fix(backend): harden provider credential isolation

This commit is contained in:
2026-07-12 08:05:51 +02:00
parent 32e73d66b5
commit f064daef09
6 changed files with 275 additions and 70 deletions
+5 -1
View File
@@ -1,6 +1,7 @@
import { spawn as nodeSpawn, type ChildProcessWithoutNullStreams } from "node:child_process";
import type { AppConfig } from "../config.js";
import { RpcClient } from "../rpc/rpc-client.js";
import { buildPiChildEnv } from "./provider-credentials.js";
export interface PiModel {
provider: string;
@@ -34,7 +35,10 @@ export function createPiModelLister(cfg: AppConfig, opts: Opts = {}): () => Prom
return async function listModels(): Promise<PiModel[]> {
if (cache && now() - cache.at < ttlMs) return cache.models;
const env: NodeJS.ProcessEnv = { ...process.env };
const env = buildPiChildEnv({
provider: cfg.defaults.provider,
credentialFile: cfg.modelApiKeyFile,
});
delete env.THT_DATA_ROOT;
if (cfg.dataRoot !== undefined) env.THT_DATA_ROOT = cfg.dataRoot;
const child = spawnFn(cfg.piBin, ["--mode", "rpc"], { cwd: cfg.harnessDir, env });