v3.9.1
🔒 Security
- Scoped proxy targets: The proxy only accepts the host of the provider named in the request.
- No credential leakage: On sites behind HTTP authentication, the browser's own credentials are no longer forwarded to the AI provider.
🐞 Bug Fixes
- Provider name casing:
providers.OpenAInow works likeproviders.openaiand keeps that provider's model defaults. - Gateway completion models: Gateways that expect prefixed model names – like Cloudflare AI Gateway's Unified API – receive the correct completion model again.




