fix(backend): inject provider credentials from file

This commit is contained in:
2026-07-12 07:53:22 +02:00
parent ee92ef45ab
commit e40a9d9a56
13 changed files with 280 additions and 15 deletions
+13
View File
@@ -1,3 +1,5 @@
import path from "node:path";
export interface AppConfig {
host: string; port: number; harnessDir: string; thtBin: string; piBin: string;
authMode: "none" | "mock" | "upstream";
@@ -6,6 +8,7 @@ export interface AppConfig {
settingsFile: string;
dataRoot?: string;
ollamaEnsureTimeoutMs: number;
modelApiKeyFile?: string;
}
export function loadConfig(env: Record<string, string | undefined>): AppConfig {
const authMode = env.AUTH_MODE ?? "none";
@@ -15,6 +18,15 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
if (env.THOTH_PUBLIC_EXPOSURE === "true" && authMode !== "upstream") {
throw new Error("public exposure requires AUTH_MODE=upstream behind a trusted proxy");
}
const modelApiKeyFile = env.THT_MODEL_API_KEY_FILE;
if (modelApiKeyFile !== undefined && (
modelApiKeyFile.trim() !== modelApiKeyFile
|| modelApiKeyFile.length === 0
|| modelApiKeyFile.includes("\0")
|| !path.isAbsolute(modelApiKeyFile)
)) {
throw new Error("model credential configuration is invalid");
}
return {
host: env.HOST ?? "127.0.0.1",
port: Number(env.PORT ?? 8787),
@@ -27,5 +39,6 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
settingsFile: env.SETTINGS_FILE ?? "data/settings.json",
dataRoot: env.THT_DATA_ROOT,
ollamaEnsureTimeoutMs: Number(env.OLLAMA_ENSURE_TIMEOUT_MS ?? 60000),
modelApiKeyFile,
};
}