Skip to content

fix: SGL provider - send Authorization header on streaming requests - #3307

Merged
akshaydeo merged 3 commits into
maximhq:devfrom
hensapir:fix/sgl-streaming-auth-header
May 30, 2026
Merged

fix: SGL provider - send Authorization header on streaming requests#3307
akshaydeo merged 3 commits into
maximhq:devfrom
hensapir:fix/sgl-streaming-auth-header

Conversation

@hensapir

@hensapir hensapir commented May 7, 2026

Copy link
Copy Markdown
Contributor

Summary

Both streaming entry points in the SGL provider — ChatCompletionStream (core/providers/sgl/sgl.go:205) and TextCompletionStream (core/providers/sgl/sgl.go:153) — pass nil for the authHeader map[string]string parameter to the shared OpenAI streaming helpers (core/providers/sgl/sgl.go:217 and :164). As a result, no Authorization: Bearer <key> header is attached to outbound streaming requests.

SGLang servers configured with --api-key always require the header, so streaming requests fail with HTTP 401 even though non-streaming requests on the same provider work correctly.

The signature mismatch between the two OpenAI helpers is the root cause:

  • The non-streaming helper, HandleOpenAIChatCompletionRequest (core/providers/openai/openai.go:795-797), takes the Key directly and builds the auth header itself.
  • The streaming helper, HandleOpenAIChatCompletionStreaming (core/providers/openai/openai.go:936), takes a prebuilt authHeader map — the caller is responsible for building it.

Every other openai-compatible provider builds it. vLLM is the canonical pattern (core/providers/vllm/vllm.go:150-153 for TextCompletionStream and :203-206 for ChatCompletionStream):

var authHeader map[string]string
if key.Value.GetValue() != "" {
    authHeader = map[string]string{"Authorization": "Bearer " + key.Value.GetValue()}
}

This PR applies that exact 4-line snippet to both SGL streaming methods.

Changes

  • core/providers/sgl/sgl.go — In ChatCompletionStream and TextCompletionStream, build authHeader from key.Value and pass it to the OpenAI streaming helpers, mirroring vLLM.
  • core/providers/sgl/chat_test.go — Add TestChatCompletionStream_SetsAuthorizationHeader and TestTextCompletionStream_SetsAuthorizationHeader regression tests. Each spins up an httptest.NewServer configured as the per-key sgl_key_config.url, captures the inbound Authorization header, and asserts it equals "Bearer <key>". Verified that both tests fail on main and pass with this fix. Required minor scaffolding for the test helper: set streamingClient and a no-op logger on newTestSGLProvider, plus a small noopPostHookRunner.
  • core/changelog.md[fix] entry per docs/contributing/raising-a-pr.mdx.

Type of change

  • Bug fix
  • Feature
  • Refactor
  • Documentation
  • Chore/CI

Affected areas

  • Core (Go)
  • Transports (HTTP)
  • Providers/Integrations
  • Plugins
  • UI (React)
  • Docs

How to test

Unit tests (added in this PR)

cd core
go test ./providers/sgl/... -run 'TestChatCompletionStream_SetsAuthorizationHeader|TestTextCompletionStream_SetsAuthorizationHeader' -v

Both tests pass on this branch and fail on main.

Empirical reproduction against a real SGLang backend

With a minimal config:

"sgl": {
  "keys": [{
    "name": "test",
    "value": "<the SGLang --api-key value>",
    "weight": 1,
    "models": ["my-model"],
    "sgl_key_config": { "url": "https://my-sglang-server" }
  }]
}

Before the fix:

  • POST /v1/chat/completions with {"stream": false}200 OK; upstream receives Authorization: Bearer <key>.
  • POST /v1/chat/completions with {"stream": true}401 from upstream; no Authorization header sent.

Same pattern for /v1/completions (text completion).

After the fix, the streaming variant matches the non-streaming behavior and returns 200 OK with the auth header attached.

Breaking changes

  • Yes
  • No

Related issues

None linked — happy to file one if maintainers prefer.

Security considerations

The fix sends the API key in the Authorization header on streaming requests, identical to the non-streaming path and to every peer openai-compatible provider. No new secret-handling surface.

Checklist

  • I read docs/contributing/README.md and followed the guidelines
  • I added/updated tests where appropriate
  • I updated documentation where needed
  • I verified builds succeed (Go and UI)
  • I verified the CI pipeline passes locally if applicable

Summary by CodeRabbit

  • Bug Fixes
    • Fixed SGL provider to properly send the Authorization header on streaming requests. Previously, authentication credentials were not included when using streaming for chat and text completions. This has been corrected to ensure all streaming requests are properly authenticated and maintain consistent behavior across endpoints.

Review Change Stack

The streaming entry points (ChatCompletionStream, TextCompletionStream)
passed nil for the authHeader parameter to the shared OpenAI streaming
helpers, so no Authorization header was attached to outbound streaming
requests. SGLang servers configured with --api-key always require the
header and returned 401 on streaming while non-streaming requests
worked. The non-streaming OpenAI helper takes the Key directly and
builds the header itself; the streaming helper requires the caller to
build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and
construct the auth header from key.Value when set.

Affected packages:
- core/providers/sgl/sgl.go - build authHeader for both streaming paths
- core/providers/sgl/chat_test.go - regression tests asserting the
  Authorization header reaches the upstream on chat and text streams
- core/changelog.md - changelog entry
@coderabbitai

coderabbitai Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0efc45f2-a1f0-4981-b2ad-d3e6aaea32ed

📥 Commits

Reviewing files that changed from the base of the PR and between 97cdf66 and 2fdc757.

📒 Files selected for processing (2)
  • core/changelog.md
  • core/providers/sgl/sgl.go

📝 Walkthrough

Walkthrough

The PR ensures SGL streaming endpoints send Authorization: Bearer <key> when an API key is present, updates tests/utilities to capture streaming requests, and adds a changelog entry documenting the fix.

Changes

SGL Streaming Authorization Header Fix

Layer / File(s) Summary
Core Implementation
core/providers/sgl/sgl.go
TextCompletionStream and ChatCompletionStream now build per-request authHeader maps with Authorization: Bearer <key> when key.Value is non-empty and pass them to the OpenAI streaming handlers instead of nil.
Test Utilities
core/providers/sgl/chat_test.go
Adds testLogger, a shared fasthttp.Client in newTestSGLProvider, noopPostHookRunner, drainStream, and streamCaptureServer to capture streaming requests and avoid goroutine leaks.
Regression Tests
core/providers/sgl/chat_test.go
TestChatCompletionStream_SetsAuthorizationHeader and TestTextCompletionStream_SetsAuthorizationHeader assert streaming requests include Authorization: Bearer <apiKey> and drain streams.
Documentation
core/changelog.md
Adds a changelog entry describing the streaming authorization header fix.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related issues

Suggested reviewers

  • akshaydeo
  • danpiths

Poem

I hopped through streams to find the key,
A Bearer token set for all to see,
Tests stood guard and caught the call,
Streams sing true — no headers fall. 🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely summarizes the main change: fixing the SGL provider to send the Authorization header on streaming requests, which directly matches the core issue addressed in the PR.
Description check ✅ Passed The description comprehensively covers all major template sections: summary of the problem, detailed changes across three files, type of change, affected areas, testing instructions with specific commands, security considerations, and a completed checklist.
Docstring Coverage ✅ Passed Docstring coverage is 85.71% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps

greptile-apps Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor

Confidence Score: 4/5

The streaming auth fix is correct and well-tested; the only blocker is that the changelog file was accidentally emptied instead of having a new entry prepended.

The core change in sgl.go is a straightforward, well-precedented fix that correctly mirrors the vLLM pattern and is covered by two new regression tests. The changelog file, however, was left completely empty — all 23 existing release-history entries were removed and no new fix entry was added — which is a concrete data-loss issue that needs to be corrected before merging.

core/changelog.md — all existing entries deleted, new fix entry missing.

Important Files Changed

Filename Overview
core/providers/sgl/sgl.go Adds authHeader construction to TextCompletionStream and ChatCompletionStream, mirroring the vLLM pattern exactly; fix is correct and complete.
core/providers/sgl/chat_test.go Adds two regression tests with an httptest server, buffered auth capture channel, and goroutine-safe drainStream helper; test scaffolding is solid.
core/changelog.md All 23 existing entries were deleted and no new entry was added; the file is now empty, which erases release history.

Reviews (3): Last reviewed commit: "Merge branch 'dev' into fix/sgl-streamin..." | Re-trigger Greptile

Comment thread core/providers/sgl/chat_test.go Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes May 7, 2026
The drain goroutines spawned to consume streamChan in
TestChatCompletionStream_SetsAuthorizationHeader and
TestTextCompletionStream_SetsAuthorizationHeader had no cancellation
path: if the streaming pipeline failed to close the channel (e.g. on a
test timeout), the goroutines would leak into the test process.

Replace the inline `go func() { for range streamChan {} }()` with a
shared drainStream helper that selects on both the channel and a `done`
channel closed via t.Cleanup, so the goroutine always exits when the
test completes regardless of channel state.

Addresses Greptile review feedback on PR maximhq#3307.
coderabbitai[bot]
coderabbitai Bot previously approved these changes May 7, 2026
akshaydeo
akshaydeo previously approved these changes May 30, 2026
@akshaydeo
akshaydeo changed the base branch from main to dev May 30, 2026 13:08
@akshaydeo
akshaydeo dismissed stale reviews from coderabbitai[bot] and themself May 30, 2026 13:08

The base branch was changed.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ hensapir
❌ akshaydeo
You have signed the CLA already but the status is still pending? Let us recheck it.

@akshaydeo
akshaydeo merged commit 0df89f9 into maximhq:dev May 30, 2026
3 of 5 checks passed
@akshaydeo akshaydeo mentioned this pull request May 30, 2026
18 tasks
akshaydeo added a commit that referenced this pull request May 30, 2026
## Summary

This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

## Changes

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

## Type of change

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
# Core/Transports
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Closes #3906
Closes #3307
Closes #3903

## Security considerations

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo added a commit that referenced this pull request May 30, 2026
…3307)

* [fix]: SGL provider - send Authorization header on streaming requests

The streaming entry points (ChatCompletionStream, TextCompletionStream)
passed nil for the authHeader parameter to the shared OpenAI streaming
helpers, so no Authorization header was attached to outbound streaming
requests. SGLang servers configured with --api-key always require the
header and returned 401 on streaming while non-streaming requests
worked. The non-streaming OpenAI helper takes the Key directly and
builds the header itself; the streaming helper requires the caller to
build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and
construct the auth header from key.Value when set.

Affected packages:
- core/providers/sgl/sgl.go - build authHeader for both streaming paths
- core/providers/sgl/chat_test.go - regression tests asserting the
  Authorization header reaches the upstream on chat and text streams
- core/changelog.md - changelog entry

* [fix]: SGL streaming tests - cancel drain goroutine on test completion

The drain goroutines spawned to consume streamChan in
TestChatCompletionStream_SetsAuthorizationHeader and
TestTextCompletionStream_SetsAuthorizationHeader had no cancellation
path: if the streaming pipeline failed to close the channel (e.g. on a
test timeout), the goroutines would leak into the test process.

Replace the inline `go func() { for range streamChan {} }()` with a
shared drainStream helper that selects on both the channel and a `done`
channel closed via t.Cleanup, so the goroutine always exits when the
test completes regardless of channel state.

Addresses Greptile review feedback on PR #3307.

---------

Co-authored-by: Akshay Deo <akshay@akshaydeo.com>
akshaydeo added a commit that referenced this pull request May 30, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes #3906
Closes #3307
Closes #3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@akshaydeo akshaydeo mentioned this pull request May 30, 2026
akshaydeo added a commit that referenced this pull request May 30, 2026
* removes from_memory for APIs

* docker scout fixes (#3900)

* test fixes for hardened runners (#3780)

* fix: SGL provider - send Authorization header on streaming requests (#3307)

* [fix]: SGL provider - send Authorization header on streaming requests

The streaming entry points (ChatCompletionStream, TextCompletionStream)
passed nil for the authHeader parameter to the shared OpenAI streaming
helpers, so no Authorization header was attached to outbound streaming
requests. SGLang servers configured with --api-key always require the
header and returned 401 on streaming while non-streaming requests
worked. The non-streaming OpenAI helper takes the Key directly and
builds the header itself; the streaming helper requires the caller to
build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and
construct the auth header from key.Value when set.

Affected packages:
- core/providers/sgl/sgl.go - build authHeader for both streaming paths
- core/providers/sgl/chat_test.go - regression tests asserting the
  Authorization header reaches the upstream on chat and text streams
- core/changelog.md - changelog entry

* [fix]: SGL streaming tests - cancel drain goroutine on test completion

The drain goroutines spawned to consume streamChan in
TestChatCompletionStream_SetsAuthorizationHeader and
TestTextCompletionStream_SetsAuthorizationHeader had no cancellation
path: if the streaming pipeline failed to close the channel (e.g. on a
test timeout), the goroutines would leak into the test process.

Replace the inline `go func() { for range streamChan {} }()` with a
shared drainStream helper that selects on both the channel and a `done`
channel closed via t.Cleanup, so the goroutine always exits when the
test completes regardless of channel state.

Addresses Greptile review feedback on PR #3307.

---------

Co-authored-by: Akshay Deo <akshay@akshaydeo.com>

* ollama streaming auth header (#3906)

## Summary

Adds Bearer token authentication support to the Ollama provider's streaming endpoints. Previously, the streaming methods for text completion and chat completion always passed `nil` for the auth header, meaning API keys configured for Ollama were silently ignored during streaming requests.

## Issues

Closes #3905

## Changes

- When a non-empty key value is present, a `Bearer` token `Authorization` header is now constructed and passed to the OpenAI-compatible streaming handlers for both `TextCompletionStream` and `ChatCompletionStream`
- If no key is configured, the auth header remains `nil`, preserving backward compatibility with unauthenticated local Ollama instances

## Type of change

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [x] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

Configure an Ollama provider with an API key (e.g., when using a hosted or authenticated Ollama instance) and issue a streaming chat or text completion request. Verify the `Authorization: Bearer <key>` header is included in the outgoing request.

```sh
go test ./core/providers/ollama/...
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

API keys are now correctly forwarded as Bearer tokens in streaming requests to Ollama. Ensure keys are stored and retrieved securely via the existing key management mechanism, as they will now be included in outbound HTTP headers for streaming calls.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **Bug Fixes**
  * Ollama streaming requests now support authentication via bearer tokens for both text and chat completions, enabling proper token-based authentication when API keys are provided.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3906?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* 1.5.7 changelogs (#3907)

This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes #3906
Closes #3307
Closes #3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* changelogs (#3909)

## Summary

Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet.

## Changes

- Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck`
- Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8)
- Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
# Verify no vulnerabilities remain
govulncheck ./...

# Build Docker image and confirm wget healthcheck works
docker build -f transports/Dockerfile -t gateway-test .
docker run --rm gateway-test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Closes #3900

## Security considerations

- Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0
- Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

---------

Co-authored-by: Hen Sapir <hen@sapir.me>
akshaydeo added a commit that referenced this pull request May 30, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes #3906
Closes #3307
Closes #3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo added a commit that referenced this pull request May 30, 2026
* docker scout fixes (#3900)

* 1.5.7 changelogs (#3907)

This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes #3906
Closes #3307
Closes #3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* changelogs (#3909)

## Summary

Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet.

## Changes

- Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck`
- Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8)
- Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
# Verify no vulnerabilities remain
govulncheck ./...

# Build Docker image and confirm wget healthcheck works
docker build -f transports/Dockerfile -t gateway-test .
docker run --rm gateway-test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Closes #3900

## Security considerations

- Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0
- Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

* enterprise changelog (#3912)

## Summary

Adds the Enterprise v1.4.6 changelog entry to the documentation site and registers it in the docs navigation.

## Changes

- Added `docs/changelogs/ent-v1.4.6.mdx` documenting the v1.4.6 release, which is a security and hardening release based on `transports/v1.5.7`. Key highlights include:
  - **DAC bypass fix**: `from_memory` query paths and shared filter-data caches were bypassing data-access scope enforcement, allowing scoped callers to observe virtual keys, teams, routing rules, and log dimensions belonging to other users. All read paths now apply the caller's DAC scope, and MCP clients no longer leak hidden virtual key IDs.
  - **DAC scope coverage expanded**: Added DAC wrappers for `GetVirtualKeys`, `GetRoutingRules`, `GetRoutingRulesByScope`, `GetRoutingRule`, and MCP virtual-key config lookups by client ID.
  - **DAC bypass regression suite**: New end-to-end Postman collection covering `from_memory` list endpoints, hidden virtual key/team detail access, log and MCP filter-data cache isolation, and MCP client assignment leakage.
  - **CVE remediation**: Updated `golang.org/x` packages (`crypto`, `net`, `sys`, `text`, `term`) clearing 20 advisories with severity up to 10.0, verified with `govulncheck`.
  - **Hardened container image**: Removed standalone GNU `wget` from the Alpine runtime image, eliminating CVE-2025-69194 (8.8); healthcheck now uses busybox `wget`.
  - **Ollama and SGL streaming auth fixes**: Both providers now correctly forward `Authorization: Bearer` headers on streaming requests.
  - **Governance model availability fix**: Access profile evaluation now correctly enforces model availability checks during budget constraint validation across managed and non-managed governance paths.
  - **Governance and Logging list API cleanup**: Removed the `from_memory` query parameter; list APIs now return consistent DB-backed results with batch-fetched virtual-key names.
- Registered `changelogs/ent-v1.4.6` as the first entry in the Enterprise changelogs section of `docs/docs.json`.

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [x] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [x] Docs

## How to test

Navigate to the Enterprise changelogs section of the documentation site and confirm that the v1.4.6 entry appears at the top of the list and renders correctly, including the breaking-change warning, feature/fix sections, and dependency tables.

## Breaking changes

- [x] Yes
- [ ] No

v1.4.0 introduced breaking changes. Upgraders should follow the [v1.4.0 Migration Guide](https://docs.example.com/enterprise/migration-guides/v1.4.0) before upgrading to v1.4.6.

## Security considerations

This release closes a DAC bypass that allowed scoped callers to read virtual keys, teams, routing rules, and log dimensions belonging to other users via `from_memory` query paths and shared filter-data caches. It also remediates 20 CVEs in `golang.org/x` dependencies (max severity 10.0) and removes a vulnerable `wget` binary (CVE-2025-69194, 8.8) from the container image.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

## Documentation

* Added Enterprise v1.4.6 release notes documenting a security-focused release with hardening improvements and critical updates.
* Updates include security remediation, governance and model validation enhancements, container image improvements, and authentication updates for supported streaming services.
* Removed deprecated parameter from governance and logging APIs.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3912?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo added a commit that referenced this pull request May 31, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes #3906
Closes #3307
Closes #3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Purvi09 pushed a commit to Purvi09/bifrost that referenced this pull request May 31, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo added a commit that referenced this pull request Jun 1, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes #3906
Closes #3307
Closes #3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo added a commit that referenced this pull request Jun 1, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906)
- SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes #3906
Closes #3307
Closes #3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Purvi09 pushed a commit to Purvi09/bifrost that referenced this pull request Jun 2, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@akshaydeo akshaydeo mentioned this pull request Jun 7, 2026
17 tasks
@coderabbitai coderabbitai Bot mentioned this pull request Jul 7, 2026
18 tasks
akhsaul pushed a commit to akhsaul/bifrost that referenced this pull request Aug 27, 2026
* removes from_memory for APIs

* docker scout fixes (maximhq#3900)

* test fixes for hardened runners (maximhq#3780)

* fix: SGL provider - send Authorization header on streaming requests (maximhq#3307)

* [fix]: SGL provider - send Authorization header on streaming requests

The streaming entry points (ChatCompletionStream, TextCompletionStream)
passed nil for the authHeader parameter to the shared OpenAI streaming
helpers, so no Authorization header was attached to outbound streaming
requests. SGLang servers configured with --api-key always require the
header and returned 401 on streaming while non-streaming requests
worked. The non-streaming OpenAI helper takes the Key directly and
builds the header itself; the streaming helper requires the caller to
build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and
construct the auth header from key.Value when set.

Affected packages:
- core/providers/sgl/sgl.go - build authHeader for both streaming paths
- core/providers/sgl/chat_test.go - regression tests asserting the
  Authorization header reaches the upstream on chat and text streams
- core/changelog.md - changelog entry

* [fix]: SGL streaming tests - cancel drain goroutine on test completion

The drain goroutines spawned to consume streamChan in
TestChatCompletionStream_SetsAuthorizationHeader and
TestTextCompletionStream_SetsAuthorizationHeader had no cancellation
path: if the streaming pipeline failed to close the channel (e.g. on a
test timeout), the goroutines would leak into the test process.

Replace the inline `go func() { for range streamChan {} }()` with a
shared drainStream helper that selects on both the channel and a `done`
channel closed via t.Cleanup, so the goroutine always exits when the
test completes regardless of channel state.

Addresses Greptile review feedback on PR maximhq#3307.

---------

Co-authored-by: Akshay Deo <akshay@akshaydeo.com>

* ollama streaming auth header (maximhq#3906)

## Summary

Adds Bearer token authentication support to the Ollama provider's streaming endpoints. Previously, the streaming methods for text completion and chat completion always passed `nil` for the auth header, meaning API keys configured for Ollama were silently ignored during streaming requests.

## Issues

Closes maximhq#3905

## Changes

- When a non-empty key value is present, a `Bearer` token `Authorization` header is now constructed and passed to the OpenAI-compatible streaming handlers for both `TextCompletionStream` and `ChatCompletionStream`
- If no key is configured, the auth header remains `nil`, preserving backward compatibility with unauthenticated local Ollama instances

## Type of change

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [x] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

Configure an Ollama provider with an API key (e.g., when using a hosted or authenticated Ollama instance) and issue a streaming chat or text completion request. Verify the `Authorization: Bearer <key>` header is included in the outgoing request.

```sh
go test ./core/providers/ollama/...
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

API keys are now correctly forwarded as Bearer tokens in streaming requests to Ollama. Ensure keys are stored and retrieved securely via the existing key management mechanism, as they will now be included in outbound HTTP headers for streaming calls.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **Bug Fixes**
  * Ollama streaming requests now support authentication via bearer tokens for both text and chat completions, enabling proper token-based authentication when API keys are provided.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3906?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* 1.5.7 changelogs (maximhq#3907)

This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* changelogs (maximhq#3909)

## Summary

Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet.

## Changes

- Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck`
- Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8)
- Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
# Verify no vulnerabilities remain
govulncheck ./...

# Build Docker image and confirm wget healthcheck works
docker build -f transports/Dockerfile -t gateway-test .
docker run --rm gateway-test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Closes maximhq#3900

## Security considerations

- Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0
- Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

---------

Co-authored-by: Hen Sapir <hen@sapir.me>
akhsaul pushed a commit to akhsaul/bifrost that referenced this pull request Aug 27, 2026
* docker scout fixes (maximhq#3900)

* 1.5.7 changelogs (maximhq#3907)

This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* changelogs (maximhq#3909)

## Summary

Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet.

## Changes

- Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck`
- Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8)
- Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
# Verify no vulnerabilities remain
govulncheck ./...

# Build Docker image and confirm wget healthcheck works
docker build -f transports/Dockerfile -t gateway-test .
docker run --rm gateway-test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Closes maximhq#3900

## Security considerations

- Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0
- Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

* enterprise changelog (maximhq#3912)

## Summary

Adds the Enterprise v1.4.6 changelog entry to the documentation site and registers it in the docs navigation.

## Changes

- Added `docs/changelogs/ent-v1.4.6.mdx` documenting the v1.4.6 release, which is a security and hardening release based on `transports/v1.5.7`. Key highlights include:
  - **DAC bypass fix**: `from_memory` query paths and shared filter-data caches were bypassing data-access scope enforcement, allowing scoped callers to observe virtual keys, teams, routing rules, and log dimensions belonging to other users. All read paths now apply the caller's DAC scope, and MCP clients no longer leak hidden virtual key IDs.
  - **DAC scope coverage expanded**: Added DAC wrappers for `GetVirtualKeys`, `GetRoutingRules`, `GetRoutingRulesByScope`, `GetRoutingRule`, and MCP virtual-key config lookups by client ID.
  - **DAC bypass regression suite**: New end-to-end Postman collection covering `from_memory` list endpoints, hidden virtual key/team detail access, log and MCP filter-data cache isolation, and MCP client assignment leakage.
  - **CVE remediation**: Updated `golang.org/x` packages (`crypto`, `net`, `sys`, `text`, `term`) clearing 20 advisories with severity up to 10.0, verified with `govulncheck`.
  - **Hardened container image**: Removed standalone GNU `wget` from the Alpine runtime image, eliminating CVE-2025-69194 (8.8); healthcheck now uses busybox `wget`.
  - **Ollama and SGL streaming auth fixes**: Both providers now correctly forward `Authorization: Bearer` headers on streaming requests.
  - **Governance model availability fix**: Access profile evaluation now correctly enforces model availability checks during budget constraint validation across managed and non-managed governance paths.
  - **Governance and Logging list API cleanup**: Removed the `from_memory` query parameter; list APIs now return consistent DB-backed results with batch-fetched virtual-key names.
- Registered `changelogs/ent-v1.4.6` as the first entry in the Enterprise changelogs section of `docs/docs.json`.

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [x] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [x] Docs

## How to test

Navigate to the Enterprise changelogs section of the documentation site and confirm that the v1.4.6 entry appears at the top of the list and renders correctly, including the breaking-change warning, feature/fix sections, and dependency tables.

## Breaking changes

- [x] Yes
- [ ] No

v1.4.0 introduced breaking changes. Upgraders should follow the [v1.4.0 Migration Guide](https://docs.example.com/enterprise/migration-guides/v1.4.0) before upgrading to v1.4.6.

## Security considerations

This release closes a DAC bypass that allowed scoped callers to read virtual keys, teams, routing rules, and log dimensions belonging to other users via `from_memory` query paths and shared filter-data caches. It also remediates 20 CVEs in `golang.org/x` dependencies (max severity 10.0) and removes a vulnerable `wget` binary (CVE-2025-69194, 8.8) from the container image.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

## Documentation

* Added Enterprise v1.4.6 release notes documenting a security-focused release with hardening improvements and critical updates.
* Updates include security remediation, governance and model validation enhancements, container image improvements, and authentication updates for supported streaming services.
* Removed deprecated parameter from governance and logging APIs.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3912?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akhsaul pushed a commit to akhsaul/bifrost that referenced this pull request Aug 27, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
occcat pushed a commit to occcat/bifrost that referenced this pull request Sep 2, 2026
* removes from_memory for APIs

* docker scout fixes (maximhq#3900)

* test fixes for hardened runners (maximhq#3780)

* fix: SGL provider - send Authorization header on streaming requests (maximhq#3307)

* [fix]: SGL provider - send Authorization header on streaming requests

The streaming entry points (ChatCompletionStream, TextCompletionStream)
passed nil for the authHeader parameter to the shared OpenAI streaming
helpers, so no Authorization header was attached to outbound streaming
requests. SGLang servers configured with --api-key always require the
header and returned 401 on streaming while non-streaming requests
worked. The non-streaming OpenAI helper takes the Key directly and
builds the header itself; the streaming helper requires the caller to
build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and
construct the auth header from key.Value when set.

Affected packages:
- core/providers/sgl/sgl.go - build authHeader for both streaming paths
- core/providers/sgl/chat_test.go - regression tests asserting the
  Authorization header reaches the upstream on chat and text streams
- core/changelog.md - changelog entry

* [fix]: SGL streaming tests - cancel drain goroutine on test completion

The drain goroutines spawned to consume streamChan in
TestChatCompletionStream_SetsAuthorizationHeader and
TestTextCompletionStream_SetsAuthorizationHeader had no cancellation
path: if the streaming pipeline failed to close the channel (e.g. on a
test timeout), the goroutines would leak into the test process.

Replace the inline `go func() { for range streamChan {} }()` with a
shared drainStream helper that selects on both the channel and a `done`
channel closed via t.Cleanup, so the goroutine always exits when the
test completes regardless of channel state.

Addresses Greptile review feedback on PR maximhq#3307.

---------

Co-authored-by: Akshay Deo <akshay@akshaydeo.com>

* ollama streaming auth header (maximhq#3906)

## Summary

Adds Bearer token authentication support to the Ollama provider's streaming endpoints. Previously, the streaming methods for text completion and chat completion always passed `nil` for the auth header, meaning API keys configured for Ollama were silently ignored during streaming requests.

## Issues

Closes maximhq#3905

## Changes

- When a non-empty key value is present, a `Bearer` token `Authorization` header is now constructed and passed to the OpenAI-compatible streaming handlers for both `TextCompletionStream` and `ChatCompletionStream`
- If no key is configured, the auth header remains `nil`, preserving backward compatibility with unauthenticated local Ollama instances

## Type of change

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [x] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

Configure an Ollama provider with an API key (e.g., when using a hosted or authenticated Ollama instance) and issue a streaming chat or text completion request. Verify the `Authorization: Bearer <key>` header is included in the outgoing request.

```sh
go test ./core/providers/ollama/...
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

API keys are now correctly forwarded as Bearer tokens in streaming requests to Ollama. Ensure keys are stored and retrieved securely via the existing key management mechanism, as they will now be included in outbound HTTP headers for streaming calls.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **Bug Fixes**
  * Ollama streaming requests now support authentication via bearer tokens for both text and chat completions, enabling proper token-based authentication when API keys are provided.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3906?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* 1.5.7 changelogs (maximhq#3907)

This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* changelogs (maximhq#3909)

## Summary

Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet.

## Changes

- Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck`
- Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8)
- Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
# Verify no vulnerabilities remain
govulncheck ./...

# Build Docker image and confirm wget healthcheck works
docker build -f transports/Dockerfile -t gateway-test .
docker run --rm gateway-test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Closes maximhq#3900

## Security considerations

- Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0
- Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

---------

Co-authored-by: Hen Sapir <hen@sapir.me>
occcat pushed a commit to occcat/bifrost that referenced this pull request Sep 2, 2026
* docker scout fixes (maximhq#3900)

* 1.5.7 changelogs (maximhq#3907)

This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

* changelogs (maximhq#3909)

## Summary

Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet.

## Changes

- Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck`
- Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8)
- Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [ ] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
# Verify no vulnerabilities remain
govulncheck ./...

# Build Docker image and confirm wget healthcheck works
docker build -f transports/Dockerfile -t gateway-test .
docker run --rm gateway-test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Closes maximhq#3900

## Security considerations

- Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0
- Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

* enterprise changelog (maximhq#3912)

## Summary

Adds the Enterprise v1.4.6 changelog entry to the documentation site and registers it in the docs navigation.

## Changes

- Added `docs/changelogs/ent-v1.4.6.mdx` documenting the v1.4.6 release, which is a security and hardening release based on `transports/v1.5.7`. Key highlights include:
  - **DAC bypass fix**: `from_memory` query paths and shared filter-data caches were bypassing data-access scope enforcement, allowing scoped callers to observe virtual keys, teams, routing rules, and log dimensions belonging to other users. All read paths now apply the caller's DAC scope, and MCP clients no longer leak hidden virtual key IDs.
  - **DAC scope coverage expanded**: Added DAC wrappers for `GetVirtualKeys`, `GetRoutingRules`, `GetRoutingRulesByScope`, `GetRoutingRule`, and MCP virtual-key config lookups by client ID.
  - **DAC bypass regression suite**: New end-to-end Postman collection covering `from_memory` list endpoints, hidden virtual key/team detail access, log and MCP filter-data cache isolation, and MCP client assignment leakage.
  - **CVE remediation**: Updated `golang.org/x` packages (`crypto`, `net`, `sys`, `text`, `term`) clearing 20 advisories with severity up to 10.0, verified with `govulncheck`.
  - **Hardened container image**: Removed standalone GNU `wget` from the Alpine runtime image, eliminating CVE-2025-69194 (8.8); healthcheck now uses busybox `wget`.
  - **Ollama and SGL streaming auth fixes**: Both providers now correctly forward `Authorization: Bearer` headers on streaming requests.
  - **Governance model availability fix**: Access profile evaluation now correctly enforces model availability checks during budget constraint validation across managed and non-managed governance paths.
  - **Governance and Logging list API cleanup**: Removed the `from_memory` query parameter; list APIs now return consistent DB-backed results with batch-fetched virtual-key names.
- Registered `changelogs/ent-v1.4.6` as the first entry in the Enterprise changelogs section of `docs/docs.json`.

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [x] Documentation
- [ ] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [x] Docs

## How to test

Navigate to the Enterprise changelogs section of the documentation site and confirm that the v1.4.6 entry appears at the top of the list and renders correctly, including the breaking-change warning, feature/fix sections, and dependency tables.

## Breaking changes

- [x] Yes
- [ ] No

v1.4.0 introduced breaking changes. Upgraders should follow the [v1.4.0 Migration Guide](https://docs.example.com/enterprise/migration-guides/v1.4.0) before upgrading to v1.4.6.

## Security considerations

This release closes a DAC bypass that allowed scoped callers to read virtual keys, teams, routing rules, and log dimensions belonging to other users via `from_memory` query paths and shared filter-data caches. It also remediates 20 CVEs in `golang.org/x` dependencies (max severity 10.0) and removes a vulnerable `wget` binary (CVE-2025-69194, 8.8) from the container image.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

## Documentation

* Added Enterprise v1.4.6 release notes documenting a security-focused release with hardening improvements and critical updates.
* Updates include security remediation, governance and model validation enhancements, container image improvements, and authentication updates for supported streaming services.
* Removed deprecated parameter from governance and logging APIs.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3912?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
occcat pushed a commit to occcat/bifrost that referenced this pull request Sep 2, 2026
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.

- Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906)
- SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!)
- Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903)
- Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [ ] Docs

Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured.

```sh
go version
go test ./...
```

Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present.

- [ ] Yes
- [x] No

Closes maximhq#3906
Closes maximhq#3307
Closes maximhq#3903

These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

* **Bug Fixes**
  * Fixed authorization header handling for Ollama streaming requests.
  * Fixed authorization header forwarding for SGL provider streaming requests.
  * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters.

* **Chores**
  * Updated component versions across the platform.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants