diff --git a/routstr/proxy.py b/routstr/proxy.py index 5feff279..5e5f54fd 100644 --- a/routstr/proxy.py +++ b/routstr/proxy.py @@ -234,14 +234,6 @@ _ALLOWED_ENDPOINTS: dict[str, frozenset[str]] = { "responses": frozenset({"POST"}), "messages": frozenset({"POST"}), "embeddings": frozenset({"POST"}), - "moderations": frozenset({"POST"}), - "rerank": frozenset({"POST"}), - "audio/speech": frozenset({"POST"}), - "audio/transcriptions": frozenset({"POST"}), - "audio/translations": frozenset({"POST"}), - "images/generations": frozenset({"POST"}), - "images/edits": frozenset({"POST"}), - "images/variations": frozenset({"POST"}), "models": frozenset({"GET"}), "attestation": frozenset({"GET"}), "tee/attestation": frozenset({"GET"}), diff --git a/tests/unit/test_proxy_path_allowlist.py b/tests/unit/test_proxy_path_allowlist.py index 33a2d610..4cd1c67f 100644 --- a/tests/unit/test_proxy_path_allowlist.py +++ b/tests/unit/test_proxy_path_allowlist.py @@ -69,6 +69,24 @@ def test_unknown_paths_are_not_forwarded() -> None: assert _forwarding_allowed("secret-endpoint", "POST") is False +@pytest.mark.parametrize( + "path", + [ + "moderations", + "rerank", + "audio/speech", + "audio/transcriptions", + "audio/translations", + "images/generations", + "images/edits", + "images/variations", + ], +) +def test_unbilled_endpoints_are_not_forwarded_by_default(path: str) -> None: + assert _forwarding_allowed(path, "POST") is False + assert _forwarding_allowed(f"v1/{path}", "POST") is False + + @pytest.mark.parametrize( "path", [ @@ -121,9 +139,6 @@ def test_known_prefix_does_not_carry_an_unknown_endpoint(path: str) -> None: ("v1/responses", "POST"), ("v1/messages", "POST"), ("v1/embeddings", "POST"), - ("moderations", "POST"), - ("audio/transcriptions", "POST"), - ("images/generations", "POST"), ("models", "GET"), ("attestation", "GET"), ("tee/attestation", "GET"),