feat: add token-protected deep health routes for database, PowerSync, email and models - #1272
Conversation
Semgrep Security ScanNo security issues found. |
|
Preview environment destroyed 🧹 Stack |
PR Metrics
Updated Mon, 21 Sep 2026 20:38:29 GMT · run #3068 |
…cted-routes-for-database-powersync
There was a problem hiding this comment.
🔭 thunder-deep-review (advisory)
Complements the other bots — surfaces only what they did not flag. Never approves, never requests changes, never gates merge.
head: c287867aa8de · mode: deep · deferred 0 item(s) already reported by other bots (best-effort dedup)
| }).fetch | ||
| } | ||
| const client = new OpenAI({ | ||
| apiKey: runtime ? settings.anthropicApiKey : settings.tinfoilApiKey, |
There was a problem hiding this comment.
🔧 Nit — Unset Anthropic/Tinfoil keys report as a generic upstream failure instead of "not configured"
I noticed the powersync and email probes return a clear not-configured reason when their URL/key is missing, but the models probe has no equivalent guard — if ANTHROPIC_API_KEY or TINFOIL_API_KEY is empty we still build the client and send an empty bearer, so every model comes back as upstream-error. On a half-configured deploy that reads like "the provider is down" rather than "you forgot a secret," which is a confusing page to get at 3am. Could we short-circuit to a not-configured reason when the relevant key is blank, so it matches the sibling routes?
No description provided.