fix(provider): harden Agent Identity OAuth lifecycle

This commit is contained in:
elky
2026-07-23 09:33:00 +08:00
parent e49024d33b
commit 3606290ac8
84 changed files with 8063 additions and 1104 deletions
+1
View File
@@ -9,6 +9,7 @@ description = "Provider-specific pool behavior adapters for Aether"
[dependencies]
aether-data-contracts.workspace = true
aether-pool-core.workspace = true
aether-provider-transport.workspace = true
serde_json.workspace = true
url.workspace = true
uuid.workspace = true
+27
View File
@@ -184,6 +184,33 @@ mod tests {
);
}
#[test]
fn codex_nested_agent_identity_quota_request_prefers_dynamic_assertion() {
let spec = build_codex_pool_quota_request(
"key-1",
Some((
"authorization".to_string(),
"AgentAssertion signed-at-request-time".to_string(),
)),
None,
Some(&json!({
"agent_identity": {
"agent_runtime_id": "runtime-1",
"agent_private_key": "private-key"
},
"headers": {
"authorization": "Bearer stale-imported-session"
}
})),
)
.expect("spec should build");
assert_eq!(
spec.headers.get("authorization").map(String::as_str),
Some("AgentAssertion signed-at-request-time")
);
}
#[test]
fn gemini_cli_quota_request_uses_v1internal_retrieve_user_quota() {
let spec = build_gemini_cli_pool_quota_request(
@@ -93,14 +93,7 @@ fn build_codex_wham_headers(
.filter(|value| !value.is_empty());
let is_agent_identity = auth_config
.and_then(Value::as_object)
.and_then(|object| {
object
.get("auth_mode")
.or_else(|| object.get("authMode"))
.and_then(Value::as_str)
})
.is_some_and(|value| value.trim().eq_ignore_ascii_case("agentIdentity"));
.is_some_and(aether_provider_transport::is_codex_agent_identity_auth_config_value);
if is_agent_identity {
let Some((name, value)) = resolved_oauth_auth else {