diff --git a/server/cmd/server/main.go b/server/cmd/server/main.go index 8191c5f..4ac5a1c 100644 --- a/server/cmd/server/main.go +++ b/server/cmd/server/main.go @@ -179,6 +179,9 @@ func main() { Registry: reg, } + // /api/models — public model catalog; no user-specific data. + r.Get("/api/models", apiSrv.HandleListModelsPublic) + // /api/* — cookie-authenticated, internal surface. r.Route("/api", func(r chi.Router) { r.Use(authSvc.Middleware) diff --git a/server/internal/api/web/models.go b/server/internal/api/web/models.go index 675d7c7..75e18a5 100644 --- a/server/internal/api/web/models.go +++ b/server/internal/api/web/models.go @@ -6,6 +6,13 @@ import ( "time" ) +// HandleListModelsPublic is the exported form of handleListModels for use +// as a public (no-auth) route. The model catalog contains no user-specific +// data so it's safe to serve without authentication. +func (s *Server) HandleListModelsPublic(w http.ResponseWriter, r *http.Request) { + s.handleListModels(w, r) +} + // handleListModels returns the model catalog from the DB. // The catalog is populated (and refreshed hourly) by pool.ModelsRefresher. // We never do live pioneer fetches here — that keeps the endpoint fast and diff --git a/web/src/routes/docs/+page.svelte b/web/src/routes/docs/+page.svelte index 0b7a40c..2f1e152 100644 --- a/web/src/routes/docs/+page.svelte +++ b/web/src/routes/docs/+page.svelte @@ -1,27 +1,24 @@