fix(ai-gateway): redact upstream URL from auth errors (without_url); forward model to verify

This commit is contained in:
Ishaan Jaff 2026-06-24 13:03:28 -07:00
parent 1584b703da
commit d7059c6c58
No known key found for this signature in database

View file

@ -47,15 +47,22 @@ impl PythonAuthClient {
#[axum::async_trait]
impl KeyAuthenticator for PythonAuthClient {
async fn verify(&self, key: &str, route: &str) -> Result<UserApiKeyAuth, AuthError> {
async fn verify(
&self,
key: &str,
route: &str,
model: Option<&str>,
) -> Result<UserApiKeyAuth, AuthError> {
let response = self
.http
.post(&self.verify_url)
.header(DATA_PLANE_KEY_HEADER, &self.data_plane_key)
.json(&serde_json::json!({ "api_key": key, "route": route }))
.json(&serde_json::json!({ "api_key": key, "route": route, "model": model }))
.send()
.await
.map_err(|err| AuthError::Upstream(err.to_string()))?;
// `without_url()` strips the target URL from the error — otherwise the
// internal proxy address would leak into AuthError::Upstream.
.map_err(|err| AuthError::Upstream(format!("network error: {}", err.without_url())))?;
let status = response.status();
if status == StatusCode::UNAUTHORIZED {