mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-09-17 04:12:17 +03:00
#13832. A user reported that `nvidia` and `openrouter` — added after the initial setup — always failed chat with `No active credentials for provider: X`, while on the same instance and the same minute `/api/providers/{id}/test` returned valid and `/sync-models` pulled 82 models. Reproducing the resolution chain on the tip shows no defect in it: a connection created exactly as `POST /api/providers` creates one resolves for every model tried, and creation order is irrelevant — the query is `provider = ? AND is_active = 1`, there is no boot-time registry and no migration that backfills only older rows. The three-line AUTH log the reporter pasted is reachable from exactly one place: the pool arriving EMPTY at the key-policy filter. Every post-query skip produces a different message ("all N accounts unavailable"). So the connections exist and are active; the calling key's `allowed_connections` / quota scope removed them — the shape you get from a key minted before those providers existed, which is also why the older providers on that key keep working. The real defect is that nothing ever said so. `/test` and `/sync-models` address a connection by id and never consult the key's scope, so they cannot contradict it, and the one log line that hinted at the filter became `debug` in #11937. `getProviderCredentials` now counts the connections it had before applying the key policy and, when that filter is what emptied the pool, returns `{ blockedByKeyPolicy, blockedCount }` instead of a bare null. `handleNoCredentials` turns it into a 403 naming the allowlist and the fix, alongside the existing allRateLimited/allExpired branches. 403, not 401: the credential is valid, this principal just may not use it. Test is red-first in tests/unit/chat-helpers.test.ts (it asserts the status, the count and that the message names the gate). This does not close the report on its own — it makes the next occurrence self-explanatory. The reporter still needs to confirm their key's allowed_connections/allowed_quotas.