[feat] plugin: optional API key for the AI summary LLM server
Servers that require authentication (e.g. vLLM or llama.cpp started with --api-key, or an LLM server behind an authenticating reverse proxy) can now be configured with an ai_summary.api_key, sent as "Authorization: Bearer". The key is administrator configuration only: there is no preference for it, and it is only sent to the configured base_url. Users can point the ai_summary_server preference at a server of their own, and such a server must not be handed the instance API key -- otherwise every user of the instance could capture it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
4abb7dba67
commit
19cc7a6f9f
@@ -49,6 +49,19 @@ class SettingsAISummary(msgspec.Struct, kw_only=True, forbid_unknown_fields=True
|
||||
can set their own server URL in the preferences (``ai_summary_server``)
|
||||
unless that preference is locked."""
|
||||
|
||||
api_key: str = ""
|
||||
"""Optional API key of the LLM server in
|
||||
:py:obj:`SettingsAISummary.base_url`, sent in an ``Authorization: Bearer``
|
||||
header. Needed by servers that require authentication, e.g. vLLM or
|
||||
llama.cpp started with ``--api-key``, or an LLM server behind an
|
||||
authenticating reverse proxy.
|
||||
|
||||
There is intentionally no user preference for the API key, and the key is
|
||||
**only** sent to :py:obj:`SettingsAISummary.base_url`: a user who points
|
||||
the ``ai_summary_server`` preference at a server of their own gets no
|
||||
``Authorization`` header, so the key can't be captured by a third party
|
||||
(see :py:obj:`searx.plugins.ai_summary._server_api_key`)."""
|
||||
|
||||
model: str = ""
|
||||
"""Name of the default model (e.g. ``llama3.2:3b``). If empty, the first
|
||||
entry of :py:obj:`SettingsAISummary.models` is used. Users can set their
|
||||
|
||||
Reference in New Issue
Block a user