Only enforce model rules when the request carries a model - #163
Merged
J3rome merged 4 commits intoAug 27, 2026
Conversation
Requests without a model were denied whenever a provider or grant configured `capability.models`, because an absent model was matched against the pattern list and failed. This blocked legitimate requests to endpoints that carry no model at all, such as `GET /v1/models`. Model patterns are now evaluated only when the request actually carries a model: an absent model no longer fails a restriction, while a model that is present must still match. Provider and user-agent matching are unchanged, so a missing user agent still fails a non-empty pattern list. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
J3rome
reviewed
Aug 26, 2026
J3rome
reviewed
Aug 26, 2026
J3rome
reviewed
Aug 26, 2026
J3rome
reviewed
Aug 26, 2026
J3rome
reviewed
Aug 26, 2026
added 2 commits
August 26, 2026 14:31
J3rome
approved these changes
Aug 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requests that carry no model were denied whenever
capability.modelswas configured, because an absent model was matched against the pattern list and failed. This blocked legitimate endpoints that have no model, notablyGET /v1/models, which returned 403.Model patterns are now checked only when the request actually carries a model. A model that is present must still match.