Repository navigation
fix(ai-gateway): resolve permission error when allow all models is configured (#3629) - #3732
Open
Adityakk9031 wants to merge 32 commits into
Open
Adityakk9031 wants to merge 32 commits into
Adityakk9031 wants to merge 32 commits into
Conversation
feat: Master table of orgs in server admin
feat: allow multiple server admins
Adityakk9031
requested review from
miloschwartz and
oschwartz10612
as code owners
September 12, 2026 20:41
oschwartz10612
force-pushed
the
dev
branch
2 times, most recently
from
September 15, 2026 14:56
a9ac442 to
c6c12f1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
close: #3629
Description & Root Cause
When configuring an AI Provider (such as Custom, OpenRouter, or Vercel AI Gateway) with Allow List set to "Allow all models" (
*), requests from AI clients like Open Code (e.g., testing with models such asunsloth/Qwen3.8-27B-GGUF:UD-Q4_K_XL) failed with a proxy/permissions error (404 Not Foundreturned as a forbidden/proxy failure).Investigation revealed two root causes:
GET /v1/models/:model:*is a wildcard pattern,expandProviderModelsdoes not expand it into explicit model IDs. For aggregator/custom providers,provider.catalogwas empty because they lack a fixed vendor prefix catalog.GET /v1/models/:modelfor a model allowed by wildcard,handleV1Modelswas only searching the pre-enumeratedmodelsarray (models.find), returning404 Not Foundinstead of checking if any attached provider allows the requested model via wildcard patterns (isAllowedByLists).catalogOwnershipScore(server/lib/aiProviderSelection.ts), unknown/custom models not in the static catalog scored0for all providers.compareProviderCandidates, typed providers (e.g.openai, class rank 2) were preferred over custom providers (class rank 0), mistakenly routing non-catalog / self-hosted models to native vendor endpoints that cannot serve them.Changes Made
server/routers/aiGateway/v1Models.ts:catalogMetadataForType: Populated catalog entries forcustom,openRouter, andvercelAiGatewayusingaiModelCatalog.getAll()so wildcard matching has full catalog metadata.handleV1Models: ForGET /v1/models/:model, added fallback wildcard validation withisAllowedByLists(requestedModel, p.allows, p.blocks)across discovery providers before returning 404.server/lib/aiModelDiscovery.ts:expandProviderModelscandidates.server/lib/aiProviderSelection.ts&docs/ai-gateway-provider-selection.md:catalogOwnershipScoreso aggregator/custom providers score1for unknown/custom models while typed providers score0(typed catalog miss), properly routing custom models to custom/aggregator providers.Verification
npm run dev:check: All TypeScript type checks and Prettier formatting passed (0 errors).node esbuild.mjs -e server/index.ts -o dist/server.mjs) succeeded.