diff --git a/changelog.d/fixes/8385-perkey-proxy-global-toggle.md b/changelog.d/fixes/8385-perkey-proxy-global-toggle.md new file mode 100644 index 0000000000..f30d5a44ed --- /dev/null +++ b/changelog.d/fixes/8385-perkey-proxy-global-toggle.md @@ -0,0 +1 @@ +- fix(backend): make disabling the global per-key proxy toggle override existing per-key proxy assignments (#8385) diff --git a/src/lib/db/settings.ts b/src/lib/db/settings.ts index 5c997e4588..647a318013 100644 --- a/src/lib/db/settings.ts +++ b/src/lib/db/settings.ts @@ -523,8 +523,10 @@ export async function resolveProxyForConnection( // Step 2: API key-level proxy (only if per-key proxy is enabled globally or per-connection) if (apiKeyId) { - // Check if per-key proxy is allowed: globally OR per-connection - const perKeyEnabled = globalPerKeyProxyEnabled || connectionPerKeyProxyEnabled; + // Check if per-key proxy is allowed: the global toggle is a true override — + // when it is off, no connection's per-key assignment may apply, regardless + // of that connection's own per_key_proxy_enabled flag (#8385). + const perKeyEnabled = globalPerKeyProxyEnabled && connectionPerKeyProxyEnabled; if (perKeyEnabled) { try { diff --git a/tests/unit/8385-perkey-proxy-global-toggle.test.ts b/tests/unit/8385-perkey-proxy-global-toggle.test.ts new file mode 100644 index 0000000000..84a0226ca8 --- /dev/null +++ b/tests/unit/8385-perkey-proxy-global-toggle.test.ts @@ -0,0 +1,117 @@ +import test from "node:test"; +import assert from "node:assert/strict"; +import fs from "node:fs"; +import os from "node:os"; +import path from "node:path"; + +const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-8385-")); +process.env.DATA_DIR = TEST_DATA_DIR; +process.env.API_KEY_SECRET = "test-secret"; + +const core = await import("../../src/lib/db/core.ts"); +const providersDb = await import("../../src/lib/db/providers.ts"); +const proxiesDb = await import("../../src/lib/db/proxies.ts"); +const settingsDb = await import("../../src/lib/db/settings.ts"); +const apiKeysDb = await import("../../src/lib/db/apiKeys.ts"); + +interface ConnectionRef { + id: string; +} + +interface ProxyResolution { + level: string | null; + proxy: unknown; +} + +async function resetStorage() { + delete process.env.INITIAL_PASSWORD; + core.resetDbInstance(); + apiKeysDb.resetApiKeyState(); + fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); + fs.mkdirSync(TEST_DATA_DIR, { recursive: true }); +} + +test.after(async () => { + core.resetDbInstance(); + fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true }); +}); + +test("issue #8385: global perKeyProxyEnabled=false must override a connection's per_key_proxy_enabled=1", async () => { + await resetStorage(); + + core + .getDbInstance() + .prepare( + "INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('settings', 'perKeyProxyEnabled', 'false')" + ) + .run(); + + const conn = (await providersDb.createProviderConnection({ + provider: "openai", + authType: "apikey", + name: "conn-8385", + apiKey: "sk-8385", + })) as unknown as ConnectionRef; + await providersDb.updateProviderConnection(conn.id, { perKeyProxyEnabled: true }); + + const proxy = await proxiesDb.createProxy({ + name: "Per-Key Proxy 8385", + type: "http", + host: "perkey.8385.local", + port: 8080, + }); + + const key = await apiKeysDb.createApiKey("probe-8385-key", "machine-8385"); + await apiKeysDb.updateApiKeyPermissions(key.id, { proxyId: proxy.id }); + + const resolved = (await settingsDb.resolveProxyForConnection( + conn.id, + key.id + )) as unknown as ProxyResolution; + + assert.notEqual( + resolved?.level, + "apiKey", + `expected global-off to override per-key assignment, but got level=${resolved?.level} proxy=${JSON.stringify(resolved?.proxy)}` + ); +}); + +test("issue #8385: global perKeyProxyEnabled=true still allows the per-key assignment to apply", async () => { + await resetStorage(); + + core + .getDbInstance() + .prepare( + "INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('settings', 'perKeyProxyEnabled', 'true')" + ) + .run(); + + const conn = (await providersDb.createProviderConnection({ + provider: "openai", + authType: "apikey", + name: "conn-8385-on", + apiKey: "sk-8385-on", + })) as unknown as ConnectionRef; + await providersDb.updateProviderConnection(conn.id, { perKeyProxyEnabled: true }); + + const proxy = await proxiesDb.createProxy({ + name: "Per-Key Proxy 8385 On", + type: "http", + host: "perkey-on.8385.local", + port: 8081, + }); + + const key = await apiKeysDb.createApiKey("probe-8385-key-on", "machine-8385-on"); + await apiKeysDb.updateApiKeyPermissions(key.id, { proxyId: proxy.id }); + + const resolved = (await settingsDb.resolveProxyForConnection( + conn.id, + key.id + )) as unknown as ProxyResolution; + + assert.equal( + resolved?.level, + "apiKey", + `expected global-on to allow the per-key assignment, but got level=${resolved?.level}` + ); +}); diff --git a/tests/unit/proxy-registry.test.ts b/tests/unit/proxy-registry.test.ts index 3c3812feb3..35e1c63940 100644 --- a/tests/unit/proxy-registry.test.ts +++ b/tests/unit/proxy-registry.test.ts @@ -304,6 +304,7 @@ test("resolveProxyForConnection uses apiKey proxy before account-level proxy", a name: "api-key-proxy", apiKey: "sk-apikey-proxy", }); + const connId = (conn as any).id; const accountProxy = await proxiesDb.createProxy({ name: "Account Proxy", @@ -311,17 +312,20 @@ test("resolveProxyForConnection uses apiKey proxy before account-level proxy", a host: "account.local", port: 8081, }); - await proxiesDb.assignProxyToScope("account", (conn as any).id, accountProxy.id); + await proxiesDb.assignProxyToScope("account", connId, accountProxy.id); const key = await apiKeysDb.createApiKey("proxy-test-key", "machine-p1"); - // Enable per-key proxy globally so the API key's proxy_id is honored + // Enable per-key proxy globally (master gate) and on the connection itself + // (#8385: the global toggle is a true AND-override, not an independent + // opt-in path — both must be on for the api-key-level proxy to apply). core .getDbInstance() .prepare( "INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('settings', 'perKeyProxyEnabled', 'true')" ) .run(); + await providersDb.updateProviderConnection(connId, { perKeyProxyEnabled: true }); const apiKeyProxy = await proxiesDb.createProxy({ name: "API Key Proxy", @@ -331,7 +335,7 @@ test("resolveProxyForConnection uses apiKey proxy before account-level proxy", a }); await apiKeysDb.updateApiKeyPermissions(key.id, { proxyId: apiKeyProxy.id }); - const resolved = await settingsDb.resolveProxyForConnection((conn as any).id, key.id); + const resolved = await settingsDb.resolveProxyForConnection(connId, key.id); assert.ok(resolved); assert.equal((resolved as any).level, "apiKey"); assert.equal((resolved as any).proxy.host, "apikey.local"); diff --git a/tests/unit/resolve-proxy-family.test.ts b/tests/unit/resolve-proxy-family.test.ts index 803aee5bb0..6e12f618ad 100644 --- a/tests/unit/resolve-proxy-family.test.ts +++ b/tests/unit/resolve-proxy-family.test.ts @@ -115,12 +115,16 @@ test("api-key-level proxy carries family=ipv6 (Step 2 object literal)", async () name: "key-ipv6", apiKey: "sk-key-ipv6", }); + const connId = (conn as any).id; core .getDbInstance() .prepare( "INSERT OR REPLACE INTO key_value (namespace, key, value) VALUES ('settings', 'perKeyProxyEnabled', 'true')" ) .run(); + // #8385: the global toggle is a true AND-override — the connection's own + // per_key_proxy_enabled must also be on for the api-key-level proxy to apply. + await providersDb.updateProviderConnection(connId, { perKeyProxyEnabled: true }); const proxy = await proxiesDb.createProxy({ name: "IPv6 API Key Proxy", type: "https", @@ -131,7 +135,7 @@ test("api-key-level proxy carries family=ipv6 (Step 2 object literal)", async () const key = await apiKeysDb.createApiKey("family-key", "machine-f1"); await apiKeysDb.updateApiKeyPermissions(key.id, { proxyId: proxy.id }); - const resolved = await settingsDb.resolveProxyForConnection((conn as any).id, key.id); + const resolved = await settingsDb.resolveProxyForConnection(connId, key.id); assert.ok(resolved); assert.equal((resolved as any).level, "apiKey"); assert.equal((resolved as any).proxy.family, "ipv6");