mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 04:12:10 +03:00
The existing /api/combos GET requires a management token, which broke read-only integrations (opencode-omniroute-auth plugin and similar) that need to enrich combo capabilities from a normal Bearer API key. Those clients got 403 AUTH_001 'Invalid management token' even though the same API key could list models via /v1/models. This adds GET /v1/combos with the same auth model as /v1/models: - Accepts valid Bearer API key OR dashboard session cookie. - Falls back to anonymous when REQUIRE_API_KEY=false (single-user local). - Projects ONLY public metadata: name, strategy, description, model id, providerId, comboName (for combo-refs). Internal routing details (connectionId, weights, labels, sortOrder, config) are stripped. /api/combos (management writes) is unchanged.