Security
- Reject browser-originated requests to the OpenAI, Anthropic, and Codex proxy routes, preventing cross-origin sites from invoking configured provider-key fallbacks.
- Preserve existing CLI and SDK behavior, provider-key fallback support, the dashboard, and permissive CORS for the standalone
/api/maskendpoint.
Users running v0.9.1 or earlier should upgrade. Deployments using configured provider-key fallbacks should continue to restrict direct network access.