Aias00 opened a new issue, #6471:
URL: https://github.com/apache/shenyu/issues/6471
### Current Behavior
When AI proxy key mode is enabled, the request path resolves the real
upstream API key from the incoming `X-API-KEY` header and writes it into
`primaryConfig`:
```java
final String realKey =
AiProxyApiKeyCache.getInstance().getRealApiKey(selector.getId(), proxyApiKey);
if (Objects.nonNull(realKey)) {
primaryConfig.setApiKey(realKey);
}
```
But the main chat client cache key explicitly excludes `apiKey`:
```java
return Objects.hash(
config.getProvider(),
config.getBaseUrl(),
config.getModel(),
config.getTemperature(),
config.getMaxTokens(),
config.getStream()
// Explicitly exclude apiKey
);
```
The cached `ChatClient` is reused by selector/config hash, while the Spring
AI model factory embeds the API key when the model is created. This means the
first request that warms the cache can determine the upstream API key used by
later requests with different proxy keys but the same selector/model settings.
### Expected Behavior
Proxy-key mode should not reuse a cached upstream client across different
resolved real API keys, or the request-time credential should be injected in a
way that is not captured by a shared cached model.
### Impact
Different tenants or callers using different Shenyu proxy keys can be routed
to the wrong upstream AI account/key after the first cache warm-up. That can
cause incorrect billing, quota usage, and authorization isolation issues.
### Code Location
-
`shenyu-plugin/shenyu-plugin-ai/shenyu-plugin-ai-proxy/src/main/java/org/apache/shenyu/plugin/ai/proxy/enhanced/AiProxyPlugin.java`
- `proxyApiKey` is resolved and assigned to `primaryConfig.apiKey`.
- `generateConfigCacheKey()` excludes `apiKey`.
- `createMainChatClient()` reuses the cached client by selector/config
hash.
-
`shenyu-plugin/shenyu-plugin-ai/shenyu-plugin-ai-common/src/main/java/org/apache/shenyu/plugin/ai/common/spring/ai/factory/OpenAiModelFactory.java`
-
`shenyu-plugin/shenyu-plugin-ai/shenyu-plugin-ai-common/src/main/java/org/apache/shenyu/plugin/ai/common/spring/ai/factory/DeepSeekModelFactory.java`
- factories build model instances with the API key from config.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]