From 5a67ece2d3e99d5bab6bd1924e2adfca20ba1db2 Mon Sep 17 00:00:00 2001 From: "Andrey A." <56412611+aantti@users.noreply.github.com> Date: Mon, 2 Feb 2026 20:22:48 +0100 Subject: [PATCH] fix: handle auth for ai assistant --- apps/studio/lib/api/apiWrapper.ts | 4 ++-- apps/studio/pages/api/ai/feedback/rate.ts | 3 ++- apps/studio/pages/api/ai/sql/generate-v4.ts | 3 ++- apps/studio/pages/api/ai/sql/policy.ts | 3 ++- 4 files changed, 8 insertions(+), 5 deletions(-) diff --git a/apps/studio/lib/api/apiWrapper.ts b/apps/studio/lib/api/apiWrapper.ts index 901c5a5501b..c5c0c546838 100644 --- a/apps/studio/lib/api/apiWrapper.ts +++ b/apps/studio/lib/api/apiWrapper.ts @@ -1,7 +1,7 @@ import type { NextApiRequest, NextApiResponse } from 'next' import { ResponseError, ResponseFailure } from 'types' -import { IS_PLATFORM } from '../constants' +import { IS_PLATFORM, STUDIO_AUTH_ENABLED } from '../constants' import { apiAuthenticate } from './apiAuthenticate' export function isResponseOk(response: T | ResponseFailure | undefined): response is T { @@ -32,7 +32,7 @@ export default async function apiWrapper( try { const { withAuth } = options || {} - if (IS_PLATFORM && withAuth) { + if ((IS_PLATFORM || STUDIO_AUTH_ENABLED) && withAuth) { const response = await apiAuthenticate(req, res) if (!isResponseOk(response)) { return res.status(401).json({ diff --git a/apps/studio/pages/api/ai/feedback/rate.ts b/apps/studio/pages/api/ai/feedback/rate.ts index 2892cabb6d5..7e9f8b2cf09 100644 --- a/apps/studio/pages/api/ai/feedback/rate.ts +++ b/apps/studio/pages/api/ai/feedback/rate.ts @@ -3,6 +3,7 @@ import { NextApiRequest, NextApiResponse } from 'next' import { z } from 'zod' import { IS_PLATFORM } from 'common' +import { STUDIO_AUTH_ENABLED } from 'lib/constants' import type { AiOptInLevel } from 'hooks/misc/useOrgOptedIntoAi' import { getModel } from 'lib/ai/model' import { getOrgAIDetails } from 'lib/ai/org-ai-details' @@ -37,7 +38,7 @@ export async function handlePost(req: NextApiRequest, res: NextApiResponse) { const authorization = req.headers.authorization const accessToken = authorization?.replace('Bearer ', '') - if (IS_PLATFORM && !accessToken) { + if ((IS_PLATFORM || STUDIO_AUTH_ENABLED) && !accessToken) { return res.status(401).json({ error: 'Authorization token is required' }) } diff --git a/apps/studio/pages/api/ai/sql/generate-v4.ts b/apps/studio/pages/api/ai/sql/generate-v4.ts index 92de85ef6d6..a07a4fcdb17 100644 --- a/apps/studio/pages/api/ai/sql/generate-v4.ts +++ b/apps/studio/pages/api/ai/sql/generate-v4.ts @@ -4,6 +4,7 @@ import type { NextApiRequest, NextApiResponse } from 'next' import z from 'zod' import { IS_PLATFORM } from 'common' +import { STUDIO_AUTH_ENABLED } from 'lib/constants' import { executeSql } from 'data/sql/execute-sql-query' import type { AiOptInLevel } from 'hooks/misc/useOrgOptedIntoAi' import { getModel } from 'lib/ai/model' @@ -59,7 +60,7 @@ async function handlePost(req: NextApiRequest, res: NextApiResponse) { const authorization = req.headers.authorization const accessToken = authorization?.replace('Bearer ', '') - if (IS_PLATFORM && !accessToken) { + if ((IS_PLATFORM || STUDIO_AUTH_ENABLED) && !accessToken) { return res.status(401).json({ error: 'Authorization token is required' }) } diff --git a/apps/studio/pages/api/ai/sql/policy.ts b/apps/studio/pages/api/ai/sql/policy.ts index d403e9b6b35..57588a5e205 100644 --- a/apps/studio/pages/api/ai/sql/policy.ts +++ b/apps/studio/pages/api/ai/sql/policy.ts @@ -1,5 +1,6 @@ import { Output, generateText, stepCountIs } from 'ai' import { IS_PLATFORM } from 'common' +import { STUDIO_AUTH_ENABLED } from 'lib/constants' import { source } from 'common-tags' import { NextApiRequest, NextApiResponse } from 'next' import { z } from 'zod' @@ -55,7 +56,7 @@ export async function handlePost(req: NextApiRequest, res: NextApiResponse) { const authorization = req.headers.authorization const accessToken = authorization?.replace('Bearer ', '') - if (IS_PLATFORM && !accessToken) { + if ((IS_PLATFORM || STUDIO_AUTH_ENABLED) && !accessToken) { return res.status(401).json({ error: 'Authorization token is required' }) }