fix(backend): reject compound provider credentials
This commit is contained in:
@@ -23,13 +23,9 @@ export const PI_0803_CREDENTIAL_ENV_NAMES = Object.freeze([
|
||||
]);
|
||||
|
||||
const PROVIDER_KEY_ENV: Readonly<Record<string, string>> = {
|
||||
"amazon-bedrock": "AWS_BEARER_TOKEN_BEDROCK",
|
||||
"ant-ling": "ANT_LING_API_KEY",
|
||||
anthropic: "ANTHROPIC_API_KEY",
|
||||
"azure-openai-responses": "AZURE_OPENAI_API_KEY",
|
||||
cerebras: "CEREBRAS_API_KEY",
|
||||
"cloudflare-ai-gateway": "CLOUDFLARE_API_KEY",
|
||||
"cloudflare-workers-ai": "CLOUDFLARE_API_KEY",
|
||||
deepseek: "DEEPSEEK_API_KEY", fireworks: "FIREWORKS_API_KEY",
|
||||
"github-copilot": "COPILOT_GITHUB_TOKEN", google: "GEMINI_API_KEY",
|
||||
"google-vertex": "GOOGLE_CLOUD_API_KEY", groq: "GROQ_API_KEY", huggingface: "HF_TOKEN",
|
||||
@@ -43,6 +39,9 @@ const PROVIDER_KEY_ENV: Readonly<Record<string, string>> = {
|
||||
"xiaomi-token-plan-sgp": "XIAOMI_TOKEN_PLAN_SGP_API_KEY", zai: "ZAI_API_KEY",
|
||||
"zai-coding-cn": "ZAI_CODING_CN_API_KEY",
|
||||
};
|
||||
const COMPOUND_PROVIDERS = new Set([
|
||||
"amazon-bedrock", "azure-openai-responses", "cloudflare-ai-gateway", "cloudflare-workers-ai",
|
||||
]);
|
||||
const LOCAL_PROVIDERS = new Set(["ollama", "lmstudio", "local", "aritmolab", "faux"]);
|
||||
|
||||
export function canonicalPiProvider(provider: string | undefined): string | undefined {
|
||||
@@ -109,6 +108,12 @@ export function buildPiChildEnv(opts: {
|
||||
delete env.THT_MODEL_API_KEY_FILE;
|
||||
for (const name of PI_0803_CREDENTIAL_ENV_NAMES) delete env[name];
|
||||
const provider = canonicalPiProvider(opts.provider);
|
||||
if (provider && COMPOUND_PROVIDERS.has(provider)) {
|
||||
throw new Error(
|
||||
"compound credential bundles are unsupported by THT_MODEL_API_KEY_FILE; "
|
||||
+ "dedicated provider configuration is required",
|
||||
);
|
||||
}
|
||||
if (provider && !LOCAL_PROVIDERS.has(provider)) {
|
||||
const envName = PROVIDER_KEY_ENV[provider];
|
||||
if (!envName || !opts.credentialFile) throw new Error("model provider credential is unavailable");
|
||||
|
||||
Reference in New Issue
Block a user