Upgrade to Sub2API v0.2.13 and harden verified build dependencies - #62
Merged
Merged
Conversation
The create form shows the upstream billing auto-probe toggle for every
API-key platform and enables it by default. TypeSafe was added as an
API-key platform but not to IsUpstreamBillingProbeIdentity, so creating a
TypeSafe account with the default form state fails with
400 UPSTREAM_BILLING_PROBE_ACCOUNT_INVALID ("account is not an API key
account").
TypeSafe accounts store credentials.api_key/base_url like every other
API-key platform, which is all the probe reads. Add TypeSafe to the probe
identity set, and add typesafe.ai to the official API domains so accounts
on the default https://api.typesafe.ai base URL record "unsupported"
without sending the key to a path that cannot exist, matching the other
official providers.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: add security policy with private vulnerability reporting
… completes When an API key with quota or rate limits was deleted while a request was still in flight, the key counter update matched no rows and returned ErrAPIKeyNotFound, rolling back the whole billing transaction including the balance/subscription charge. Skip the key-scoped counters in that case and keep settling the user and account side as usual.
fix(billing): settle usage when the API key is deleted before billing completes
…ng-probe fix(billing): allow upstream billing probe for TypeSafe API-key accounts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This upgrades the fixed Sub2API baseline from v0.2.12 to v0.2.13 while preserving Zero One contracts and the approved production UI.
A request whose API Key is deleted before settlement now still bills the user transactionally; only the missing key counters are skipped, and genuine database errors still fail. TypeSafe API Key account creation accepts the default upstream billing probe setting, with official endpoints retaining the unsupported/no-request policy. Existing account-cost snapshots, financial records, authorization and monitor ownership remain intact. There are no new migrations.
The build toolchain also mitigates newly reviewed GHSA-vfj7-8cjw-p6xm with a locked pnpm braces depth patch, adversarial/normal caller regressions and a security-CI prerequisite. The exact advisory exception expires on 2026-10-17 because no upstream fix is published; the raw audit still reports the package version. Landing Vitest moves to 4.1.11 to remove its mocker advisory. Both Docker builders install the patch before frozen dependencies; the deployment builder heap cap becomes 3 GiB after reproducing typecheck OOM at 1.5 GiB.
Baseline/provenance, current operations docs and the deterministic seven-path change map are updated. Nineteen reviewed screenshots differ only inside the version badge; historical production assets stay byte-identical. The approved UI tag fixes the final source/snapshot set.
Validation:
make test: ordinary/unit/integration Go suites, zero lint issues, 308 Console files / 2,255 tests, and 18 Landing files / 134 tests.Production deployment requires successful exact-main product/security evidence, paired same-SHA multi-architecture images, a fresh encrypted off-host restore/rehearsal, unchanged migration ledger and business-column fingerprints, Backend-first cutover with watchdog, dedicated model probes and at least 30 minutes of observation. Recovery data and credentials remain outside Git.