[feat] plugin: optional API key for the AI summary LLM server

Servers that require authentication (e.g. vLLM or llama.cpp started with
--api-key, or an LLM server behind an authenticating reverse proxy) can
now be configured with an ai_summary.api_key, sent as "Authorization:
Bearer".

The key is administrator configuration only: there is no preference for
it, and it is only sent to the configured base_url.  Users can point the
ai_summary_server preference at a server of their own, and such a server
must not be handed the instance API key -- otherwise every user of the
instance could capture it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
jasonwitty
2026-08-05 23:04:17 -07:00
co-authored by Claude Opus 5
parent 4abb7dba67
commit 19cc7a6f9f
5 changed files with 190 additions and 4 deletions
+13
View File
@@ -49,6 +49,19 @@ class SettingsAISummary(msgspec.Struct, kw_only=True, forbid_unknown_fields=True
can set their own server URL in the preferences (``ai_summary_server``)
unless that preference is locked."""
api_key: str = ""
"""Optional API key of the LLM server in
:py:obj:`SettingsAISummary.base_url`, sent in an ``Authorization: Bearer``
header. Needed by servers that require authentication, e.g. vLLM or
llama.cpp started with ``--api-key``, or an LLM server behind an
authenticating reverse proxy.
There is intentionally no user preference for the API key, and the key is
**only** sent to :py:obj:`SettingsAISummary.base_url`: a user who points
the ``ai_summary_server`` preference at a server of their own gets no
``Authorization`` header, so the key can't be captured by a third party
(see :py:obj:`searx.plugins.ai_summary._server_api_key`)."""
model: str = ""
"""Name of the default model (e.g. ``llama3.2:3b``). If empty, the first
entry of :py:obj:`SettingsAISummary.models` is used. Users can set their