Dashboardopencode-loreUpstream routing transport, encoding, a…

Upstream routing transport, encoding, and authorization

Category: decision
Confidence: 1.00
ID: 01a0aeaf-529a-714d-9922-63bec23f1cd2
Project ID: 6f4be9ff-ed84-4cca-a9e7-732a0b0b8677
Cross-project: No
Recalled in other projects: 0
Source session: 1RiQk7Zb3QbQ4Z6eg
Created: 2026-09-12 19:58:45
Updated: 2026-09-17 09:25:20

Content

For auto-routed upstreams, serialize uncompressed JSON instead of replaying the client's Content-Encoding; preserve encoding only for native passthrough or explicit X-Lore-Upstream-URL/X-Lore-Provider routes. OpenAI-protocol upstream requests must always use Authorization: Bearer ${cred.value}, regardless of the caller's scheme. Remote gateway mode must reject every http: upstream before forwarding credentials or bodies, including manual configs and compact fallbacks; allowlists authorize only exact HTTPS origins.

Move to: