fix(api-manager): allow empty combo restrictions (#10066)

* fix(api-manager): allow empty combo restrictions

Represent unrestricted Combo access explicitly as combo/* so an empty Allowed Combos list can deny every Combo without affecting direct model routes. Preserve existing keys through migration 149 and cover Dashboard, policy, routing-target, and migration behavior.

* docs: sync migration count to 149 after api-key combo-access migration

Merging release/v3.8.50 forward landed 149_api_key_combo_access.sql,
bumping the real migration count from 148 to 149. Updates README.md,
AGENTS.md, llm.txt (root + all 42 i18n mirrors, exact-copy requirement)
so the strict docs-counts-sync gate matches the live count again.

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

---------

Co-authored-by: adevwithpurpose <adevwithpurpose@users.noreply.github.com>
Co-authored-by: xz-dev <xz-dev@users.noreply.github.com>
Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
This commit is contained in:
Xiangzhe
2026-08-17 18:00:05 +08:00
committed by GitHub
parent 2723698fe2
commit b082d0735b
57 changed files with 458 additions and 192 deletions

View File

@@ -31,6 +31,7 @@ import { resolveEndpointCategory } from "@/shared/constants/endpointCategories";
import { resolveQuotaKeyScope } from "@/lib/quota/quotaKey";
import { isQuotaModelName, parseQuotaModelName } from "@/lib/quota/quotaModelNaming";
import { buildApiKeyUsageLimitPolicyRejection } from "@/lib/usage/apiKeyUsageLimits";
import { ALL_COMBOS_ACCESS_RULE } from "@/shared/constants/comboAccess";
// Default to no per-key request cap. API keys can still opt into explicit
// limits via Settings/API Keys, while provider/account quota controls remain
@@ -181,6 +182,7 @@ function normalizeComboAccessName(value: unknown): string | null {
}
function matchesComboAccessRule(comboName: string, requestedModel: string, rule: string): boolean {
if (rule === ALL_COMBOS_ACCESS_RULE) return true;
const normalizedRule = normalizeComboAccessName(rule);
if (!normalizedRule) return false;
return (
@@ -303,7 +305,7 @@ async function validateStandardRoutingTarget(
modelStr: string
): Promise<Response | null> {
let requestedComboName: string | null = null;
if (apiKeyInfo.allowedCombos && apiKeyInfo.allowedCombos.length > 0) {
if (Array.isArray(apiKeyInfo.allowedCombos)) {
try {
const comboAccess = await isComboAllowedForKey(apiKeyInfo.allowedCombos, modelStr);
requestedComboName = comboAccess.comboName;
@@ -557,7 +559,7 @@ async function validateComboAccess(
allowedCombos: string[] | undefined,
modelStr: string
): Promise<{ comboName: string | null; rejection: Response | null }> {
if (!allowedCombos?.length) return { comboName: null, rejection: null };
if (!Array.isArray(allowedCombos)) return { comboName: null, rejection: null };
try {
const comboAccess = await isComboAllowedForKey(allowedCombos, modelStr);
if (comboAccess.allowed) return { comboName: comboAccess.comboName, rejection: null };