From 6564508e1df8f69a93fdc09475a7e85c8f43bb95 Mon Sep 17 00:00:00 2001 From: inference-bot Date: Wed, 23 Sep 2026 20:10:23 -0600 Subject: [PATCH] Remove per-member model allowlist: members access all gateway models (empty models = all allowed) --- app/main.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/app/main.py b/app/main.py index 3a4c044..ee5272c 100644 --- a/app/main.py +++ b/app/main.py @@ -104,7 +104,12 @@ MEMBER_BUDGET = float(os.environ.get("MEMBER_BUDGET", "15.0")) REINVITE_AFTER_DAYS = float(os.environ.get("REINVITE_AFTER_DAYS", "3")) # Models every member key/team may access. -MEMBER_MODELS = ["deepseek-v4-1-flash", "gpt-oss-120b", "glm-5-3-flash"] +# Deliberately REMOVED: members get access to every model the gateway serves. +# The gateway's `model_list` is the single source of truth for what's available; +# teams and keys carry no per-model restriction (empty = "all models allowed" in +# LiteLLM). Adding a provider is a gateway-config change only — no team/key +# migration. (Kept as a documented empty value so the intent is explicit.) +MEMBER_MODELS: list[str] = [] # The "members" group in Cloudron (group-based access control). # Members are assigned to this group, which grants access to the chat app.