Record Step 3 completion: broker for member API keys

This commit is contained in:
inference-bot committed 2026-09-14 09:45:53 -06:00
1 parent 463abaa68a
commit 9d07b2cf23
1 file changed
+6 -2
+6 -2
View File
@@ -154,8 +154,12 @@ Member (browser) ──SSO──▶ Member Dashboard (new Cloudron app, "members
### Step 3 — Broker (Phase 2) ### Step 3 — Broker (Phase 2)
- Add token-protected `create-key` / `revoke-key` endpoints in the portal, scoped to a member's team, rate-limited. **COMPLETED (2026-09-13).** The portal now serves as the broker for member-managed API keys.
- **Gate:** mint a key for a test member, confirm it draws from their team budget and appears under their team; revoke works.
- Added `member_api_keys` table (email + name → sk_token + hash) and three endpoints under `/broker/keys` (GET list, POST create, DELETE revoke).
- Authentication: the member dashboard passes `X-Broker-Secret` (shared secret, `BROKER_SECRET` env) + `X-Member-Email`. The portal verifies the secret and that the email is an active member. Fail-closed: missing/wrong secret → 401, non-member → 403.
- Each API key is a LiteLLM virtual key under the member's team (`alias: api:<email>:<name>`), so it draws from the same $15 team budget as chat. The `sk-` token is returned once and stored; the hash is kept for revoke.
- Verified: create/list/revoke all work; the API key completes real inference; security boundaries hold (wrong secret 401, non-member 403, no-secret 401).
### Step 4 — Member dashboard (Phase 3) ### Step 4 — Member dashboard (Phase 3)