fix: gate Model Prefs picker behind BYOK access (v0.73.1)
Settings -> AI's model-selection form (per-use-case provider + model ID picker) had no access gate -- every user could see and use it, regardless of whether they had a BYOK key to route calls to or any reason to care which model served a request. Now gated behind isByokEnabled, same reasoning as BYOK itself: picking a specific provider/model only makes sense once you have your own key. Hidden entirely for everyone else, not locked-and-teased -- there's nothing for a non-BYOK user to unlock here. GET/PUT /api/v1/users/me/model-prefs switched from requireSession to requireByok to match. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -88,15 +88,17 @@ export default async function AiSettingsPage() {
|
||||
)}
|
||||
</section>
|
||||
|
||||
<section className="rounded-xl border p-6 space-y-4">
|
||||
<div>
|
||||
<h2 className="font-semibold text-lg">{m.settings.modelPrefs.title}</h2>
|
||||
<p className="text-sm text-muted-foreground mt-1">
|
||||
{m.settings.modelPrefs.description}
|
||||
</p>
|
||||
</div>
|
||||
<ModelPrefsForm initialPrefs={modelPrefs ?? null} />
|
||||
</section>
|
||||
{dbUser?.isByokEnabled && (
|
||||
<section className="rounded-xl border p-6 space-y-4">
|
||||
<div>
|
||||
<h2 className="font-semibold text-lg">{m.settings.modelPrefs.title}</h2>
|
||||
<p className="text-sm text-muted-foreground mt-1">
|
||||
{m.settings.modelPrefs.description}
|
||||
</p>
|
||||
</div>
|
||||
<ModelPrefsForm initialPrefs={modelPrefs ?? null} />
|
||||
</section>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import { type NextRequest, NextResponse } from "next/server";
|
||||
import { z } from "zod";
|
||||
import { requireSession } from "@/lib/api-auth";
|
||||
import { requireByok } from "@/lib/api-auth";
|
||||
import { db, userModelPrefs, eq } from "@epicure/db";
|
||||
|
||||
const Schema = z.object({
|
||||
@@ -13,7 +13,7 @@ const Schema = z.object({
|
||||
});
|
||||
|
||||
export async function GET() {
|
||||
const { session, response } = await requireSession();
|
||||
const { session, response } = await requireByok();
|
||||
if (response) return response;
|
||||
|
||||
const prefs = await db.query.userModelPrefs.findFirst({
|
||||
@@ -24,7 +24,7 @@ export async function GET() {
|
||||
}
|
||||
|
||||
export async function PUT(req: NextRequest) {
|
||||
const { session, response } = await requireSession();
|
||||
const { session, response } = await requireByok();
|
||||
if (response) return response;
|
||||
|
||||
const body = Schema.safeParse(await req.json());
|
||||
|
||||
Reference in New Issue
Block a user