mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 20:32:20 +03:00
isModelAllowedForKey() existed in src/lib/db/apiKeys.ts but was never called anywhere. API keys with allowedModels restrictions could access any model through any endpoint. Changes: - Add shared enforceApiKeyPolicy() middleware (model restriction + budget) - Wire it into chat handler (replacing inline budget-only check) - Wire it into all /v1/* endpoints: embeddings, images/generations, audio/speech, audio/transcriptions, moderations, rerank - Wire it into provider-specific endpoints: /v1/providers/[provider]/embeddings, /v1/providers/[provider]/images/generations The middleware checks: 1. Model restriction — if key has allowedModels, verify the model is permitted 2. Budget limit — if key has budget configured, verify it hasn't been exceeded Fixes #130