[feat] plugin: optional API key for the AI summary LLM server

Servers that require authentication (e.g. vLLM or llama.cpp started with
--api-key, or an LLM server behind an authenticating reverse proxy) can
now be configured with an ai_summary.api_key, sent as "Authorization:
Bearer".

The key is administrator configuration only: there is no preference for
it, and it is only sent to the configured base_url.  Users can point the
ai_summary_server preference at a server of their own, and such a server
must not be handed the instance API key -- otherwise every user of the
instance could capture it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
jasonwitty
2026-08-05 23:04:17 -07:00
co-authored by Claude Opus 5
parent 4abb7dba67
commit 19cc7a6f9f
5 changed files with 190 additions and 4 deletions
+5
View File
@@ -297,6 +297,11 @@ plugins:
# # ai_summary_server preference.
# base_url: "http://127.0.0.1:11434"
#
# # API key of the server above, if it requires authentication (e.g. vLLM or
# # llama.cpp with --api-key). Sent as "Authorization: Bearer" and only to
# # base_url, never to a server configured by a user in the preferences.
# api_key: ""
#
# # Default model; if empty, the first entry of models: is used.
# model: "llama3.2:3b"
#