openai api server - last two api calls not protected with check_api_key when used with api keys
Open
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 39.5k
- Forks
- 4.8k
- PR merge metrics
- No merged PRs in 30d
Description
While playing around with the --api-keys option on the openai_api_server.py I noticed that the last two api calls are not protected with check_api_key. Is this intended?
- /api/v1/chat/completions
- /api/v1/token_check
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in openai_api_server.py and inspect the handlers for /api/v1/chat/completions and /api/v1/token_check, along with the existing check_api_key usage. Confirm the expected behavior when --api-keys is enabled and ensure both endpoints follow that protection consistently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- api, authentication
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100