API-key normalization and model-discovery snapshot validation

This commit is contained in:
Brandon Hopkins
2026-07-26 18:58:39 -07:00
parent 0463b30152
commit fea131101d
4 changed files with 61 additions and 11 deletions
@@ -110,11 +110,7 @@ func (p *Provider) FromAPIRequest(req *api.AgentNetworkProviderRequest) {
p.UpstreamURL = req.UpstreamUrl
p.APIKeyProvided = req.ApiKey != nil
if req.ApiKey != nil {
if strings.TrimSpace(*req.ApiKey) == "" {
p.APIKey = ""
} else {
p.APIKey = *req.ApiKey
}
p.APIKey = strings.TrimSpace(*req.ApiKey)
}
if req.ExtraValues != nil {
// Replace the whole map (rather than merge) so unsetting a
@@ -100,6 +100,14 @@ func TestProvider_APIKeyPresenceAndResponse(t *testing.T) {
assert.Equal(t, key, p.APIKey)
assert.True(t, p.ToAPIResponse().HasApiKey)
paddedKey := " \tprotected-endpoint-token\n"
withPaddedKey := base()
withPaddedKey.ApiKey = &paddedKey
p.FromAPIRequest(withPaddedKey)
assert.True(t, p.APIKeyProvided)
assert.Equal(t, key, p.APIKey, "non-blank API keys must be normalized before storage")
assert.True(t, p.ToAPIResponse().HasApiKey, "the response must reflect the normalized stored key")
empty := ""
clearKey := base()
clearKey.ApiKey = &empty