Skip to content

feat(web): manage access policies on native API keys - #478

Draft
linonetwo wants to merge 2 commits into
seakee:mainfrom
linonetwo:feature/native-key-access-policy-ui
Draft

feat(web): manage access policies on native API keys#478
linonetwo wants to merge 2 commits into
seakee:mainfrom
linonetwo:feature/native-key-access-policy-ui

Conversation

@linonetwo

Copy link
Copy Markdown

Summary

Adds an optional Access & quotas action to the existing CPA native api-keys card. It does not add another key list or issue a second downstream key. The modal binds policy by the existing key's SHA-256 and configures provider/model grants plus request/token quotas through the plugin Management API.

Motivation

A policy plugin that creates its own keys duplicates CPA's native authentication and CPAMP aliases. Operators then have to synchronize two identities and plaintext keys. The desired model is:

  • CPA/this existing CPAMP card creates, copies, renames and deletes the native key.
  • CPAMP api_key_aliases remains the display-name source.
  • The policy plugin stores authorization and quota state by hash only.

API

Uses cpa-key-policy native-access endpoints:

  • GET/PUT /v0/management/plugins/cpa-key-policy/policies
  • PUT /v0/management/plugins/cpa-key-policy/policies/bulk

Provider and model values support exact names plus * and ? wildcards. UI and external automation share the same API.

Compatibility

The action is additive and only appears as an optional integration. Includes zh-CN, zh-TW, en and ru strings. The backend work is tracked in origin652/cpa-plugin-key-policy#6 and model catalog filtering in router-for-me/CLIProxyAPI#4766.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant