authorization header on streaming requests The streaming entry points (ChatCompletionStream, TextCompletionStream) passed nil for the authHeader parameter to the shared OpenAI streaming helpers, so no Authorization header was attached to outbound streaming requests. SGLang servers configured with --api-key always require the header and returned 401 on streaming while non-streaming requests worked. The non-streaming OpenAI helper takes the Key directly and builds the header itself; the streaming helper requires the caller to build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and construct the auth header from key.Value when set. Affected packages: - core/providers/sgl/sgl.go - build authHeader for both streaming paths - core/providers/sgl/chat_test.go - regression tests asserting the Authorization header reaches the upstream on chat and text streams - core/changelog.md - changelog entry * [fix]: SGL streaming tests - cancel drain goroutine on test completion The drain goroutines spawned to consume streamChan in TestChatCompletionStream_SetsAuthorizationHeader and TestTextCompletionStream_SetsAuthorizationHeader had no cancellation path: if the streaming pipeline failed to close the channel (e.g. on a test timeout), the goroutines would leak into the test process. Replace the inline `go func() { for range streamChan {} }()` with a shared drainStream helper that selects on both the channel and a `done` channel closed via t.Cleanup, so the goroutine always exits when the test completes regardless of channel state. Addresses Greptile review feedback on PR #3307. --------- Co-authored-by: Akshay Deo <akshay@akshaydeo.com> * ollama streaming auth header (#3906) ## Summary Adds Bearer token authentication support to the Ollama provider's streaming endpoints. Previously, the streaming methods for text completion and chat completion always passed `nil` for the auth header, meaning API keys configured for Ollama were silently ignored during streaming requests. ## Issues Closes #3905 ## Changes - When a non-empty key value is present, a `Bearer` token `Authorization` header is now constructed and passed to the OpenAI-compatible streaming handlers for both `TextCompletionStream` and `ChatCompletionStream` - If no key is configured, the auth header remains `nil`, preserving backward compatibility with unauthenticated local Ollama instances ## Type of change - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [x] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [ ] Docs ## How to test Configure an Ollama provider with an API key (e.g., when using a hosted or authenticated Ollama instance) and issue a streaming chat or text completion request. Verify the `Authorization: Bearer <key>` header is included in the outgoing request. ```sh go test ./core/providers/ollama/... ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues ## Security considerations API keys are now correctly forwarded as Bearer tokens in streaming requests to Ollama. Ensure keys are stored and retrieved securely via the existing key management mechanism, as they will now be included in outbound HTTP headers for streaming calls. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [ ] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Ollama streaming requests now support authentication via bearer tokens for both text and chat completions, enabling proper token-based authentication when API keys are provided. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3906?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * 1.5.7 changelogs (#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes #3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable --------- Co-authored-by: Hen Sapir <hen@sapir.me>
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
* docker scout fixes (#3900) * 1.5.7 changelogs (#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes #3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable * enterprise changelog (#3912) ## Summary Adds the Enterprise v1.4.6 changelog entry to the documentation site and registers it in the docs navigation. ## Changes - Added `docs/changelogs/ent-v1.4.6.mdx` documenting the v1.4.6 release, which is a security and hardening release based on `transports/v1.5.7`. Key highlights include: - **DAC bypass fix**: `from_memory` query paths and shared filter-data caches were bypassing data-access scope enforcement, allowing scoped callers to observe virtual keys, teams, routing rules, and log dimensions belonging to other users. All read paths now apply the caller's DAC scope, and MCP clients no longer leak hidden virtual key IDs. - **DAC scope coverage expanded**: Added DAC wrappers for `GetVirtualKeys`, `GetRoutingRules`, `GetRoutingRulesByScope`, `GetRoutingRule`, and MCP virtual-key config lookups by client ID. - **DAC bypass regression suite**: New end-to-end Postman collection covering `from_memory` list endpoints, hidden virtual key/team detail access, log and MCP filter-data cache isolation, and MCP client assignment leakage. - **CVE remediation**: Updated `golang.org/x` packages (`crypto`, `net`, `sys`, `text`, `term`) clearing 20 advisories with severity up to 10.0, verified with `govulncheck`. - **Hardened container image**: Removed standalone GNU `wget` from the Alpine runtime image, eliminating CVE-2025-69194 (8.8); healthcheck now uses busybox `wget`. - **Ollama and SGL streaming auth fixes**: Both providers now correctly forward `Authorization: Bearer` headers on streaming requests. - **Governance model availability fix**: Access profile evaluation now correctly enforces model availability checks during budget constraint validation across managed and non-managed governance paths. - **Governance and Logging list API cleanup**: Removed the `from_memory` query parameter; list APIs now return consistent DB-backed results with batch-fetched virtual-key names. - Registered `changelogs/ent-v1.4.6` as the first entry in the Enterprise changelogs section of `docs/docs.json`. ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [x] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [x] Docs ## How to test Navigate to the Enterprise changelogs section of the documentation site and confirm that the v1.4.6 entry appears at the top of the list and renders correctly, including the breaking-change warning, feature/fix sections, and dependency tables. ## Breaking changes - [x] Yes - [ ] No v1.4.0 introduced breaking changes. Upgraders should follow the [v1.4.0 Migration Guide](https://docs.example.com/enterprise/migration-guides/v1.4.0) before upgrading to v1.4.6. ## Security considerations This release closes a DAC bypass that allowed scoped callers to read virtual keys, teams, routing rules, and log dimensions belonging to other users via `from_memory` query paths and shared filter-data caches. It also remediates 20 CVEs in `golang.org/x` dependencies (max severity 10.0) and removes a vulnerable `wget` binary (CVE-2025-69194, 8.8) from the container image. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Added Enterprise v1.4.6 release notes documenting a security-focused release with hardening improvements and critical updates. * Updates include security remediation, governance and model validation enhancements, container image improvements, and authentication updates for supported streaming services. * Removed deprecated parameter from governance and logging APIs. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3912?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
* removes from_memory for APIs * docker scout fixes (maximhq#3900) * test fixes for hardened runners (maximhq#3780) * fix: SGL provider - send Authorization header on streaming requests (maximhq#3307) * [fix]: SGL provider - send Authorization header on streaming requests The streaming entry points (ChatCompletionStream, TextCompletionStream) passed nil for the authHeader parameter to the shared OpenAI streaming helpers, so no Authorization header was attached to outbound streaming requests. SGLang servers configured with --api-key always require the header and returned 401 on streaming while non-streaming requests worked. The non-streaming OpenAI helper takes the Key directly and builds the header itself; the streaming helper requires the caller to build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and construct the auth header from key.Value when set. Affected packages: - core/providers/sgl/sgl.go - build authHeader for both streaming paths - core/providers/sgl/chat_test.go - regression tests asserting the Authorization header reaches the upstream on chat and text streams - core/changelog.md - changelog entry * [fix]: SGL streaming tests - cancel drain goroutine on test completion The drain goroutines spawned to consume streamChan in TestChatCompletionStream_SetsAuthorizationHeader and TestTextCompletionStream_SetsAuthorizationHeader had no cancellation path: if the streaming pipeline failed to close the channel (e.g. on a test timeout), the goroutines would leak into the test process. Replace the inline `go func() { for range streamChan {} }()` with a shared drainStream helper that selects on both the channel and a `done` channel closed via t.Cleanup, so the goroutine always exits when the test completes regardless of channel state. Addresses Greptile review feedback on PR maximhq#3307. --------- Co-authored-by: Akshay Deo <akshay@akshaydeo.com> * ollama streaming auth header (maximhq#3906) ## Summary Adds Bearer token authentication support to the Ollama provider's streaming endpoints. Previously, the streaming methods for text completion and chat completion always passed `nil` for the auth header, meaning API keys configured for Ollama were silently ignored during streaming requests. ## Issues Closes maximhq#3905 ## Changes - When a non-empty key value is present, a `Bearer` token `Authorization` header is now constructed and passed to the OpenAI-compatible streaming handlers for both `TextCompletionStream` and `ChatCompletionStream` - If no key is configured, the auth header remains `nil`, preserving backward compatibility with unauthenticated local Ollama instances ## Type of change - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [x] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [ ] Docs ## How to test Configure an Ollama provider with an API key (e.g., when using a hosted or authenticated Ollama instance) and issue a streaming chat or text completion request. Verify the `Authorization: Bearer <key>` header is included in the outgoing request. ```sh go test ./core/providers/ollama/... ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues ## Security considerations API keys are now correctly forwarded as Bearer tokens in streaming requests to Ollama. Ensure keys are stored and retrieved securely via the existing key management mechanism, as they will now be included in outbound HTTP headers for streaming calls. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [ ] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Ollama streaming requests now support authentication via bearer tokens for both text and chat completions, enabling proper token-based authentication when API keys are provided. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3906?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * 1.5.7 changelogs (maximhq#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (maximhq#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes maximhq#3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable --------- Co-authored-by: Hen Sapir <hen@sapir.me>
* docker scout fixes (maximhq#3900) * 1.5.7 changelogs (maximhq#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (maximhq#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes maximhq#3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable * enterprise changelog (maximhq#3912) ## Summary Adds the Enterprise v1.4.6 changelog entry to the documentation site and registers it in the docs navigation. ## Changes - Added `docs/changelogs/ent-v1.4.6.mdx` documenting the v1.4.6 release, which is a security and hardening release based on `transports/v1.5.7`. Key highlights include: - **DAC bypass fix**: `from_memory` query paths and shared filter-data caches were bypassing data-access scope enforcement, allowing scoped callers to observe virtual keys, teams, routing rules, and log dimensions belonging to other users. All read paths now apply the caller's DAC scope, and MCP clients no longer leak hidden virtual key IDs. - **DAC scope coverage expanded**: Added DAC wrappers for `GetVirtualKeys`, `GetRoutingRules`, `GetRoutingRulesByScope`, `GetRoutingRule`, and MCP virtual-key config lookups by client ID. - **DAC bypass regression suite**: New end-to-end Postman collection covering `from_memory` list endpoints, hidden virtual key/team detail access, log and MCP filter-data cache isolation, and MCP client assignment leakage. - **CVE remediation**: Updated `golang.org/x` packages (`crypto`, `net`, `sys`, `text`, `term`) clearing 20 advisories with severity up to 10.0, verified with `govulncheck`. - **Hardened container image**: Removed standalone GNU `wget` from the Alpine runtime image, eliminating CVE-2025-69194 (8.8); healthcheck now uses busybox `wget`. - **Ollama and SGL streaming auth fixes**: Both providers now correctly forward `Authorization: Bearer` headers on streaming requests. - **Governance model availability fix**: Access profile evaluation now correctly enforces model availability checks during budget constraint validation across managed and non-managed governance paths. - **Governance and Logging list API cleanup**: Removed the `from_memory` query parameter; list APIs now return consistent DB-backed results with batch-fetched virtual-key names. - Registered `changelogs/ent-v1.4.6` as the first entry in the Enterprise changelogs section of `docs/docs.json`. ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [x] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [x] Docs ## How to test Navigate to the Enterprise changelogs section of the documentation site and confirm that the v1.4.6 entry appears at the top of the list and renders correctly, including the breaking-change warning, feature/fix sections, and dependency tables. ## Breaking changes - [x] Yes - [ ] No v1.4.0 introduced breaking changes. Upgraders should follow the [v1.4.0 Migration Guide](https://docs.example.com/enterprise/migration-guides/v1.4.0) before upgrading to v1.4.6. ## Security considerations This release closes a DAC bypass that allowed scoped callers to read virtual keys, teams, routing rules, and log dimensions belonging to other users via `from_memory` query paths and shared filter-data caches. It also remediates 20 CVEs in `golang.org/x` dependencies (max severity 10.0) and removes a vulnerable `wget` binary (CVE-2025-69194, 8.8) from the container image. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Added Enterprise v1.4.6 release notes documenting a security-focused release with hardening improvements and critical updates. * Updates include security remediation, governance and model validation enhancements, container image improvements, and authentication updates for supported streaming services. * Removed deprecated parameter from governance and logging APIs. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3912?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
* removes from_memory for APIs * docker scout fixes (maximhq#3900) * test fixes for hardened runners (maximhq#3780) * fix: SGL provider - send Authorization header on streaming requests (maximhq#3307) * [fix]: SGL provider - send Authorization header on streaming requests The streaming entry points (ChatCompletionStream, TextCompletionStream) passed nil for the authHeader parameter to the shared OpenAI streaming helpers, so no Authorization header was attached to outbound streaming requests. SGLang servers configured with --api-key always require the header and returned 401 on streaming while non-streaming requests worked. The non-streaming OpenAI helper takes the Key directly and builds the header itself; the streaming helper requires the caller to build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and construct the auth header from key.Value when set. Affected packages: - core/providers/sgl/sgl.go - build authHeader for both streaming paths - core/providers/sgl/chat_test.go - regression tests asserting the Authorization header reaches the upstream on chat and text streams - core/changelog.md - changelog entry * [fix]: SGL streaming tests - cancel drain goroutine on test completion The drain goroutines spawned to consume streamChan in TestChatCompletionStream_SetsAuthorizationHeader and TestTextCompletionStream_SetsAuthorizationHeader had no cancellation path: if the streaming pipeline failed to close the channel (e.g. on a test timeout), the goroutines would leak into the test process. Replace the inline `go func() { for range streamChan {} }()` with a shared drainStream helper that selects on both the channel and a `done` channel closed via t.Cleanup, so the goroutine always exits when the test completes regardless of channel state. Addresses Greptile review feedback on PR maximhq#3307. --------- Co-authored-by: Akshay Deo <akshay@akshaydeo.com> * ollama streaming auth header (maximhq#3906) ## Summary Adds Bearer token authentication support to the Ollama provider's streaming endpoints. Previously, the streaming methods for text completion and chat completion always passed `nil` for the auth header, meaning API keys configured for Ollama were silently ignored during streaming requests. ## Issues Closes maximhq#3905 ## Changes - When a non-empty key value is present, a `Bearer` token `Authorization` header is now constructed and passed to the OpenAI-compatible streaming handlers for both `TextCompletionStream` and `ChatCompletionStream` - If no key is configured, the auth header remains `nil`, preserving backward compatibility with unauthenticated local Ollama instances ## Type of change - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [x] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [ ] Docs ## How to test Configure an Ollama provider with an API key (e.g., when using a hosted or authenticated Ollama instance) and issue a streaming chat or text completion request. Verify the `Authorization: Bearer <key>` header is included in the outgoing request. ```sh go test ./core/providers/ollama/... ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues ## Security considerations API keys are now correctly forwarded as Bearer tokens in streaming requests to Ollama. Ensure keys are stored and retrieved securely via the existing key management mechanism, as they will now be included in outbound HTTP headers for streaming calls. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [ ] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Ollama streaming requests now support authentication via bearer tokens for both text and chat completions, enabling proper token-based authentication when API keys are provided. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3906?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * 1.5.7 changelogs (maximhq#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (maximhq#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes maximhq#3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable --------- Co-authored-by: Hen Sapir <hen@sapir.me>
* docker scout fixes (maximhq#3900) * 1.5.7 changelogs (maximhq#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (maximhq#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes maximhq#3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable * enterprise changelog (maximhq#3912) ## Summary Adds the Enterprise v1.4.6 changelog entry to the documentation site and registers it in the docs navigation. ## Changes - Added `docs/changelogs/ent-v1.4.6.mdx` documenting the v1.4.6 release, which is a security and hardening release based on `transports/v1.5.7`. Key highlights include: - **DAC bypass fix**: `from_memory` query paths and shared filter-data caches were bypassing data-access scope enforcement, allowing scoped callers to observe virtual keys, teams, routing rules, and log dimensions belonging to other users. All read paths now apply the caller's DAC scope, and MCP clients no longer leak hidden virtual key IDs. - **DAC scope coverage expanded**: Added DAC wrappers for `GetVirtualKeys`, `GetRoutingRules`, `GetRoutingRulesByScope`, `GetRoutingRule`, and MCP virtual-key config lookups by client ID. - **DAC bypass regression suite**: New end-to-end Postman collection covering `from_memory` list endpoints, hidden virtual key/team detail access, log and MCP filter-data cache isolation, and MCP client assignment leakage. - **CVE remediation**: Updated `golang.org/x` packages (`crypto`, `net`, `sys`, `text`, `term`) clearing 20 advisories with severity up to 10.0, verified with `govulncheck`. - **Hardened container image**: Removed standalone GNU `wget` from the Alpine runtime image, eliminating CVE-2025-69194 (8.8); healthcheck now uses busybox `wget`. - **Ollama and SGL streaming auth fixes**: Both providers now correctly forward `Authorization: Bearer` headers on streaming requests. - **Governance model availability fix**: Access profile evaluation now correctly enforces model availability checks during budget constraint validation across managed and non-managed governance paths. - **Governance and Logging list API cleanup**: Removed the `from_memory` query parameter; list APIs now return consistent DB-backed results with batch-fetched virtual-key names. - Registered `changelogs/ent-v1.4.6` as the first entry in the Enterprise changelogs section of `docs/docs.json`. ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [x] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [x] Docs ## How to test Navigate to the Enterprise changelogs section of the documentation site and confirm that the v1.4.6 entry appears at the top of the list and renders correctly, including the breaking-change warning, feature/fix sections, and dependency tables. ## Breaking changes - [x] Yes - [ ] No v1.4.0 introduced breaking changes. Upgraders should follow the [v1.4.0 Migration Guide](https://docs.example.com/enterprise/migration-guides/v1.4.0) before upgrading to v1.4.6. ## Security considerations This release closes a DAC bypass that allowed scoped callers to read virtual keys, teams, routing rules, and log dimensions belonging to other users via `from_memory` query paths and shared filter-data caches. It also remediates 20 CVEs in `golang.org/x` dependencies (max severity 10.0) and removes a vulnerable `wget` binary (CVE-2025-69194, 8.8) from the container image. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Added Enterprise v1.4.6 release notes documenting a security-focused release with hardening improvements and critical updates. * Updates include security remediation, governance and model validation enhancements, container image improvements, and authentication updates for supported streaming services. * Removed deprecated parameter from governance and logging APIs. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3912?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Summary
Both streaming entry points in the SGL provider —
ChatCompletionStream(core/providers/sgl/sgl.go:205) andTextCompletionStream(core/providers/sgl/sgl.go:153) — passnilfor theauthHeader map[string]stringparameter to the shared OpenAI streaming helpers (core/providers/sgl/sgl.go:217and:164). As a result, noAuthorization: Bearer <key>header is attached to outbound streaming requests.SGLang servers configured with
--api-keyalways require the header, so streaming requests fail with HTTP 401 even though non-streaming requests on the same provider work correctly.The signature mismatch between the two OpenAI helpers is the root cause:
HandleOpenAIChatCompletionRequest(core/providers/openai/openai.go:795-797), takes theKeydirectly and builds the auth header itself.HandleOpenAIChatCompletionStreaming(core/providers/openai/openai.go:936), takes a prebuiltauthHeadermap — the caller is responsible for building it.Every other openai-compatible provider builds it. vLLM is the canonical pattern (
core/providers/vllm/vllm.go:150-153forTextCompletionStreamand:203-206forChatCompletionStream):This PR applies that exact 4-line snippet to both SGL streaming methods.
Changes
core/providers/sgl/sgl.go— InChatCompletionStreamandTextCompletionStream, buildauthHeaderfromkey.Valueand pass it to the OpenAI streaming helpers, mirroring vLLM.core/providers/sgl/chat_test.go— AddTestChatCompletionStream_SetsAuthorizationHeaderandTestTextCompletionStream_SetsAuthorizationHeaderregression tests. Each spins up anhttptest.NewServerconfigured as the per-keysgl_key_config.url, captures the inboundAuthorizationheader, and asserts it equals"Bearer <key>". Verified that both tests fail onmainand pass with this fix. Required minor scaffolding for the test helper: setstreamingClientand a no-oploggeronnewTestSGLProvider, plus a smallnoopPostHookRunner.core/changelog.md—[fix]entry perdocs/contributing/raising-a-pr.mdx.Type of change
Affected areas
How to test
Unit tests (added in this PR)
Both tests pass on this branch and fail on
main.Empirical reproduction against a real SGLang backend
With a minimal config:
Before the fix:
POST /v1/chat/completionswith{"stream": false}→200 OK; upstream receivesAuthorization: Bearer <key>.POST /v1/chat/completionswith{"stream": true}→401from upstream; noAuthorizationheader sent.Same pattern for
/v1/completions(text completion).After the fix, the streaming variant matches the non-streaming behavior and returns
200 OKwith the auth header attached.Breaking changes
Related issues
None linked — happy to file one if maintainers prefer.
Security considerations
The fix sends the API key in the
Authorizationheader on streaming requests, identical to the non-streaming path and to every peer openai-compatible provider. No new secret-handling surface.Checklist
docs/contributing/README.mdand followed the guidelinesSummary by CodeRabbit