fix: gate Model Prefs picker behind BYOK access (v0.73.1)

Settings -> AI's model-selection form (per-use-case provider + model
ID picker) had no access gate -- every user could see and use it,
regardless of whether they had a BYOK key to route calls to or any
reason to care which model served a request. Now gated behind
isByokEnabled, same reasoning as BYOK itself: picking a specific
provider/model only makes sense once you have your own key. Hidden
entirely for everyone else, not locked-and-teased -- there's nothing
for a non-BYOK user to unlock here.

GET/PUT /api/v1/users/me/model-prefs switched from requireSession to
requireByok to match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-24 09:13:36 +02:00
parent d230098b1e
commit a834695609
8 changed files with 34 additions and 20 deletions
@@ -1,6 +1,6 @@
import { type NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { requireSession } from "@/lib/api-auth";
import { requireByok } from "@/lib/api-auth";
import { db, userModelPrefs, eq } from "@epicure/db";
const Schema = z.object({
@@ -13,7 +13,7 @@ const Schema = z.object({
});
export async function GET() {
const { session, response } = await requireSession();
const { session, response } = await requireByok();
if (response) return response;
const prefs = await db.query.userModelPrefs.findFirst({
@@ -24,7 +24,7 @@ export async function GET() {
}
export async function PUT(req: NextRequest) {
const { session, response } = await requireSession();
const { session, response } = await requireByok();
if (response) return response;
const body = Schema.safeParse(await req.json());