You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Platform tokens follow-ups: edge reject on inference routes, per-IP limiter, revoke on sign-out-all #167
Edge (nan-devops, Worker api-edge-normaliser): reject Authorization: Bearer nan_pat_... (any whitespace, tabs incl.) on every non-platform route of api.nan.builders, so inference routes served directly by LiteLLM (/v1/chat/completions, /v1/responses, /v1/embeddings, ...) never even receive a PAT. LiteLLM already 401s them; this is defence in depth. Tests: byte-identical behavior for sk- keys; /v1/runs* passthrough unchanged.
cloud-api: per-IP limiter for malformed/unknown PATs (each well-formed unknown token costs one DB lookup; 256-bit tokens are unguessable, this is load protection only), mirroring the sk- key limiter.
cloud-ui: "Sign out of all sessions" should offer to revoke platform tokens too.
Additional follow-ups (from the API reference review, 2026-10-10):
cloud-api: the session_required 401 message ("API keys only work for inference") is outdated since member sk- keys and nan_pat_ tokens work on GET /api/workspaces[/{uuid}] and /v1/runs*. Reword it (the website docs quote it verbatim in src/data/openapi.json; update both together).
Document the 429 / 500 bodies the /api auth layer can return in the API reference.
Follow-up from T-167 (cloud-api #326): the per-IP limiter for rejected platform tokens (30/min, burst 5) also 429s VALID tokens from the same IP once the bucket is spent. Workspaces egress through their host's public IP, so a misbehaving agent in one member's workspace could briefly 429 another member's valid PAT calls from the same host (same property as the existing sk- limiter). Options: exempt the fleet egress IPs (devops fleet registry) from the IP bucket and rely on per-token limits there, or key the bucket by token prefix + IP.
Follow-ups from cloud-api #323 review (#166).
api-edge-normaliser): rejectAuthorization: Bearer nan_pat_...(any whitespace, tabs incl.) on every non-platform route of api.nan.builders, so inference routes served directly by LiteLLM (/v1/chat/completions, /v1/responses, /v1/embeddings, ...) never even receive a PAT. LiteLLM already 401s them; this is defence in depth. Tests: byte-identical behavior for sk- keys; /v1/runs* passthrough unchanged.