feat(openrouter): validate API key at save time

The stored key that caused the persistent 401s turned out to be only
9 characters long — an accepted-but-truncated paste. Prevent this class
of problem at the source:
- require a minimum key length in the zod schema
- verify new keys against OpenRouter's /api/v1/key endpoint on save,
  rejecting explicit 401/403 (network errors don't block saving)
- return zod validation messages as 400 instead of a generic 500
- surface the server's error message in the settings toast (desktop
  and mobile) instead of a generic failure text
This commit is contained in:
Claude committed 2026-07-14 06:39:01 +00:00
1 parent 75e1d88c26
commit 5550fb05d6
5 files changed
+48 -6

No files matched your search

+16
View File
@@ -215,6 +215,22 @@ VERSION 3 - ÉMOTIONNELLE:
return text.charAt(0).toUpperCase() + text.slice(1).toLowerCase();
}
/**
* Vérifie qu'une clé API est acceptée par OpenRouter.
* Retourne false uniquement sur un rejet d'authentification explicite (401/403) ;
* en cas d'erreur réseau, on laisse passer pour ne pas bloquer la sauvegarde.
*/
async verifyApiKey(apiKey: string): Promise<boolean> {
try {
const response = await fetch("https://openrouter.ai/api/v1/key", {
headers: { "Authorization": `Bearer ${apiKey}` }
});
return response.status !== 401 && response.status !== 403;
} catch {
return true;
}
}
async getAvailableModels(): Promise<any[]> {
try {
const response = await fetch("https://openrouter.ai/api/v1/models", {