Skip to content

fix: strip provider response headers - #3955

Merged
akshaydeo merged 1 commit into
devfrom
06-01-fix_strip_provider_response_headers
Jun 2, 2026
Merged

fix: strip provider response headers#3955
akshaydeo merged 1 commit into
devfrom
06-01-fix_strip_provider_response_headers

Conversation

@TejasGhatte

@TejasGhatte TejasGhatte commented Jun 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

Fixes a security vulnerability where provider API key headers injected by Bifrost upstream were being echoed back to clients in response headers. This was identified as a regression in the /genai_passthrough endpoint where x-goog-api-key values were leaking to clients (e.g., via Google's file-download 302 redirects).

fixes #3954

Changes

  • Added x-goog-api-key, x-api-key, and api-key to the providerResponseFilterHeaders blocklist so they are stripped from upstream responses before being forwarded to clients.
  • Added a regression test TestExtractProviderResponseHeaders_StripsProviderSecrets that verifies all four sensitive headers (x-goog-api-key, x-api-key, api-key, authorization) are stripped while benign headers like x-request-id are preserved.

Type of change

  • Bug fix
  • Feature
  • Refactor
  • Documentation
  • Chore/CI

Affected areas

  • Core (Go)
  • Transports (HTTP)
  • Providers/Integrations
  • Plugins
  • UI (React)
  • Docs

How to test

go test ./core/providers/utils/... -run TestExtractProviderResponseHeaders_StripsProviderSecrets -v

Expected output: the test passes, confirming that x-goog-api-key, x-api-key, api-key, and authorization are absent from the extracted response headers map, and that x-request-id is preserved.

Screenshots/Recordings

N/A

Breaking changes

  • Yes
  • No

Related issues

Regression fix for x-goog-api-key leak via /genai_passthrough.

Security considerations

This patch closes a credential leak where provider API keys (x-goog-api-key, x-api-key, api-key) injected into upstream requests could be reflected back to end clients in HTTP response headers. Any client receiving these responses prior to this fix may have been exposed to the upstream provider credentials. No new secrets or auth mechanisms are introduced.

Checklist

  • I read docs/contributing/README.md and followed the guidelines
  • I added/updated tests where appropriate
  • I updated documentation where needed
  • I verified builds succeed (Go and UI)
  • I verified the CI pipeline passes locally if applicable

Summary by CodeRabbit

  • Bug Fixes

    • API key and authentication headers (case-insensitive) are now filtered from provider responses to prevent exposure of sensitive credentials to clients.
    • Legitimate non-sensitive response headers are preserved to maintain request tracing and debugging.
  • Tests

    • Added a test that verifies sensitive provider headers are stripped while ensuring benign headers remain intact.

@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 2eb39506-fb19-46c4-9a15-4658147d5039

📥 Commits

Reviewing files that changed from the base of the PR and between d9fe7d0 and 5d788af.

📒 Files selected for processing (2)
  • core/providers/utils/utils.go
  • core/providers/utils/utils_test.go

📝 Walkthrough

Walkthrough

Adds x-goog-api-key, x-api-key, and api-key to the provider response header filter so ExtractProviderResponseHeaders (fasthttp/net/http) omits them when building client-facing headers. A new test verifies case-insensitive removal of those secret headers while preserving benign headers like x-request-id.

Changes

API Key Header Filtering

Layer / File(s) Summary
Filter provider API key headers
core/providers/utils/utils.go, core/providers/utils/utils_test.go
providerResponseFilterHeaders extended to include x-goog-api-key, x-api-key, and api-key. Test TestExtractProviderResponseHeaders_StripsProviderSecrets verifies these and other secret headers (e.g., authorization) are removed case-insensitively while x-request-id remains.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested reviewers

  • akshaydeo
  • danpiths

Poem

🐰 I nibble through headers late at night,
I hide the keys from prying sight,
Filters hum, secrets cease to peep,
The harmless tags I gently keep,
Hooray — no tokens hop away tonight!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely summarizes the main change: stripping provider response headers that contain sensitive API keys to fix a security vulnerability.
Description check ✅ Passed The PR description comprehensively covers all required template sections including summary, changes, type, affected areas, testing instructions, security considerations, and a completed checklist.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 06-01-fix_strip_provider_response_headers

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain main module or its selected dependencies"


Comment @coderabbitai help to get the list of available commands and usage tips.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


tejas ghatte seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

Copy link
Copy Markdown
Collaborator Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@TejasGhatte
TejasGhatte marked this pull request as ready for review June 1, 2026 14:38
@greptile-apps

greptile-apps Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Confidence Score: 5/5

Safe to merge — the change is a targeted, additive blocklist update that closes a real credential-leak path with no behavioral side effects on the normal request flow.

The diff is minimal: three new entries added to an existing filter map used by both response-header extraction paths. The logic is straightforward (map lookup on lower-cased key), the existing authorization entry confirms the pattern is already established, and the new regression test confirms the fasthttp path strips all four secret headers as intended. No concurrency concerns, no pooled-object changes, no new external dependencies.

No files require special attention.

Important Files Changed

Filename Overview
core/providers/utils/utils.go Adds x-goog-api-key, x-api-key, and api-key to the providerResponseFilterHeaders blocklist; both ExtractProviderResponseHeaders and ExtractProviderResponseHeadersFromHTTP now strip these headers via the shared map.
core/providers/utils/utils_test.go Adds TestExtractProviderResponseHeaders_StripsProviderSecrets covering the fasthttp path; verifies all four secret headers are stripped and benign headers are preserved.

Reviews (2): Last reviewed commit: "fix: strip provider response headers" | Re-trigger Greptile

Comment thread core/providers/utils/utils_test.go
@TejasGhatte
TejasGhatte force-pushed the 06-01-fix_strip_provider_response_headers branch from d9fe7d0 to 5d788af Compare June 2, 2026 06:31

akshaydeo commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

Merge activity

  • Jun 2, 7:04 AM UTC: A user started a stack merge that includes this pull request via Graphite.
  • Jun 2, 7:04 AM UTC: @akshaydeo merged this pull request with Graphite.

@akshaydeo
akshaydeo merged commit 2484a7c into dev Jun 2, 2026
14 of 15 checks passed
@akshaydeo
akshaydeo deleted the 06-01-fix_strip_provider_response_headers branch June 2, 2026 07:04
akshaydeo pushed a commit that referenced this pull request Jun 2, 2026
## Summary

Fixes a security vulnerability where provider API key headers injected by Bifrost upstream were being echoed back to clients in response headers. This was identified as a regression in the `/genai_passthrough` endpoint where `x-goog-api-key` values were leaking to clients (e.g., via Google's file-download 302 redirects).  
  
fixes #3954

## Changes

- Added `x-goog-api-key`, `x-api-key`, and `api-key` to the `providerResponseFilterHeaders` blocklist so they are stripped from upstream responses before being forwarded to clients.
- Added a regression test `TestExtractProviderResponseHeaders_StripsProviderSecrets` that verifies all four sensitive headers (`x-goog-api-key`, `x-api-key`, `api-key`, `authorization`) are stripped while benign headers like `x-request-id` are preserved.

## Type of change

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
go test ./core/providers/utils/... -run TestExtractProviderResponseHeaders_StripsProviderSecrets -v
```

Expected output: the test passes, confirming that `x-goog-api-key`, `x-api-key`, `api-key`, and `authorization` are absent from the extracted response headers map, and that `x-request-id` is preserved.

## Screenshots/Recordings

N/A

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Regression fix for `x-goog-api-key` leak via `/genai_passthrough`.

## Security considerations

This patch closes a credential leak where provider API keys (`x-goog-api-key`, `x-api-key`, `api-key`) injected into upstream requests could be reflected back to end clients in HTTP response headers. Any client receiving these responses prior to this fix may have been exposed to the upstream provider credentials. No new secrets or auth mechanisms are introduced.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **Bug Fixes**
  * API key and authentication headers (case-insensitive) are now filtered from provider responses to prevent exposure of sensitive credentials to clients.
  * Legitimate non-sensitive response headers are preserved to maintain request tracing and debugging.

* **Tests**
  * Added a test that verifies sensitive provider headers are stripped while ensuring benign headers remain intact.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo pushed a commit that referenced this pull request Jun 4, 2026
## Summary

Fixes a security vulnerability where provider API key headers injected by Bifrost upstream were being echoed back to clients in response headers. This was identified as a regression in the `/genai_passthrough` endpoint where `x-goog-api-key` values were leaking to clients (e.g., via Google's file-download 302 redirects).  
  
fixes #3954

## Changes

- Added `x-goog-api-key`, `x-api-key`, and `api-key` to the `providerResponseFilterHeaders` blocklist so they are stripped from upstream responses before being forwarded to clients.
- Added a regression test `TestExtractProviderResponseHeaders_StripsProviderSecrets` that verifies all four sensitive headers (`x-goog-api-key`, `x-api-key`, `api-key`, `authorization`) are stripped while benign headers like `x-request-id` are preserved.

## Type of change

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
go test ./core/providers/utils/... -run TestExtractProviderResponseHeaders_StripsProviderSecrets -v
```

Expected output: the test passes, confirming that `x-goog-api-key`, `x-api-key`, `api-key`, and `authorization` are absent from the extracted response headers map, and that `x-request-id` is preserved.

## Screenshots/Recordings

N/A

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Regression fix for `x-goog-api-key` leak via `/genai_passthrough`.

## Security considerations

This patch closes a credential leak where provider API keys (`x-goog-api-key`, `x-api-key`, `api-key`) injected into upstream requests could be reflected back to end clients in HTTP response headers. Any client receiving these responses prior to this fix may have been exposed to the upstream provider credentials. No new secrets or auth mechanisms are introduced.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **Bug Fixes**
  * API key and authentication headers (case-insensitive) are now filtered from provider responses to prevent exposure of sensitive credentials to clients.
  * Legitimate non-sensitive response headers are preserved to maintain request tracing and debugging.

* **Tests**
  * Added a test that verifies sensitive provider headers are stripped while ensuring benign headers remain intact.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@akshaydeo akshaydeo mentioned this pull request Jun 5, 2026
18 tasks
akshaydeo added a commit that referenced this pull request Jun 6, 2026
## Summary

This PR bumps the Go toolchain version from `1.26.3` to `1.26.4` across all modules and CI workflows, and cuts a new release (`core` v1.5.17, `framework` v1.3.17, `transports` v1.5.9, `plugins/compat` v0.1.16, `plugins/governance` v1.5.17, and associated plugin versions) incorporating a large batch of features and fixes accumulated since the previous release.

## Changes

- **Go 1.26.4** — Updated `go-version` in all GitHub Actions workflows (`e2e-tests`, `helm-release`, `pr-tests`, `release-cli`, `release-pipeline`, `snyk`) and all `go.mod` files (core, framework, transports, cli, all plugins, examples, and test modules).
- **Core (v1.5.17)** — OpenAI compaction support, multi-customer logs and usage tracking, multiple team/business unit support, `request_headers` wildcard pattern capture for OTel and Maxim plugins, xAI `x_search` tool, fetch URL validation with SSRF hardening, `file://` pricing URL scheme, virtual key provider fan-out filtering, and a broad set of fixes including Anthropic prompt cache key, empty thinking block stripping, OpenAI stream usage event cleanup, Gemini numeric schema constraints, stale connection retries, Azure Claude diagnostic strip, and passthrough budget handling.
- **Framework (v1.3.17)** — Scope-aware budgets and limits wired from model configs, provider-level governance, multiple customer budget support with `calendar_aligned` windows, paginated virtual key fetch, `config.json` source-of-truth flow, FTS index cap reduction, sync worker drift fix, cascade deletes for model configs, and high-scale virtual key flow improvements.
- **Transports (v1.5.9)** — Full changelog covering all of the above plus UI improvements (log navigation, customer detail sheet, `BudgetDisplay` component, inline loading shell, materialized view alias), SCIM provisioning fields, Helm/config schema additions (`roles`, `per_user_oauth`), client IP resolution from forwarded headers, and dependency upgrades (`recharts` to 3.8.1, `golang.org/x` CVE remediation).
- **Plugins** — `governance` v1.5.17 adds team budget/rate-limit exporters, ghost node reconciliation fix, and VK double usage counting fix; `logging` v1.5.17 adds wildcard header capture and file attachment rendering; `otel` v1.2.17 adds `disable_content_logging` and multiple collectors support; `maxim` v1.6.17 adds `request_headers` wildcard capture; `compat` v0.1.16 fixes `max_tokens` preservation during param filtering.

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [x] UI (React)
- [ ] Docs

## How to test

```sh
# Verify Go version
go version  # should report go1.26.4

# Run core tests
cd core && go test ./...

# Run framework tests
cd framework && go test ./...

# Run transports tests
cd transports && go test ./...

# Run plugin tests
cd plugins/governance && go test ./...
cd plugins/logging && go test ./...
cd plugins/otel && go test ./...

# UI
cd ui
pnpm i
pnpm build
pnpm test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

#4053, #4066, #4041, #4012, #3976, #3947, #3991, #4045, #3957, #3938, #3937, #3939, #3981, #3998, #3997, #4092, #4091, #4079, #4080, #4086, #3929, #3994, #4028, #3970, #3919, #3861, #3664, #3999, #4088, #4070, #4051, #4043, #4057, #4023, #3941, #3955, #4024, #3956, #3967, #3925, #3992, #3900

## Security considerations

- Fetch URL validation hardened against SSRF by tightening IP checks for private networks and link-local addresses (#4092, #3947, #3991).
- Transitive `golang.org/x` dependencies (crypto, net, sys, text) bumped to address Docker Scout CVEs (#3900).

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **New Features**
  * OpenAI compaction, multi-customer/team logstore support, request-header wildcard capture, enhanced governance (provider-level & scope-aware limits), disable-content-logging option, support for multiple OpenTelemetry collectors, SSRF hardening and URL validation.

* **Chores**
  * Bumped Go toolchain across modules and updated component/plugin version releases.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@akshaydeo akshaydeo mentioned this pull request Jun 7, 2026
akshaydeo pushed a commit that referenced this pull request Jun 7, 2026
## Summary

Fixes a security vulnerability where provider API key headers injected by Bifrost upstream were being echoed back to clients in response headers. This was identified as a regression in the `/genai_passthrough` endpoint where `x-goog-api-key` values were leaking to clients (e.g., via Google's file-download 302 redirects).  
  
fixes #3954

## Changes

- Added `x-goog-api-key`, `x-api-key`, and `api-key` to the `providerResponseFilterHeaders` blocklist so they are stripped from upstream responses before being forwarded to clients.
- Added a regression test `TestExtractProviderResponseHeaders_StripsProviderSecrets` that verifies all four sensitive headers (`x-goog-api-key`, `x-api-key`, `api-key`, `authorization`) are stripped while benign headers like `x-request-id` are preserved.

## Type of change

- [x] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
go test ./core/providers/utils/... -run TestExtractProviderResponseHeaders_StripsProviderSecrets -v
```

Expected output: the test passes, confirming that `x-goog-api-key`, `x-api-key`, `api-key`, and `authorization` are absent from the extracted response headers map, and that `x-request-id` is preserved.

## Screenshots/Recordings

N/A

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

Regression fix for `x-goog-api-key` leak via `/genai_passthrough`.

## Security considerations

This patch closes a credential leak where provider API keys (`x-goog-api-key`, `x-api-key`, `api-key`) injected into upstream requests could be reflected back to end clients in HTTP response headers. Any client receiving these responses prior to this fix may have been exposed to the upstream provider credentials. No new secrets or auth mechanisms are introduced.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **Bug Fixes**
  * API key and authentication headers (case-insensitive) are now filtered from provider responses to prevent exposure of sensitive credentials to clients.
  * Legitimate non-sensitive response headers are preserved to maintain request tracing and debugging.

* **Tests**
  * Added a test that verifies sensitive provider headers are stripped while ensuring benign headers remain intact.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akshaydeo added a commit that referenced this pull request Jun 7, 2026
## ✨ Features

- **OpenAI Compaction** — Added OpenAI conversation compaction support
across core, framework, logging, and the API surface (#4053)
- **Multi-Customer & Org Hierarchy** — Logs and usage tracking now
support multiple customers, teams, and business units, including
business unit CRUD, team assignment, and governance endpoints in the
OpenAPI spec (#4066, #4041, #4082)
- **Provider-Level Governance** — Budgets & limits are now scope-aware
and can be applied at the virtual-key top level and per provider, wired
from the model configs table, with UI filters for scope and providers
(#3938, #3937, #3939, #3981, #3962)
- **Customer Budgets** — Customers support multiple budgets and
`calendar_aligned` budget windows (#3998, #3997)
- **Virtual Key Attribution & Controls** — Added a `created_by` user
attribution column and a `blacklisted_models` column for virtual key
provider configs (#3672, #3653)
- **Request Header Capture** — OTel and Maxim observability plugins
capture `request_headers` by pattern, with wildcard support (e.g.
`x-custom-*`); logging gained the same wildcard header capture (#4012,
#3958)
- **OTel Content Controls & Collectors** — New `disable_content_logging`
option drops message/tool content from exported spans, plus support for
multiple OTel collectors (#4064, #3894)
- **xAI x_search** — Added xAI `x_search` tool support (#3976)
- **URL Validation** — Added fetch URL validation with private-network
configuration and link-local blocking (#3947, #3991)
- **File Scheme Pricing URLs** — Pricing source URLs now accept the
`file://` scheme for air-gapped and self-hosted deployments (#4045)
- **Paginated Virtual Keys** — Virtual key fetching is paginated to
handle deployments with very large numbers of keys (#3957)
- **Client IP Resolution** — Resolve client IP from
`X-Forwarded-For`/`X-Real-IP` headers
- **SCIM Provisioning** — Added `attributeType`/`attributeValue` SCIM
provisioning fields
- **Helm/Config Schema** — Added `roles` RBAC governance config and
`per_user_oauth` MCP auth to the Helm chart and config schema (#4004,
#4009)
- **Log Navigation UI** — Added a "View logs" menu item to customer,
team, and virtual key tables, clickable links in log detail views, a
customer detail sheet, and a reusable `BudgetDisplay` component (#4073,
#4054, #4026, #4055)
- **Faster First Paint** — Added an inline loading shell to `#root`
before React mounts (#4063)
- **Materialized View Alias** — Added an `alias` column to the
materialized view with filter support (#4078)

## 🐞 Fixed

- **Fetch URL IP Checks** — Hardened fetch URL IP checks against SSRF
(#4092)
- **Mantle Model Matching** — Broadened Mantle model matching to all
`gpt` variants (#4091)
- **Empty Thinking Blocks** — Strip thinking blocks when the signature
is empty (#4079)
- **OpenAI Stream Usage** — Removed usage from the `responses.created`
event in the OpenAI stream (#4080)
- **Prompt Cache Key** — Set the prompt cache key from the Anthropic
integration (#4086)
- **Upstream Failure Status** — Map upstream connection failures to 502
instead of 400 (#3929) (thanks
[@chris-colinsky](https://github.com/chris-colinsky)!)
- **Gemini Schema Constraints** — Accept numeric schema integer
constraints for Gemini (#3994) (thanks
[@yanhao98](https://github.com/yanhao98)!)
- **Files Provider Param** — Accept the `?provider=` query param on `GET
/v1/files` (#3971) (thanks [@alexef](https://github.com/alexef)!)
- **Optional Batch Model** — Made the `model` field optional on `POST
/v1/batches` (#3973) (thanks [@alexef](https://github.com/alexef)!)
- **Helm Azure Config** — Added missing `azure_key_config` fields to the
Helm schema (#3996) (thanks
[@axelray-dev](https://github.com/axelray-dev)!)
- **Text Completion Chunk Model** — Added the missing `Model` field to
`TextCompletionChunkResponse` (#3970) (thanks
[@kuishou68](https://github.com/kuishou68)!)
- **MCP Inline stdio Env** — MCP stdio server configs accept inline
environment variable assignments (#3861) (thanks
[@Shushmitaaaa](https://github.com/Shushmitaaaa)!)
- **Orphaned Tool Results** — Orphaned tool results in the OpenAI to
Anthropic conversion flow are no longer rejected by the Anthropic API
(#3919)
- **Node Usage Reconciliation** — Added a monotonic `inc_number` log
cursor so node usage reconciliation does not skip late async log writes
(#3664)
- **Bedrock Output Assessments** — Corrected the type of
`outputAssessments` in Bedrock responses (#4028)
- **Model Pool Pricing Reloads** — Preserve non-pricing model pool
entries across pricing reloads (#3999)
- **Ghost Node Reconciliation** — Replicate the VK hierarchy flow for
ghost node reconciliation (#4088)
- **VK Double Usage Counting** — Fixed double usage counting when
creating a virtual key (#4070)
- **Model Config Lifecycle** — Cascade deletes for model configs and
removal of stale in-memory model configs (#4051, #4043)
- **FTS Index Cap** — Reduced the FTS index `left()` cap from 800k to
250k chars to stay within the tsvector limit (#4057)
- **Sync Worker Drift** — Reduced the sync worker ticker period to 5m to
prevent threshold drift (#4023)
- **Passthrough** — Fixed passthrough budgets, gated passthrough models
per VK, model extraction for Azure passthrough, and restricted
fallbacks/provider selection to the VK boundary (#3941, #3988, #3983,
#3924)
- **Provider Response Headers** — Strip provider response headers and
add a content-type filter (#3955, #4024)
- **Stream Handling** — Drain non-SSE stream readers and retry stale
connections (#3956, #3967)
- **Azure Claude** — Strip Azure diagnostic property for Claude models
(#3925)
- **Compat max_tokens** — Preserve chat `max_tokens` during param
filtering (#3992)
- **Raw Request Flag** — Removed the raw request flag from providers
that don't support it (#4058)
- **UI Fixes** — Standardized page container layout, virtual key model
configs UI, and dashboard chart tooltips (#4046, #4052, #4044)

## 🔧 Maintenance

- **Dependency Upgrades** — Bumped transitive `golang.org/x`
dependencies (crypto, net, sys, text) for Docker Scout CVE remediation
and `recharts` to 3.8.1; cascaded version bumps across all modules
(#3900, #4003)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Security: /genai_passthrough leaks upstream Gemini API key via x-goog-api-key response header

3 participants