refactor: 大规模模块拆分与重组,新增 aether-admin crate

- 新建独立 aether-admin crate 承载 admin 相关共享契约与纯辅助函数
- 拆分 ai_pipeline 下 kiro/private_envelope/conversion/planner 等大文件为子模块目录
- 重组 admin handlers 各业务域(billing/oauth/provider/system/users 等)为目录结构,移除 shared.rs/builders.rs 等反模式
- 移除 ai_pipeline runtime adapters 旧实现(claude/openai/gemini/kiro/vertex/antigravity 等),改由 provider transport 统一承载
- 移除 control_facade/execution_facade/auth_snapshot_facade 等冗余 facade 层
- 拆分 query/billing 与 query/monitoring 模块、state/runtime/payments 与 security 模块
- 扩展架构测试覆盖 admin_billing/admin_model/admin_users 等新模块
- 删除 docs/architecture/refactor-execution-plan.md 已完成的执行计划文档
This commit is contained in:
fawney19
2026-04-09 00:10:38 +08:00
parent 4fb9882b54
commit 4fc95adfb9
663 changed files with 48471 additions and 40232 deletions
@@ -1,426 +0,0 @@
use crate::control::GatewayPublicRequestContext;
use crate::handlers::admin::provider::shared::paths::{
admin_clear_oauth_invalid_key_id, admin_provider_id_for_keys, admin_update_key_id,
};
use crate::handlers::admin::provider::shared::payloads::{
AdminProviderKeyBatchDeleteRequest, AdminProviderKeyCreateRequest,
AdminProviderKeyUpdateRequest,
};
use crate::handlers::admin::shared::build_admin_provider_key_response;
use crate::{AppState, GatewayError};
use axum::{
body::{Body, Bytes},
http,
response::{IntoResponse, Response},
Json,
};
use serde_json::json;
use std::collections::BTreeSet;
use std::time::{SystemTime, UNIX_EPOCH};
use super::super::write::keys::{
build_admin_create_provider_key_record, build_admin_update_provider_key_record,
};
pub(super) async fn maybe_handle(
state: &AppState,
request_context: &GatewayPublicRequestContext,
request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.control_decision.as_ref() else {
return Ok(None);
};
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("update_key")
&& request_context.request_method == http::Method::PUT
&& request_context
.request_path
.starts_with("/api/admin/endpoints/keys/")
{
let Some(key_id) = admin_update_key_id(&request_context.request_path) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": "Key 不存在" })),
)
.into_response(),
));
};
let Some(request_body) = request_body else {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体不能为空" })),
)
.into_response(),
));
};
if !state.has_provider_catalog_data_reader() {
return Ok(None);
}
let raw_value = match serde_json::from_slice::<serde_json::Value>(request_body) {
Ok(value) => value,
Err(_) => {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
)
.into_response(),
));
}
};
let Some(raw_payload) = raw_value.as_object().cloned() else {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
)
.into_response(),
));
};
let payload = match serde_json::from_value::<AdminProviderKeyUpdateRequest>(raw_value) {
Ok(payload) => payload,
Err(_) => {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
)
.into_response(),
));
}
};
let Some(existing_key) = state
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
)
.into_response(),
));
};
let Some(provider) = state
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&existing_key.provider_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": format!("Provider {} 不存在", existing_key.provider_id) })),
)
.into_response(),
));
};
let updated_record = match build_admin_update_provider_key_record(
state,
&provider,
&existing_key,
&raw_payload,
payload,
)
.await
{
Ok(record) => record,
Err(detail) => {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": detail })),
)
.into_response(),
));
}
};
let Some(updated) = state.update_provider_catalog_key(&updated_record).await? else {
return Ok(None);
};
let now_unix_secs = SystemTime::now()
.duration_since(UNIX_EPOCH)
.ok()
.map(|duration| duration.as_secs())
.unwrap_or(0);
return Ok(Some(
Json(build_admin_provider_key_response(
state,
&updated,
now_unix_secs,
))
.into_response(),
));
}
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("delete_key")
&& request_context.request_method == http::Method::DELETE
&& request_context
.request_path
.starts_with("/api/admin/endpoints/keys/")
{
let Some(key_id) = admin_update_key_id(&request_context.request_path) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": "Key 不存在" })),
)
.into_response(),
));
};
let Some(_existing_key) = state
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
)
.into_response(),
));
};
if !state.delete_provider_catalog_key(&key_id).await? {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
)
.into_response(),
));
}
return Ok(Some(
Json(json!({
"message": format!("Key {key_id} 已删除")
}))
.into_response(),
));
}
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("batch_delete_keys")
&& request_context.request_method == http::Method::POST
&& request_context.request_path == "/api/admin/endpoints/keys/batch-delete"
{
let Some(request_body) = request_body else {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体不能为空" })),
)
.into_response(),
));
};
let payload =
match serde_json::from_slice::<AdminProviderKeyBatchDeleteRequest>(request_body) {
Ok(payload) => payload,
Err(_) => {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
)
.into_response(),
));
}
};
if payload.ids.len() > 100 {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "ids 最多 100 个" })),
)
.into_response(),
));
}
if payload.ids.is_empty() {
return Ok(Some(
Json(json!({
"success_count": 0,
"failed_count": 0,
"failed": []
}))
.into_response(),
));
}
let found_keys = state
.read_provider_catalog_keys_by_ids(&payload.ids)
.await?;
let found_ids = found_keys
.iter()
.map(|key| key.id.clone())
.collect::<BTreeSet<_>>();
let mut failed = payload
.ids
.iter()
.filter(|key_id| !found_ids.contains(*key_id))
.map(|key_id| json!({ "id": key_id, "error": "not found" }))
.collect::<Vec<_>>();
let mut success_count = 0usize;
for key_id in found_ids {
if state.delete_provider_catalog_key(&key_id).await? {
success_count += 1;
} else {
failed.push(json!({ "id": key_id, "error": "not found" }));
}
}
return Ok(Some(
Json(json!({
"success_count": success_count,
"failed_count": failed.len(),
"failed": failed,
}))
.into_response(),
));
}
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("clear_oauth_invalid")
&& request_context.request_method == http::Method::POST
&& request_context
.request_path
.starts_with("/api/admin/endpoints/keys/")
&& request_context
.request_path
.ends_with("/clear-oauth-invalid")
{
let Some(key_id) = admin_clear_oauth_invalid_key_id(&request_context.request_path) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": "Key 不存在" })),
)
.into_response(),
));
};
let Some(key) = state
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
)
.into_response(),
));
};
if key.oauth_invalid_at_unix_secs.is_none() {
return Ok(Some(
Json(json!({
"message": "该 Key 当前无失效标记,无需清除"
}))
.into_response(),
));
}
state
.clear_provider_catalog_key_oauth_invalid_marker(&key_id)
.await?;
return Ok(Some(
Json(json!({
"message": "已清除 OAuth 失效标记"
}))
.into_response(),
));
}
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("create_provider_key")
&& request_context.request_method == http::Method::POST
&& request_context
.request_path
.starts_with("/api/admin/endpoints/providers/")
&& request_context.request_path.ends_with("/keys")
{
let Some(provider_id) = admin_provider_id_for_keys(&request_context.request_path) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": "Provider 不存在" })),
)
.into_response(),
));
};
let Some(request_body) = request_body else {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体不能为空" })),
)
.into_response(),
));
};
if !state.has_provider_catalog_data_reader() {
return Ok(None);
}
let payload = match serde_json::from_slice::<AdminProviderKeyCreateRequest>(request_body) {
Ok(payload) => payload,
Err(_) => {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
)
.into_response(),
));
}
};
let Some(provider) = state
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&provider_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": format!("Provider {provider_id} 不存在") })),
)
.into_response(),
));
};
let record = match build_admin_create_provider_key_record(state, &provider, payload).await {
Ok(record) => record,
Err(detail) => {
return Ok(Some(
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": detail })),
)
.into_response(),
));
}
};
let Some(created) = state.create_provider_catalog_key(&record).await? else {
return Ok(None);
};
let now_unix_secs = SystemTime::now()
.duration_since(UNIX_EPOCH)
.ok()
.map(|duration| duration.as_secs())
.unwrap_or(0);
return Ok(Some(
Json(build_admin_provider_key_response(
state,
&created,
now_unix_secs,
))
.into_response(),
));
}
Ok(None)
}
@@ -0,0 +1,89 @@
use crate::handlers::admin::provider::shared::payloads::AdminProviderKeyBatchDeleteRequest;
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
http,
response::{IntoResponse, Response},
Json,
};
use serde_json::json;
use std::collections::BTreeSet;
pub(super) async fn maybe_handle(
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.decision() else {
return Ok(None);
};
if decision.route_family.as_deref() != Some("endpoints_manage")
|| decision.route_kind.as_deref() != Some("batch_delete_keys")
|| request_context.method() != http::Method::POST
|| request_context.path() != "/api/admin/endpoints/keys/batch-delete"
{
return Ok(None);
}
let Some(request_body) = request_body else {
return Ok(Some(bad_request_response("请求体不能为空")));
};
let payload = match serde_json::from_slice::<AdminProviderKeyBatchDeleteRequest>(request_body) {
Ok(payload) => payload,
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
};
if payload.ids.len() > 100 {
return Ok(Some(bad_request_response("ids 最多 100 个")));
}
if payload.ids.is_empty() {
return Ok(Some(
Json(json!({
"success_count": 0,
"failed_count": 0,
"failed": []
}))
.into_response(),
));
}
let found_keys = state
.read_provider_catalog_keys_by_ids(&payload.ids)
.await?;
let found_ids = found_keys
.iter()
.map(|key| key.id.clone())
.collect::<BTreeSet<_>>();
let mut failed = payload
.ids
.iter()
.filter(|key_id| !found_ids.contains(*key_id))
.map(|key_id| json!({ "id": key_id, "error": "not found" }))
.collect::<Vec<_>>();
let mut success_count = 0usize;
for key_id in found_ids {
if state.delete_provider_catalog_key(&key_id).await? {
success_count += 1;
} else {
failed.push(json!({ "id": key_id, "error": "not found" }));
}
}
Ok(Some(
Json(json!({
"success_count": success_count,
"failed_count": failed.len(),
"failed": failed,
}))
.into_response(),
))
}
fn bad_request_response(detail: impl Into<String>) -> Response<Body> {
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": detail.into() })),
)
.into_response()
}
@@ -0,0 +1,91 @@
use crate::handlers::admin::provider::shared::paths::admin_provider_id_for_keys;
use crate::handlers::admin::provider::shared::payloads::AdminProviderKeyCreateRequest;
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
http,
response::{IntoResponse, Response},
Json,
};
use serde_json::json;
use std::time::{SystemTime, UNIX_EPOCH};
pub(super) async fn maybe_handle(
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.decision() else {
return Ok(None);
};
if decision.route_family.as_deref() != Some("endpoints_manage")
|| decision.route_kind.as_deref() != Some("create_provider_key")
|| request_context.method() != http::Method::POST
|| !request_context
.path()
.starts_with("/api/admin/endpoints/providers/")
|| !request_context.path().ends_with("/keys")
{
return Ok(None);
}
let Some(provider_id) = admin_provider_id_for_keys(request_context.path()) else {
return Ok(Some(not_found_response("Provider 不存在")));
};
let Some(request_body) = request_body else {
return Ok(Some(bad_request_response("请求体不能为空")));
};
if !state.has_provider_catalog_data_reader() {
return Ok(None);
}
let payload = match serde_json::from_slice::<AdminProviderKeyCreateRequest>(request_body) {
Ok(payload) => payload,
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
};
let Some(provider) = state
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&provider_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(not_found_response(format!(
"Provider {provider_id} 不存在"
))));
};
let record = match state
.build_admin_create_provider_key_record(&provider, payload)
.await
{
Ok(record) => record,
Err(detail) => return Ok(Some(bad_request_response(detail))),
};
let Some(created) = state.create_provider_catalog_key(&record).await? else {
return Ok(None);
};
let now_unix_secs = SystemTime::now()
.duration_since(UNIX_EPOCH)
.ok()
.map(|duration| duration.as_secs())
.unwrap_or(0);
Ok(Some(
Json(state.build_admin_provider_key_response(&created, now_unix_secs)).into_response(),
))
}
fn bad_request_response(detail: impl Into<String>) -> Response<Body> {
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": detail.into() })),
)
.into_response()
}
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": detail.into() })),
)
.into_response()
}
@@ -0,0 +1,59 @@
use crate::handlers::admin::provider::shared::paths::admin_update_key_id;
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
http,
response::{IntoResponse, Response},
Json,
};
use serde_json::json;
pub(super) async fn maybe_handle(
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
_request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.decision() else {
return Ok(None);
};
if decision.route_family.as_deref() != Some("endpoints_manage")
|| decision.route_kind.as_deref() != Some("delete_key")
|| request_context.method() != http::Method::DELETE
|| !request_context
.path()
.starts_with("/api/admin/endpoints/keys/")
{
return Ok(None);
}
let Some(key_id) = admin_update_key_id(request_context.path()) else {
return Ok(Some(not_found_response("Key 不存在")));
};
let Some(_existing_key) = state
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
};
if !state.delete_provider_catalog_key(&key_id).await? {
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
}
Ok(Some(
Json(json!({
"message": format!("Key {key_id} 已删除")
}))
.into_response(),
))
}
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": detail.into() })),
)
.into_response()
}
@@ -0,0 +1,38 @@
mod batch;
mod create;
mod delete;
mod oauth_invalid;
mod update;
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
response::Response,
};
pub(super) async fn maybe_handle(
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
if let Some(response) = update::maybe_handle(state, request_context, request_body).await? {
return Ok(Some(response));
}
if let Some(response) = delete::maybe_handle(state, request_context, request_body).await? {
return Ok(Some(response));
}
if let Some(response) = batch::maybe_handle(state, request_context, request_body).await? {
return Ok(Some(response));
}
if let Some(response) =
oauth_invalid::maybe_handle(state, request_context, request_body).await?
{
return Ok(Some(response));
}
if let Some(response) = create::maybe_handle(state, request_context, request_body).await? {
return Ok(Some(response));
}
Ok(None)
}
@@ -0,0 +1,67 @@
use crate::handlers::admin::provider::shared::paths::admin_clear_oauth_invalid_key_id;
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
http,
response::{IntoResponse, Response},
Json,
};
use serde_json::json;
pub(super) async fn maybe_handle(
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
_request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.decision() else {
return Ok(None);
};
if decision.route_family.as_deref() != Some("endpoints_manage")
|| decision.route_kind.as_deref() != Some("clear_oauth_invalid")
|| request_context.method() != http::Method::POST
|| !request_context
.path()
.starts_with("/api/admin/endpoints/keys/")
|| !request_context.path().ends_with("/clear-oauth-invalid")
{
return Ok(None);
}
let Some(key_id) = admin_clear_oauth_invalid_key_id(request_context.path()) else {
return Ok(Some(not_found_response("Key 不存在")));
};
let Some(key) = state
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
};
if key.oauth_invalid_at_unix_secs.is_none() {
return Ok(Some(
Json(json!({
"message": "该 Key 当前无失效标记,无需清除"
}))
.into_response(),
));
}
state
.clear_provider_catalog_key_oauth_invalid_marker(&key_id)
.await?;
Ok(Some(
Json(json!({
"message": "已清除 OAuth 失效标记"
}))
.into_response(),
))
}
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": detail.into() })),
)
.into_response()
}
@@ -0,0 +1,109 @@
use crate::handlers::admin::provider::shared::paths::admin_update_key_id;
use crate::handlers::admin::provider::shared::payloads::AdminProviderKeyUpdateRequest;
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
http,
response::{IntoResponse, Response},
Json,
};
use serde_json::json;
use std::time::{SystemTime, UNIX_EPOCH};
pub(super) async fn maybe_handle(
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.decision() else {
return Ok(None);
};
if decision.route_family.as_deref() != Some("endpoints_manage")
|| decision.route_kind.as_deref() != Some("update_key")
|| request_context.method() != http::Method::PUT
|| !request_context
.path()
.starts_with("/api/admin/endpoints/keys/")
{
return Ok(None);
}
let Some(key_id) = admin_update_key_id(request_context.path()) else {
return Ok(Some(not_found_response("Key 不存在")));
};
let Some(request_body) = request_body else {
return Ok(Some(bad_request_response("请求体不能为空")));
};
if !state.has_provider_catalog_data_reader() {
return Ok(None);
}
let raw_value = match serde_json::from_slice::<serde_json::Value>(request_body) {
Ok(value) => value,
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
};
let Some(raw_payload) = raw_value.as_object().cloned() else {
return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象")));
};
let payload = match serde_json::from_value::<AdminProviderKeyUpdateRequest>(raw_value) {
Ok(payload) => payload,
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
};
let Some(existing_key) = state
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
};
let Some(provider) = state
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&existing_key.provider_id))
.await?
.into_iter()
.next()
else {
return Ok(Some(not_found_response(format!(
"Provider {} 不存在",
existing_key.provider_id
))));
};
let updated_record = match state
.build_admin_update_provider_key_record(&provider, &existing_key, &raw_payload, payload)
.await
{
Ok(record) => record,
Err(detail) => return Ok(Some(bad_request_response(detail))),
};
let Some(updated) = state.update_provider_catalog_key(&updated_record).await? else {
return Ok(None);
};
let now_unix_secs = SystemTime::now()
.duration_since(UNIX_EPOCH)
.ok()
.map(|duration| duration.as_secs())
.unwrap_or(0);
Ok(Some(
Json(state.build_admin_provider_key_response(&updated, now_unix_secs)).into_response(),
))
}
fn bad_request_response(detail: impl Into<String>) -> Response<Body> {
(
http::StatusCode::BAD_REQUEST,
Json(json!({ "detail": detail.into() })),
)
.into_response()
}
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
(
http::StatusCode::NOT_FOUND,
Json(json!({ "detail": detail.into() })),
)
.into_response()
}
@@ -1,9 +1,9 @@
use crate::control::GatewayPublicRequestContext;
use crate::handlers::admin::provider::shared::paths::admin_provider_id_for_refresh_quota;
use crate::handlers::admin::provider::shared::payloads::{
AdminProviderQuotaRefreshRequest, OAUTH_ACCOUNT_BLOCK_PREFIX,
};
use crate::{AppState, GatewayError};
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
http,
@@ -19,27 +19,26 @@ use super::super::oauth::quota::kiro::refresh_kiro_provider_quota_locally;
use super::super::oauth::quota::shared::normalize_string_id_list;
pub(super) async fn maybe_handle(
state: &AppState,
request_context: &GatewayPublicRequestContext,
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.control_decision.as_ref() else {
let Some(decision) = request_context.decision() else {
return Ok(None);
};
if decision.route_family.as_deref() != Some("endpoints_manage")
|| decision.route_kind.as_deref() != Some("refresh_quota")
|| request_context.request_method != http::Method::POST
|| request_context.method() != http::Method::POST
|| !request_context
.request_path
.path()
.starts_with("/api/admin/endpoints/providers/")
|| !request_context.request_path.ends_with("/refresh-quota")
|| !request_context.path().ends_with("/refresh-quota")
{
return Ok(None);
}
let Some(provider_id) = admin_provider_id_for_refresh_quota(&request_context.request_path)
else {
let Some(provider_id) = admin_provider_id_for_refresh_quota(request_context.path()) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
@@ -1,10 +1,9 @@
use crate::control::GatewayPublicRequestContext;
use crate::handlers::admin::provider::shared::paths::{
admin_export_key_id, admin_provider_id_for_keys, admin_reveal_key_id,
};
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
use crate::handlers::admin::shared::{attach_admin_audit_response, query_param_value};
use crate::handlers::public::build_admin_keys_grouped_by_format_payload;
use crate::{AppState, GatewayError};
use crate::GatewayError;
use axum::{
body::{Body, Bytes},
http,
@@ -13,23 +12,20 @@ use axum::{
};
use serde_json::json;
use super::super::write::keys::build_admin_provider_keys_payload;
use super::super::write::reveal::{build_admin_export_key_payload, build_admin_reveal_key_payload};
pub(super) async fn maybe_handle(
state: &AppState,
request_context: &GatewayPublicRequestContext,
state: &AdminAppState<'_>,
request_context: &AdminRequestContext<'_>,
_request_body: Option<&Bytes>,
) -> Result<Option<Response<Body>>, GatewayError> {
let Some(decision) = request_context.control_decision.as_ref() else {
let Some(decision) = request_context.decision() else {
return Ok(None);
};
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("keys_grouped_by_format")
&& request_context.request_path == "/api/admin/endpoints/keys/grouped-by-format"
&& request_context.path() == "/api/admin/endpoints/keys/grouped-by-format"
{
let Some(payload) = build_admin_keys_grouped_by_format_payload(state).await else {
let Some(payload) = state.build_admin_keys_grouped_by_format_payload().await else {
return Ok(None);
};
return Ok(Some(Json(payload).into_response()));
@@ -38,11 +34,11 @@ pub(super) async fn maybe_handle(
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("reveal_key")
&& request_context
.request_path
.path()
.starts_with("/api/admin/endpoints/keys/")
&& request_context.request_path.ends_with("/reveal")
&& request_context.path().ends_with("/reveal")
{
let Some(key_id) = admin_reveal_key_id(&request_context.request_path) else {
let Some(key_id) = admin_reveal_key_id(request_context.path()) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
@@ -65,7 +61,7 @@ pub(super) async fn maybe_handle(
.into_response(),
));
};
return Ok(Some(match build_admin_reveal_key_payload(state, &key) {
return Ok(Some(match state.build_admin_reveal_key_payload(&key) {
Ok(payload) => attach_admin_audit_response(
Json(payload).into_response(),
"admin_provider_key_revealed",
@@ -84,11 +80,11 @@ pub(super) async fn maybe_handle(
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("export_key")
&& request_context
.request_path
.path()
.starts_with("/api/admin/endpoints/keys/")
&& request_context.request_path.ends_with("/export")
&& request_context.path().ends_with("/export")
{
let Some(key_id) = admin_export_key_id(&request_context.request_path) else {
let Some(key_id) = admin_export_key_id(request_context.path()) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
@@ -112,7 +108,7 @@ pub(super) async fn maybe_handle(
));
};
return Ok(Some(
match build_admin_export_key_payload(state, &key).await {
match state.build_admin_export_key_payload(&key).await {
Ok(payload) => attach_admin_audit_response(
Json(payload).into_response(),
"admin_provider_key_exported",
@@ -132,11 +128,11 @@ pub(super) async fn maybe_handle(
if decision.route_family.as_deref() == Some("endpoints_manage")
&& decision.route_kind.as_deref() == Some("list_provider_keys")
&& request_context
.request_path
.path()
.starts_with("/api/admin/endpoints/providers/")
&& request_context.request_path.ends_with("/keys")
&& request_context.path().ends_with("/keys")
{
let Some(provider_id) = admin_provider_id_for_keys(&request_context.request_path) else {
let Some(provider_id) = admin_provider_id_for_keys(request_context.path()) else {
return Ok(Some(
(
http::StatusCode::NOT_FOUND,
@@ -145,15 +141,18 @@ pub(super) async fn maybe_handle(
.into_response(),
));
};
let skip = query_param_value(request_context.request_query_string.as_deref(), "skip")
let skip = query_param_value(request_context.query_string(), "skip")
.and_then(|value| value.parse::<usize>().ok())
.unwrap_or(0);
let limit = query_param_value(request_context.request_query_string.as_deref(), "limit")
let limit = query_param_value(request_context.query_string(), "limit")
.and_then(|value| value.parse::<usize>().ok())
.filter(|value| *value > 0)
.unwrap_or(100);
return Ok(Some(
match build_admin_provider_keys_payload(state, &provider_id, skip, limit).await {
match state
.build_admin_provider_keys_payload(&provider_id, skip, limit)
.await
{
Some(payload) => Json(payload).into_response(),
None => (
http::StatusCode::NOT_FOUND,