Conversation
The dev-plan guard that rejects pinning a specific provider/mapping (e.g. `deepseek/deepseek-v4-pro`) was nested inside `isDevPlanRestricted`, which is false whenever `devPlanAllowAllModels` is enabled. That toggle is only meant to widen which models are available, not to allow pinning a single provider — the gateway must own routing so it can prefer cached mappings. Hoist the direct-provider and custom-provider rejections out of the allow-all-models gate and key them on `isDevPlan` instead, so pinning is blocked for any coding plan regardless of the toggle. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
WalkthroughThe chat completions handler in Coding Plan Direct Provider Routing Enforcement
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8a40721fa2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| // regardless of `devPlanAllowAllModels` — that toggle only controls which | ||
| // models are available, not whether routing can be pinned to a single | ||
| // provider. The gateway must own routing so it can prefer cached mappings. | ||
| if (isDevPlan) { |
There was a problem hiding this comment.
Preserve the original provider when blocking pins
This guard still uses requestedProvider after resolveModelInfo() has normalized it, and that helper clears a pinned provider when its mapping is deactivated. In that scenario (for example azure/gpt-4o-mini, whose Azure mapping is deactivated while the OpenAI mapping remains active), a coding-plan org with devPlanAllowAllModels can send the prefixed model, requestedProvider becomes undefined, and the request proceeds through normal routing instead of returning the intended 403. Check the original parsed provider before it can be cleared to make the new direct-pin block complete.
Useful? React with 👍 / 👎.
|
Closing as duplicate of #2622. Both PRs implement the identical fix — hoisting the direct/custom provider-pin rejection out of the #2622 is the better one to keep: it also DRYs the |
Problem
On dev plans (devpass / coding plans), a request that pins a specific provider/mapping in the model string — e.g.
deepseek/deepseek-v4-pro— was still accepted and routed directly to that provider (direct-provider-specified). It should never be allowed: the gateway must own routing so it can prefer cached mappings.Cause
The direct-provider rejection lived inside the
isDevPlanRestrictedblock inapps/gateway/src/chat/chat.ts:When an org enables allow all models,
isDevPlanRestrictedbecomesfalseand the entire block — including the direct-provider/custom guard — is skipped. But the allow-all-models toggle is only meant to widen which models are available (beyond the recommended coding set), not to permit pinning a single provider/mapping.Fix
isDevPlanRestricted(that is the allow-all-models toggle's job).isDevPlan, so pinning is blocked for any coding plan regardless ofdevPlanAllowAllModels.Test
Added
apps/gateway/src/api.spec.tscase: a dev-plan org withallowAllModels: truerequestingopenai/gpt-4onow gets403 Direct provider routing is not available on coding plans.🤖 Generated with Claude Code
Summary by CodeRabbit
Bug Fixes
Tests