fix(provider): harden Agent Identity OAuth lifecycle

This commit is contained in:
elky
2026-07-23 09:33:00 +08:00
parent e49024d33b
commit 3606290ac8
84 changed files with 8063 additions and 1104 deletions
@@ -5,7 +5,7 @@ use crate::handlers::admin::request::AdminAppState;
use crate::handlers::admin::shared::{provider_key_status_snapshot_payload, unix_secs_to_rfc3339};
use crate::provider_key_auth::{
provider_key_auth_config_is_agent_identity, provider_key_auth_config_uses_header_authorization,
provider_key_auth_semantics, provider_key_can_refresh_oauth,
provider_key_auth_semantics, provider_key_can_export_oauth, provider_key_can_refresh_oauth,
provider_key_effective_api_formats,
};
use aether_admin::provider::pool as admin_provider_pool_pure;
@@ -1228,12 +1228,17 @@ pub(super) fn build_admin_pool_key_payload(
"can_refresh_oauth".to_string(),
json!(provider_key_can_refresh_oauth(
auth_semantics,
provider_type,
auth_config.as_ref()
)),
);
payload.insert(
"can_export_oauth".to_string(),
json!(auth_semantics.can_export_oauth()),
json!(provider_key_can_export_oauth(
auth_semantics,
provider_type,
auth_config.as_ref()
)),
);
payload.insert(
"can_edit_oauth".to_string(),
@@ -8,7 +8,7 @@ use super::{
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::provider_key_auth::{
provider_key_auth_config_is_agent_identity, provider_key_auth_config_uses_header_authorization,
provider_key_auth_semantics, provider_key_can_refresh_oauth,
provider_key_auth_semantics, provider_key_can_export_oauth, provider_key_can_refresh_oauth,
};
use crate::GatewayError;
use aether_admin::provider::pool as admin_provider_pool_pure;
@@ -156,8 +156,16 @@ pub(super) async fn build_admin_pool_resolve_selection_response(
&provider_type,
auth_config.as_ref(),
),
"can_refresh_oauth": provider_key_can_refresh_oauth(auth_semantics, auth_config.as_ref()),
"can_export_oauth": auth_semantics.can_export_oauth(),
"can_refresh_oauth": provider_key_can_refresh_oauth(
auth_semantics,
&provider_type,
auth_config.as_ref(),
),
"can_export_oauth": provider_key_can_export_oauth(
auth_semantics,
&provider_type,
auth_config.as_ref(),
),
"can_edit_oauth": auth_semantics.can_edit_oauth(),
"oauth_header_auth": auth_semantics.oauth_managed()
&& provider_key_auth_config_uses_header_authorization(auth_config.as_ref()),