Skip to content

fix(gateway): block provider routing on dev plans always - #2622

Merged
steebchen merged 1 commit into
mainfrom
fix/devpass-block-provider-routing-allow-all
Jul 14, 2026
Merged

steebchen merged 1 commit into
mainfrom
fix/devpass-block-provider-routing-allow-all

Conversation

@steebchen

@steebchen steebchen commented Jun 10, 2026 •

Copy link
Copy Markdown
Member

Summary

This confirms and fixes the behavior raised: targeting a specific provider for DeepSeek (e.g. deepseek/deepseek-v4-pro) worked on a dev pass once the "allow all models" feature was enabled. It shouldn't — only canonical model ids (e.g. deepseek-v4-pro) are allowed for dev pass, regardless of allow-all-models.

Root cause

The direct- and custom-provider routing rejections lived inside the if (isDevPlanRestricted) block. isDevPlanRestricted is false when devPlanAllowAllModels is on, so enabling allow-all-models silently also unlocked the provider/model routing format.

Fix

Split the two concerns:

  • Routing-format restriction (provider/model, custom/model) now applies to any dev plan via the existing isDevPlan flag — independent of allow-all-models.
  • Model-level restriction (coding-model + cached-input requirement) stays gated by isDevPlanRestricted, i.e. relaxed by allow-all-models.

Removed the now-misleading "enable access to all models" hint from the routing-format error messages, since that flag no longer affects them.

Test

Added a gateway test asserting deepseek/deepseek-v4-pro is rejected with 403 ("Direct provider routing is not available on coding plans") even with allowAllModels: true. Existing image-output dev-plan tests still pass.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Development-plan (coding-plan) access rules were updated so model eligibility and provider-routing restrictions are enforced independently.
    • Direct provider routing and custom provider routing are now rejected with 403 immediately, even when all models are allowed.
    • Error messages now instruct using the root model id (without provider/model) and remove outdated dashboard guidance.
  • Tests

    • Added a POST /v1/chat/completions test verifying provider-targeting model strings are rejected with 403 and the expected error text.

@coderabbitai

coderabbitai Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 59df185d-88e6-45a5-9a5d-95e5e1c4197c

📥 Commits

Reviewing files that changed from the base of the PR and between 441e55b and 1fd42d7.

📒 Files selected for processing (2)
  • apps/gateway/src/api.spec.ts
  • apps/gateway/src/chat/chat.ts
💤 Files with no reviewable changes (2)
  • apps/gateway/src/api.spec.ts
  • apps/gateway/src/chat/chat.ts

Walkthrough

The PR separates dev-plan coding-model checks from provider-routing checks in the chat gateway, rejects direct and custom provider routing for dev-plan orgs, updates the error text, and adds a test for provider-prefixed model names.

Changes

Dev-plan provider routing restriction

Layer / File(s) Summary
Provider routing restriction refactor in chat handler
apps/gateway/src/chat/chat.ts
isDevPlanRestricted now only covers coding-model eligibility, while a new isDevPlan path rejects direct provider routing and custom provider routing with updated 403 messages that point to the root model id.
Test coverage for provider routing restrictions
apps/gateway/src/api.spec.ts
Adds a /v1/chat/completions negative test for a pro dev-plan org with allowAllModels: true using a provider/model request and asserting the 403 error text.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

  • theopenco/llmgateway#2416: Also updates dev-plan request validation in apps/gateway/src/chat/chat.ts to reject direct and custom provider routing with 403 responses.
  • theopenco/llmgateway#2150: Also changes dev-plan restriction logic in apps/gateway/src/chat/chat.ts around provider routing and coding-plan eligibility.
  • theopenco/llmgateway#1478: Introduces the devPlanAllowAllModels toggle that this PR’s restriction split relies on.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: provider routing is now blocked on dev plans regardless of allow-all-models.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/devpass-block-provider-routing-allow-all

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5ea1689baa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +2188 to 2193
if (isDevPlan) {
if (
requestedProvider &&
requestedProvider !== "llmgateway" &&
requestedProvider !== "custom"
) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Block provider prefixes before clearing deactivated providers

This guard checks requestedProvider after resolveModelInfo() has already normalized it, and that helper clears a specifically requested provider when that provider mapping is deactivated. For example, a dev-plan org with devPlanAllowAllModels can request a deactivated mapping such as aws-bedrock/claude-3-7-sonnet; the provider prefix is parsed, then cleared, so this new isDevPlan block does not reject it and the request falls back to another provider. That leaves a provider-targeting model string accepted in the exact policy this change is trying to enforce; use the original parsed provider to decide whether a prefix was supplied.

Useful? React with 👍 / 👎.

@steebchen
steebchen force-pushed the fix/devpass-block-provider-routing-allow-all branch from 5ea1689 to c82a43d Compare June 13, 2026 13:40
@steebchen
steebchen force-pushed the fix/devpass-block-provider-routing-allow-all branch from c82a43d to 441e55b Compare June 21, 2026 22:40
Direct/custom provider-targeting model strings (e.g. `deepseek/deepseek-v4-pro`)
were only rejected on dev plans when devPlanAllowAllModels was off. Enabling
allow-all-models cleared isDevPlanRestricted, which also gated the routing-format
check, so the `provider/model` format leaked through.

Split the routing-format restriction from the model-level coding/cached-input
restriction: provider/custom routing is now rejected for any dev plan regardless
of allow-all-models. That flag only relaxes the model-level restrictions; only
canonical root model ids are ever accepted on dev plans.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 9, 2026 20:33
@steebchen
steebchen force-pushed the fix/devpass-block-provider-routing-allow-all branch from 441e55b to 1fd42d7 Compare July 9, 2026 20:33
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@steebchen
steebchen merged commit e5bae79 into main Jul 14, 2026
17 of 18 checks passed
@steebchen
steebchen deleted the fix/devpass-block-provider-routing-allow-all branch July 14, 2026 22:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants