fix(providers): preserve health in redacted key summaries

This commit is contained in:
elky
2026-09-07 08:53:41 +08:00
parent 6948852992
commit 14f96c9fa0
4 changed files with 117 additions and 4 deletions
+2 -4
View File
@@ -533,12 +533,10 @@ impl AppState {
&self,
provider_ids: &[String],
) -> Result<Vec<provider_catalog::StoredProviderCatalogKey>, GatewayError> {
let keys = self
.data
self.data
.list_provider_catalog_key_summaries_by_provider_ids(provider_ids)
.await
.map_err(|err| GatewayError::Internal(err.to_string()))?;
self.open_provider_catalog_keys(keys).await
.map_err(|err| GatewayError::Internal(err.to_string()))
}
pub(crate) async fn list_provider_catalog_key_maintenance_summaries_by_provider_ids(
@@ -272,6 +272,50 @@ mod tests {
)
}
#[tokio::test]
async fn app_state_reads_redacted_key_summaries_without_opening_credentials() {
for (api_key, auth_config) in [
(Some("summary"), None),
(None, Some("{}")),
(Some("summary"), Some("{}")),
] {
let health = serde_json::json!({"openai:chat": {"health_score": 0.75}});
let key = sample_key(
"key-1",
"provider-1",
api_key.map(ToOwned::to_owned),
auth_config.map(ToOwned::to_owned),
)
.with_health_fields(Some(health.clone()), None);
let repository = Arc::new(InMemoryProviderCatalogReadRepository::seed(
vec![sample_provider("provider-1")],
Vec::new(),
vec![key],
));
let state = AppState::new()
.expect("test state should build")
.with_data_state_for_tests(
GatewayDataState::with_provider_catalog_reader_for_tests(repository)
.with_encryption_key_for_tests(DEVELOPMENT_ENCRYPTION_KEY),
);
let provider_ids = ["provider-1".to_string()];
let summaries = state
.list_provider_catalog_key_summaries_by_provider_ids(&provider_ids)
.await
.expect("redacted summaries should not require credential authentication");
assert_eq!(summaries.len(), 1);
assert_eq!(summaries[0].health_by_format.as_ref(), Some(&health));
assert_eq!(summaries[0].encrypted_api_key.as_deref(), api_key);
assert_eq!(summaries[0].encrypted_auth_config.as_deref(), auth_config);
assert!(state
.list_provider_catalog_keys_by_provider_ids(&provider_ids)
.await
.is_err());
}
}
#[tokio::test]
async fn app_state_migrates_both_legacy_fields_with_one_exact_cas() {
let legacy_api =
@@ -70,6 +70,68 @@ async fn provider_health_summary(
payload["items"][0].clone()
}
#[tokio::test]
async fn admin_provider_summary_health_preserves_redacted_key_summaries() {
let endpoint = sample_endpoint(
"endpoint-chat",
"provider-openai",
"openai:chat",
"https://api.openai.example",
);
let keys = [
("key-api", "api_key", None, 0.25),
("key-oauth", "oauth", Some("{}"), 0.75),
]
.into_iter()
.map(|(key_id, auth_type, auth_config, score)| {
let mut key = sample_key(key_id, "provider-openai", "openai:chat", "test")
.with_health_fields(
Some(json!({"openai:chat": {"health_score": score}})),
None,
);
key.auth_type = auth_type.to_string();
key.encrypted_api_key = Some("summary".to_string());
key.encrypted_auth_config = auth_config.map(ToOwned::to_owned);
key
})
.collect();
let repository = Arc::new(InMemoryProviderCatalogReadRepository::seed(
vec![sample_provider("provider-openai", "openai", 10)],
vec![endpoint],
keys,
));
let state = AppState::new()
.expect("gateway should build")
.with_data_state_for_tests(GatewayDataState::with_provider_catalog_reader_for_tests(
repository,
));
for uri in [
"/api/admin/providers/summary",
"/api/admin/providers/provider-openai/summary",
] {
let response = local_admin_providers_response(&state, http::Method::GET, uri, None).await;
assert_eq!(response.status(), StatusCode::OK);
let body = axum::body::to_bytes(response.into_body(), 1024 * 1024)
.await
.expect("summary body should read");
let payload: serde_json::Value = serde_json::from_slice(&body).expect("summary should parse");
let summary = if uri == "/api/admin/providers/summary" {
&payload["items"][0]
} else {
&payload
};
assert_eq!(summary["total_keys"], 2);
assert_eq!(summary["active_keys"], 2);
assert_eq!(summary["endpoint_health_details"][0]["total_keys"], 2);
assert_eq!(summary["endpoint_health_details"][0]["active_keys"], 2);
assert_eq!(summary["endpoint_health_details"][0]["health_score"], 0.5);
assert_eq!(summary["avg_health_score"], 0.5);
assert_eq!(summary["unhealthy_endpoints"], 0);
}
}
#[tokio::test]
async fn admin_provider_summary_health_ignores_disabled_keys() {
let endpoint = sample_endpoint(