From 65787d7cc3b22fe12336c197a1f6277c21aab3f5 Mon Sep 17 00:00:00 2001 From: Waleed Date: Fri, 19 Dec 2025 11:33:00 -0800 Subject: [PATCH] fix(api-keys): remove billed account check during api key generation (#2476) --- .../app/api/workspaces/[id]/api-keys/route.ts | 34 ------------------- 1 file changed, 34 deletions(-) diff --git a/apps/sim/app/api/workspaces/[id]/api-keys/route.ts b/apps/sim/app/api/workspaces/[id]/api-keys/route.ts index 11d94cb0fd..f29df67dc9 100644 --- a/apps/sim/app/api/workspaces/[id]/api-keys/route.ts +++ b/apps/sim/app/api/workspaces/[id]/api-keys/route.ts @@ -98,23 +98,6 @@ export async function POST(request: NextRequest, { params }: { params: Promise<{ return NextResponse.json({ error: 'Forbidden' }, { status: 403 }) } - const workspaceRows = await db - .select({ billedAccountUserId: workspace.billedAccountUserId }) - .from(workspace) - .where(eq(workspace.id, workspaceId)) - .limit(1) - - if (!workspaceRows.length) { - return NextResponse.json({ error: 'Workspace not found' }, { status: 404 }) - } - - if (workspaceRows[0].billedAccountUserId !== userId) { - return NextResponse.json( - { error: 'Only the workspace billing account can create workspace API keys' }, - { status: 403 } - ) - } - const body = await request.json() const { name } = CreateKeySchema.parse(body) @@ -202,23 +185,6 @@ export async function DELETE( return NextResponse.json({ error: 'Forbidden' }, { status: 403 }) } - const workspaceRows = await db - .select({ billedAccountUserId: workspace.billedAccountUserId }) - .from(workspace) - .where(eq(workspace.id, workspaceId)) - .limit(1) - - if (!workspaceRows.length) { - return NextResponse.json({ error: 'Workspace not found' }, { status: 404 }) - } - - if (workspaceRows[0].billedAccountUserId !== userId) { - return NextResponse.json( - { error: 'Only the workspace billing account can delete workspace API keys' }, - { status: 403 } - ) - } - const body = await request.json() const { keys } = DeleteKeysSchema.parse(body)