mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-09-01 17:10:24 +08:00
Add Ollama Cloud support with Base URL and API Key configuration (#692)
* Add Ollama Cloud support with Base URL and API Key configuration * implemented feedback * fix: use OLLAMA_BASE_URL env fallback in validate-model endpoint * Remove dedicated Ollama configuration block * security(ollama): prevent API key leak to client-controlled URLs * added test * fix: security hardening and Ollama Cloud default URL - Add server OLLAMA_API_KEY fallback to validate-model endpoint with SSRF guard mirroring ai-providers.ts - Tighten top-level SSRF exemption: only exempt Ollama when no server OLLAMA_API_KEY is configured - Update Electron config to support OLLAMA_API_KEY env var - Change default Ollama URL from localhost:11434 to ollama.com/api (Ollama Cloud) for web UI users - Add tests for server env combo, API-key-only, and SSRF guard scenarios --------- Co-authored-by: dayuan.jiang <jdy.toh@gmail.com>
This commit is contained in:
committed by
GitHub
parent
e171fbcdd8
commit
a5d1554c3f
@@ -174,10 +174,21 @@ export async function POST(req: Request) {
|
||||
}
|
||||
|
||||
case "ollama": {
|
||||
const ollama = createOllama({
|
||||
baseURL: baseUrl || "http://localhost:11434",
|
||||
// SECURITY: Mirror ai-providers.ts guard — only use server
|
||||
// OLLAMA_API_KEY when the URL is also from server config.
|
||||
const ollamaApiKey = baseUrl
|
||||
? apiKey || undefined
|
||||
: apiKey || process.env.OLLAMA_API_KEY || undefined
|
||||
const ollamaProvider = createOllama({
|
||||
baseURL:
|
||||
baseUrl ||
|
||||
process.env.OLLAMA_BASE_URL ||
|
||||
"https://ollama.com/api",
|
||||
...(ollamaApiKey && {
|
||||
headers: { Authorization: `Bearer ${ollamaApiKey}` },
|
||||
}),
|
||||
})
|
||||
model = ollama(modelId)
|
||||
model = ollamaProvider(modelId)
|
||||
break
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user