fix: stop returning model api keys and voice credentials to the frontend - #4037
Open
jeffwu-1999 wants to merge 3 commits into
Open
jeffwu-1999 wants to merge 3 commits into
jeffwu-1999 wants to merge 3 commits into
Conversation
- /config/load_config: build_model_config no longer echoes the stored api_key (and the STT/TTS model_appid / access_token pair); the config page never displays or resubmits these fields from this payload, so nothing breaks by omitting them - /model/* list responses: _sanitize_model_credentials now also strips model_appid / access_token, which are the full auth material for Volcano Engine STT/TTS models - update path: empty-string model_appid / access_token are dropped from the update payload instead of overwriting stored values, mirroring the existing "empty api_key means keep" contract the edit dialog relies on - tests: cover the extended sanitization and the keep-existing update semantics; update assertions that previously expected raw keys
jeffwu-1999
requested review from
Dallas98,
WMC001,
YehongPan and
hhhhsc701
as code owners
September 29, 2026 08:42
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
The batch connection-edit path sent api_key unconditionally, so an
operator who left the key field untouched submitted an empty string.
List responses never carry stored keys, so sending "" both echoed a
credential-shaped field back to the server and overwrote the stored key
with an empty value.
Guard it the same way the single-model edit dialog does (apiKey.trim() ?
{ apiKey } : {}), keeping the "empty means keep existing credential"
contract consistent across both edit paths.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
变更说明 / What Changed
修改模型时 api-key 等凭证返回前端。模型列表接口此前已剥离api_key,但仍有两个泄露路径,本 PR 一并堵住:
stored api_key, nor the STT/TTS model_appid / access_token pair. The
config page never displays or resubmits these fields from this payload,
so nothing breaks by omitting them
strip model_appid / access_token — the full auth material for Volcano
Engine STT/TTS models, previously returned in cleartext
update payload instead of overwriting stored values, mirroring the
existing "empty api_key means keep" contract the edit dialog relies on
the keep-existing update semantics; update assertions that previously
expected raw keys
验证 / Verification
影响面 / Impact