fix(openrouter): trim API key and guard against empty key

An OpenRouter key with trailing whitespace/newline (common from
copy-paste) produces "Missing Authentication header" from their API,
which looked identical to a missing key. Trim apiKey on save (schema
level) and on use (defense in depth), fail fast with a clear message
if the stored key is empty, and log a masked key preview + model on
each generation call to make future auth failures diagnosable from
container logs.
This commit is contained in:
Claude committed 2026-07-14 06:25:47 +00:00
1 parent 09b4e597ae
commit de7fc7d03c
2 files changed
+10 -3

No files matched your search

+9 -2
View File
@@ -26,16 +26,23 @@ export class OpenRouterService {
throw new Error('Configuration OpenRouter non trouvée. Veuillez demander à un administrateur de configurer OpenRouter dans les Paramètres.');
}
if (!config.apiKey || !config.apiKey.trim()) {
throw new Error('Clé API OpenRouter manquante ou vide en base de données. Veuillez la ressaisir dans les Paramètres.');
}
const prompt = this.buildPrompt(productInfo, config.systemPrompt);
// Use provided model or fall back to config model
const modelToUse = modelOverride || config.model;
const keyPreview = `${config.apiKey.slice(0, 10)}...(len=${config.apiKey.length})`;
console.log(`[OpenRouter] Generating with model="${modelToUse}" key=${keyPreview} configUserId=${config.userId}`);
try {
const response = await fetch(this.baseUrl, {
method: "POST",
headers: {
"Authorization": `Bearer ${config.apiKey}`,
"Authorization": `Bearer ${config.apiKey.trim()}`,
"Content-Type": "application/json",
"HTTP-Referer": process.env.APP_URL || "http://localhost:5555",
"X-Title": "Social Flow"
+1 -1
View File
@@ -394,7 +394,7 @@ export const insertOpenrouterConfigSchema = createInsertSchema(openrouterConfig)
createdAt: true,
updatedAt: true,
}).extend({
apiKey: z.string().min(1, "La clé API ne peut pas être vide"),
apiKey: z.string().trim().min(1, "La clé API ne peut pas être vide"),
});
export const updateOpenrouterConfigSchema = insertOpenrouterConfigSchema.partial({