a834695609
Settings -> AI's model-selection form (per-use-case provider + model ID picker) had no access gate -- every user could see and use it, regardless of whether they had a BYOK key to route calls to or any reason to care which model served a request. Now gated behind isByokEnabled, same reasoning as BYOK itself: picking a specific provider/model only makes sense once you have your own key. Hidden entirely for everyone else, not locked-and-teased -- there's nothing for a non-BYOK user to unlock here. GET/PUT /api/v1/users/me/model-prefs switched from requireSession to requireByok to match. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
43 lines
1.4 KiB
TypeScript
43 lines
1.4 KiB
TypeScript
import { type NextRequest, NextResponse } from "next/server";
|
|
import { z } from "zod";
|
|
import { requireByok } from "@/lib/api-auth";
|
|
import { db, userModelPrefs, eq } from "@epicure/db";
|
|
|
|
const Schema = z.object({
|
|
textProvider: z.string().nullable().optional(),
|
|
textModel: z.string().nullable().optional(),
|
|
visionProvider: z.string().nullable().optional(),
|
|
visionModel: z.string().nullable().optional(),
|
|
mealPlanProvider: z.string().nullable().optional(),
|
|
mealPlanModel: z.string().nullable().optional(),
|
|
});
|
|
|
|
export async function GET() {
|
|
const { session, response } = await requireByok();
|
|
if (response) return response;
|
|
|
|
const prefs = await db.query.userModelPrefs.findFirst({
|
|
where: eq(userModelPrefs.userId, session!.user.id),
|
|
});
|
|
|
|
return NextResponse.json(prefs ?? null);
|
|
}
|
|
|
|
export async function PUT(req: NextRequest) {
|
|
const { session, response } = await requireByok();
|
|
if (response) return response;
|
|
|
|
const body = Schema.safeParse(await req.json());
|
|
if (!body.success) return NextResponse.json({ error: "Invalid request" }, { status: 400 });
|
|
|
|
await db
|
|
.insert(userModelPrefs)
|
|
.values({ id: crypto.randomUUID(), userId: session!.user.id, ...body.data, updatedAt: new Date() })
|
|
.onConflictDoUpdate({
|
|
target: userModelPrefs.userId,
|
|
set: { ...body.data, updatedAt: new Date() },
|
|
});
|
|
|
|
return NextResponse.json({ ok: true });
|
|
}
|