mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-10 19:29:50 +08:00
refactor: 大规模模块拆分与重组,新增 aether-admin crate
- 新建独立 aether-admin crate 承载 admin 相关共享契约与纯辅助函数 - 拆分 ai_pipeline 下 kiro/private_envelope/conversion/planner 等大文件为子模块目录 - 重组 admin handlers 各业务域(billing/oauth/provider/system/users 等)为目录结构,移除 shared.rs/builders.rs 等反模式 - 移除 ai_pipeline runtime adapters 旧实现(claude/openai/gemini/kiro/vertex/antigravity 等),改由 provider transport 统一承载 - 移除 control_facade/execution_facade/auth_snapshot_facade 等冗余 facade 层 - 拆分 query/billing 与 query/monitoring 模块、state/runtime/payments 与 security 模块 - 扩展架构测试覆盖 admin_billing/admin_model/admin_users 等新模块 - 删除 docs/architecture/refactor-execution-plan.md 已完成的执行计划文档
This commit is contained in:
@@ -1,426 +0,0 @@
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::handlers::admin::provider::shared::paths::{
|
||||
admin_clear_oauth_invalid_key_id, admin_provider_id_for_keys, admin_update_key_id,
|
||||
};
|
||||
use crate::handlers::admin::provider::shared::payloads::{
|
||||
AdminProviderKeyBatchDeleteRequest, AdminProviderKeyCreateRequest,
|
||||
AdminProviderKeyUpdateRequest,
|
||||
};
|
||||
use crate::handlers::admin::shared::build_admin_provider_key_response;
|
||||
use crate::{AppState, GatewayError};
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
use std::collections::BTreeSet;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
use super::super::write::keys::{
|
||||
build_admin_create_provider_key_record, build_admin_update_provider_key_record,
|
||||
};
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.control_decision.as_ref() else {
|
||||
return Ok(None);
|
||||
};
|
||||
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("update_key")
|
||||
&& request_context.request_method == http::Method::PUT
|
||||
&& request_context
|
||||
.request_path
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
{
|
||||
let Some(key_id) = admin_update_key_id(&request_context.request_path) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "Key 不存在" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体不能为空" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
if !state.has_provider_catalog_data_reader() {
|
||||
return Ok(None);
|
||||
}
|
||||
let raw_value = match serde_json::from_slice::<serde_json::Value>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
};
|
||||
let Some(raw_payload) = raw_value.as_object().cloned() else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let payload = match serde_json::from_value::<AdminProviderKeyUpdateRequest>(raw_value) {
|
||||
Ok(payload) => payload,
|
||||
Err(_) => {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
};
|
||||
let Some(existing_key) = state
|
||||
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let Some(provider) = state
|
||||
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&existing_key.provider_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": format!("Provider {} 不存在", existing_key.provider_id) })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let updated_record = match build_admin_update_provider_key_record(
|
||||
state,
|
||||
&provider,
|
||||
&existing_key,
|
||||
&raw_payload,
|
||||
payload,
|
||||
)
|
||||
.await
|
||||
{
|
||||
Ok(record) => record,
|
||||
Err(detail) => {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
};
|
||||
let Some(updated) = state.update_provider_catalog_key(&updated_record).await? else {
|
||||
return Ok(None);
|
||||
};
|
||||
let now_unix_secs = SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.ok()
|
||||
.map(|duration| duration.as_secs())
|
||||
.unwrap_or(0);
|
||||
return Ok(Some(
|
||||
Json(build_admin_provider_key_response(
|
||||
state,
|
||||
&updated,
|
||||
now_unix_secs,
|
||||
))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("delete_key")
|
||||
&& request_context.request_method == http::Method::DELETE
|
||||
&& request_context
|
||||
.request_path
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
{
|
||||
let Some(key_id) = admin_update_key_id(&request_context.request_path) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "Key 不存在" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let Some(_existing_key) = state
|
||||
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
if !state.delete_provider_catalog_key(&key_id).await? {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
return Ok(Some(
|
||||
Json(json!({
|
||||
"message": format!("Key {key_id} 已删除")
|
||||
}))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("batch_delete_keys")
|
||||
&& request_context.request_method == http::Method::POST
|
||||
&& request_context.request_path == "/api/admin/endpoints/keys/batch-delete"
|
||||
{
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体不能为空" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let payload =
|
||||
match serde_json::from_slice::<AdminProviderKeyBatchDeleteRequest>(request_body) {
|
||||
Ok(payload) => payload,
|
||||
Err(_) => {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
};
|
||||
if payload.ids.len() > 100 {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "ids 最多 100 个" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
if payload.ids.is_empty() {
|
||||
return Ok(Some(
|
||||
Json(json!({
|
||||
"success_count": 0,
|
||||
"failed_count": 0,
|
||||
"failed": []
|
||||
}))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
let found_keys = state
|
||||
.read_provider_catalog_keys_by_ids(&payload.ids)
|
||||
.await?;
|
||||
let found_ids = found_keys
|
||||
.iter()
|
||||
.map(|key| key.id.clone())
|
||||
.collect::<BTreeSet<_>>();
|
||||
let mut failed = payload
|
||||
.ids
|
||||
.iter()
|
||||
.filter(|key_id| !found_ids.contains(*key_id))
|
||||
.map(|key_id| json!({ "id": key_id, "error": "not found" }))
|
||||
.collect::<Vec<_>>();
|
||||
|
||||
let mut success_count = 0usize;
|
||||
for key_id in found_ids {
|
||||
if state.delete_provider_catalog_key(&key_id).await? {
|
||||
success_count += 1;
|
||||
} else {
|
||||
failed.push(json!({ "id": key_id, "error": "not found" }));
|
||||
}
|
||||
}
|
||||
|
||||
return Ok(Some(
|
||||
Json(json!({
|
||||
"success_count": success_count,
|
||||
"failed_count": failed.len(),
|
||||
"failed": failed,
|
||||
}))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("clear_oauth_invalid")
|
||||
&& request_context.request_method == http::Method::POST
|
||||
&& request_context
|
||||
.request_path
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
&& request_context
|
||||
.request_path
|
||||
.ends_with("/clear-oauth-invalid")
|
||||
{
|
||||
let Some(key_id) = admin_clear_oauth_invalid_key_id(&request_context.request_path) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "Key 不存在" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let Some(key) = state
|
||||
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": format!("Key {key_id} 不存在") })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
if key.oauth_invalid_at_unix_secs.is_none() {
|
||||
return Ok(Some(
|
||||
Json(json!({
|
||||
"message": "该 Key 当前无失效标记,无需清除"
|
||||
}))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
state
|
||||
.clear_provider_catalog_key_oauth_invalid_marker(&key_id)
|
||||
.await?;
|
||||
return Ok(Some(
|
||||
Json(json!({
|
||||
"message": "已清除 OAuth 失效标记"
|
||||
}))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("create_provider_key")
|
||||
&& request_context.request_method == http::Method::POST
|
||||
&& request_context
|
||||
.request_path
|
||||
.starts_with("/api/admin/endpoints/providers/")
|
||||
&& request_context.request_path.ends_with("/keys")
|
||||
{
|
||||
let Some(provider_id) = admin_provider_id_for_keys(&request_context.request_path) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "Provider 不存在" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体不能为空" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
if !state.has_provider_catalog_data_reader() {
|
||||
return Ok(None);
|
||||
}
|
||||
let payload = match serde_json::from_slice::<AdminProviderKeyCreateRequest>(request_body) {
|
||||
Ok(payload) => payload,
|
||||
Err(_) => {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求体必须是合法的 JSON 对象" })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
};
|
||||
let Some(provider) = state
|
||||
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&provider_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": format!("Provider {provider_id} 不存在") })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let record = match build_admin_create_provider_key_record(state, &provider, payload).await {
|
||||
Ok(record) => record,
|
||||
Err(detail) => {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
};
|
||||
let Some(created) = state.create_provider_catalog_key(&record).await? else {
|
||||
return Ok(None);
|
||||
};
|
||||
let now_unix_secs = SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.ok()
|
||||
.map(|duration| duration.as_secs())
|
||||
.unwrap_or(0);
|
||||
return Ok(Some(
|
||||
Json(build_admin_provider_key_response(
|
||||
state,
|
||||
&created,
|
||||
now_unix_secs,
|
||||
))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
Ok(None)
|
||||
}
|
||||
@@ -0,0 +1,89 @@
|
||||
use crate::handlers::admin::provider::shared::payloads::AdminProviderKeyBatchDeleteRequest;
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
use std::collections::BTreeSet;
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
if decision.route_family.as_deref() != Some("endpoints_manage")
|
||||
|| decision.route_kind.as_deref() != Some("batch_delete_keys")
|
||||
|| request_context.method() != http::Method::POST
|
||||
|| request_context.path() != "/api/admin/endpoints/keys/batch-delete"
|
||||
{
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok(Some(bad_request_response("请求体不能为空")));
|
||||
};
|
||||
let payload = match serde_json::from_slice::<AdminProviderKeyBatchDeleteRequest>(request_body) {
|
||||
Ok(payload) => payload,
|
||||
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
|
||||
};
|
||||
if payload.ids.len() > 100 {
|
||||
return Ok(Some(bad_request_response("ids 最多 100 个")));
|
||||
}
|
||||
if payload.ids.is_empty() {
|
||||
return Ok(Some(
|
||||
Json(json!({
|
||||
"success_count": 0,
|
||||
"failed_count": 0,
|
||||
"failed": []
|
||||
}))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
let found_keys = state
|
||||
.read_provider_catalog_keys_by_ids(&payload.ids)
|
||||
.await?;
|
||||
let found_ids = found_keys
|
||||
.iter()
|
||||
.map(|key| key.id.clone())
|
||||
.collect::<BTreeSet<_>>();
|
||||
let mut failed = payload
|
||||
.ids
|
||||
.iter()
|
||||
.filter(|key_id| !found_ids.contains(*key_id))
|
||||
.map(|key_id| json!({ "id": key_id, "error": "not found" }))
|
||||
.collect::<Vec<_>>();
|
||||
|
||||
let mut success_count = 0usize;
|
||||
for key_id in found_ids {
|
||||
if state.delete_provider_catalog_key(&key_id).await? {
|
||||
success_count += 1;
|
||||
} else {
|
||||
failed.push(json!({ "id": key_id, "error": "not found" }));
|
||||
}
|
||||
}
|
||||
|
||||
Ok(Some(
|
||||
Json(json!({
|
||||
"success_count": success_count,
|
||||
"failed_count": failed.len(),
|
||||
"failed": failed,
|
||||
}))
|
||||
.into_response(),
|
||||
))
|
||||
}
|
||||
|
||||
fn bad_request_response(detail: impl Into<String>) -> Response<Body> {
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail.into() })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -0,0 +1,91 @@
|
||||
use crate::handlers::admin::provider::shared::paths::admin_provider_id_for_keys;
|
||||
use crate::handlers::admin::provider::shared::payloads::AdminProviderKeyCreateRequest;
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
if decision.route_family.as_deref() != Some("endpoints_manage")
|
||||
|| decision.route_kind.as_deref() != Some("create_provider_key")
|
||||
|| request_context.method() != http::Method::POST
|
||||
|| !request_context
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/providers/")
|
||||
|| !request_context.path().ends_with("/keys")
|
||||
{
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let Some(provider_id) = admin_provider_id_for_keys(request_context.path()) else {
|
||||
return Ok(Some(not_found_response("Provider 不存在")));
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok(Some(bad_request_response("请求体不能为空")));
|
||||
};
|
||||
if !state.has_provider_catalog_data_reader() {
|
||||
return Ok(None);
|
||||
}
|
||||
let payload = match serde_json::from_slice::<AdminProviderKeyCreateRequest>(request_body) {
|
||||
Ok(payload) => payload,
|
||||
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
|
||||
};
|
||||
let Some(provider) = state
|
||||
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&provider_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(not_found_response(format!(
|
||||
"Provider {provider_id} 不存在"
|
||||
))));
|
||||
};
|
||||
let record = match state
|
||||
.build_admin_create_provider_key_record(&provider, payload)
|
||||
.await
|
||||
{
|
||||
Ok(record) => record,
|
||||
Err(detail) => return Ok(Some(bad_request_response(detail))),
|
||||
};
|
||||
let Some(created) = state.create_provider_catalog_key(&record).await? else {
|
||||
return Ok(None);
|
||||
};
|
||||
let now_unix_secs = SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.ok()
|
||||
.map(|duration| duration.as_secs())
|
||||
.unwrap_or(0);
|
||||
|
||||
Ok(Some(
|
||||
Json(state.build_admin_provider_key_response(&created, now_unix_secs)).into_response(),
|
||||
))
|
||||
}
|
||||
|
||||
fn bad_request_response(detail: impl Into<String>) -> Response<Body> {
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail.into() })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
|
||||
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": detail.into() })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -0,0 +1,59 @@
|
||||
use crate::handlers::admin::provider::shared::paths::admin_update_key_id;
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
_request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
if decision.route_family.as_deref() != Some("endpoints_manage")
|
||||
|| decision.route_kind.as_deref() != Some("delete_key")
|
||||
|| request_context.method() != http::Method::DELETE
|
||||
|| !request_context
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
{
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let Some(key_id) = admin_update_key_id(request_context.path()) else {
|
||||
return Ok(Some(not_found_response("Key 不存在")));
|
||||
};
|
||||
let Some(_existing_key) = state
|
||||
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
|
||||
};
|
||||
if !state.delete_provider_catalog_key(&key_id).await? {
|
||||
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
|
||||
}
|
||||
|
||||
Ok(Some(
|
||||
Json(json!({
|
||||
"message": format!("Key {key_id} 已删除")
|
||||
}))
|
||||
.into_response(),
|
||||
))
|
||||
}
|
||||
|
||||
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": detail.into() })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
mod batch;
|
||||
mod create;
|
||||
mod delete;
|
||||
mod oauth_invalid;
|
||||
mod update;
|
||||
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
response::Response,
|
||||
};
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
if let Some(response) = update::maybe_handle(state, request_context, request_body).await? {
|
||||
return Ok(Some(response));
|
||||
}
|
||||
if let Some(response) = delete::maybe_handle(state, request_context, request_body).await? {
|
||||
return Ok(Some(response));
|
||||
}
|
||||
if let Some(response) = batch::maybe_handle(state, request_context, request_body).await? {
|
||||
return Ok(Some(response));
|
||||
}
|
||||
if let Some(response) =
|
||||
oauth_invalid::maybe_handle(state, request_context, request_body).await?
|
||||
{
|
||||
return Ok(Some(response));
|
||||
}
|
||||
if let Some(response) = create::maybe_handle(state, request_context, request_body).await? {
|
||||
return Ok(Some(response));
|
||||
}
|
||||
|
||||
Ok(None)
|
||||
}
|
||||
+67
@@ -0,0 +1,67 @@
|
||||
use crate::handlers::admin::provider::shared::paths::admin_clear_oauth_invalid_key_id;
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
_request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
if decision.route_family.as_deref() != Some("endpoints_manage")
|
||||
|| decision.route_kind.as_deref() != Some("clear_oauth_invalid")
|
||||
|| request_context.method() != http::Method::POST
|
||||
|| !request_context
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
|| !request_context.path().ends_with("/clear-oauth-invalid")
|
||||
{
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let Some(key_id) = admin_clear_oauth_invalid_key_id(request_context.path()) else {
|
||||
return Ok(Some(not_found_response("Key 不存在")));
|
||||
};
|
||||
let Some(key) = state
|
||||
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
|
||||
};
|
||||
if key.oauth_invalid_at_unix_secs.is_none() {
|
||||
return Ok(Some(
|
||||
Json(json!({
|
||||
"message": "该 Key 当前无失效标记,无需清除"
|
||||
}))
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
state
|
||||
.clear_provider_catalog_key_oauth_invalid_marker(&key_id)
|
||||
.await?;
|
||||
Ok(Some(
|
||||
Json(json!({
|
||||
"message": "已清除 OAuth 失效标记"
|
||||
}))
|
||||
.into_response(),
|
||||
))
|
||||
}
|
||||
|
||||
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": detail.into() })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -0,0 +1,109 @@
|
||||
use crate::handlers::admin::provider::shared::paths::admin_update_key_id;
|
||||
use crate::handlers::admin::provider::shared::payloads::AdminProviderKeyUpdateRequest;
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
if decision.route_family.as_deref() != Some("endpoints_manage")
|
||||
|| decision.route_kind.as_deref() != Some("update_key")
|
||||
|| request_context.method() != http::Method::PUT
|
||||
|| !request_context
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
{
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let Some(key_id) = admin_update_key_id(request_context.path()) else {
|
||||
return Ok(Some(not_found_response("Key 不存在")));
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok(Some(bad_request_response("请求体不能为空")));
|
||||
};
|
||||
if !state.has_provider_catalog_data_reader() {
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let raw_value = match serde_json::from_slice::<serde_json::Value>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
|
||||
};
|
||||
let Some(raw_payload) = raw_value.as_object().cloned() else {
|
||||
return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象")));
|
||||
};
|
||||
let payload = match serde_json::from_value::<AdminProviderKeyUpdateRequest>(raw_value) {
|
||||
Ok(payload) => payload,
|
||||
Err(_) => return Ok(Some(bad_request_response("请求体必须是合法的 JSON 对象"))),
|
||||
};
|
||||
|
||||
let Some(existing_key) = state
|
||||
.read_provider_catalog_keys_by_ids(std::slice::from_ref(&key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(not_found_response(format!("Key {key_id} 不存在"))));
|
||||
};
|
||||
let Some(provider) = state
|
||||
.read_provider_catalog_providers_by_ids(std::slice::from_ref(&existing_key.provider_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.next()
|
||||
else {
|
||||
return Ok(Some(not_found_response(format!(
|
||||
"Provider {} 不存在",
|
||||
existing_key.provider_id
|
||||
))));
|
||||
};
|
||||
|
||||
let updated_record = match state
|
||||
.build_admin_update_provider_key_record(&provider, &existing_key, &raw_payload, payload)
|
||||
.await
|
||||
{
|
||||
Ok(record) => record,
|
||||
Err(detail) => return Ok(Some(bad_request_response(detail))),
|
||||
};
|
||||
let Some(updated) = state.update_provider_catalog_key(&updated_record).await? else {
|
||||
return Ok(None);
|
||||
};
|
||||
let now_unix_secs = SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.ok()
|
||||
.map(|duration| duration.as_secs())
|
||||
.unwrap_or(0);
|
||||
|
||||
Ok(Some(
|
||||
Json(state.build_admin_provider_key_response(&updated, now_unix_secs)).into_response(),
|
||||
))
|
||||
}
|
||||
|
||||
fn bad_request_response(detail: impl Into<String>) -> Response<Body> {
|
||||
(
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail.into() })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
|
||||
fn not_found_response(detail: impl Into<String>) -> Response<Body> {
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": detail.into() })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -1,9 +1,9 @@
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::handlers::admin::provider::shared::paths::admin_provider_id_for_refresh_quota;
|
||||
use crate::handlers::admin::provider::shared::payloads::{
|
||||
AdminProviderQuotaRefreshRequest, OAUTH_ACCOUNT_BLOCK_PREFIX,
|
||||
};
|
||||
use crate::{AppState, GatewayError};
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
@@ -19,27 +19,26 @@ use super::super::oauth::quota::kiro::refresh_kiro_provider_quota_locally;
|
||||
use super::super::oauth::quota::shared::normalize_string_id_list;
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.control_decision.as_ref() else {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
|
||||
if decision.route_family.as_deref() != Some("endpoints_manage")
|
||||
|| decision.route_kind.as_deref() != Some("refresh_quota")
|
||||
|| request_context.request_method != http::Method::POST
|
||||
|| request_context.method() != http::Method::POST
|
||||
|| !request_context
|
||||
.request_path
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/providers/")
|
||||
|| !request_context.request_path.ends_with("/refresh-quota")
|
||||
|| !request_context.path().ends_with("/refresh-quota")
|
||||
{
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let Some(provider_id) = admin_provider_id_for_refresh_quota(&request_context.request_path)
|
||||
else {
|
||||
let Some(provider_id) = admin_provider_id_for_refresh_quota(request_context.path()) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
|
||||
@@ -1,10 +1,9 @@
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::handlers::admin::provider::shared::paths::{
|
||||
admin_export_key_id, admin_provider_id_for_keys, admin_reveal_key_id,
|
||||
};
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::handlers::admin::shared::{attach_admin_audit_response, query_param_value};
|
||||
use crate::handlers::public::build_admin_keys_grouped_by_format_payload;
|
||||
use crate::{AppState, GatewayError};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::{Body, Bytes},
|
||||
http,
|
||||
@@ -13,23 +12,20 @@ use axum::{
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
use super::super::write::keys::build_admin_provider_keys_payload;
|
||||
use super::super::write::reveal::{build_admin_export_key_payload, build_admin_reveal_key_payload};
|
||||
|
||||
pub(super) async fn maybe_handle(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
_request_body: Option<&Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.control_decision.as_ref() else {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("keys_grouped_by_format")
|
||||
&& request_context.request_path == "/api/admin/endpoints/keys/grouped-by-format"
|
||||
&& request_context.path() == "/api/admin/endpoints/keys/grouped-by-format"
|
||||
{
|
||||
let Some(payload) = build_admin_keys_grouped_by_format_payload(state).await else {
|
||||
let Some(payload) = state.build_admin_keys_grouped_by_format_payload().await else {
|
||||
return Ok(None);
|
||||
};
|
||||
return Ok(Some(Json(payload).into_response()));
|
||||
@@ -38,11 +34,11 @@ pub(super) async fn maybe_handle(
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("reveal_key")
|
||||
&& request_context
|
||||
.request_path
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
&& request_context.request_path.ends_with("/reveal")
|
||||
&& request_context.path().ends_with("/reveal")
|
||||
{
|
||||
let Some(key_id) = admin_reveal_key_id(&request_context.request_path) else {
|
||||
let Some(key_id) = admin_reveal_key_id(request_context.path()) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
@@ -65,7 +61,7 @@ pub(super) async fn maybe_handle(
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
return Ok(Some(match build_admin_reveal_key_payload(state, &key) {
|
||||
return Ok(Some(match state.build_admin_reveal_key_payload(&key) {
|
||||
Ok(payload) => attach_admin_audit_response(
|
||||
Json(payload).into_response(),
|
||||
"admin_provider_key_revealed",
|
||||
@@ -84,11 +80,11 @@ pub(super) async fn maybe_handle(
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("export_key")
|
||||
&& request_context
|
||||
.request_path
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/keys/")
|
||||
&& request_context.request_path.ends_with("/export")
|
||||
&& request_context.path().ends_with("/export")
|
||||
{
|
||||
let Some(key_id) = admin_export_key_id(&request_context.request_path) else {
|
||||
let Some(key_id) = admin_export_key_id(request_context.path()) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
@@ -112,7 +108,7 @@ pub(super) async fn maybe_handle(
|
||||
));
|
||||
};
|
||||
return Ok(Some(
|
||||
match build_admin_export_key_payload(state, &key).await {
|
||||
match state.build_admin_export_key_payload(&key).await {
|
||||
Ok(payload) => attach_admin_audit_response(
|
||||
Json(payload).into_response(),
|
||||
"admin_provider_key_exported",
|
||||
@@ -132,11 +128,11 @@ pub(super) async fn maybe_handle(
|
||||
if decision.route_family.as_deref() == Some("endpoints_manage")
|
||||
&& decision.route_kind.as_deref() == Some("list_provider_keys")
|
||||
&& request_context
|
||||
.request_path
|
||||
.path()
|
||||
.starts_with("/api/admin/endpoints/providers/")
|
||||
&& request_context.request_path.ends_with("/keys")
|
||||
&& request_context.path().ends_with("/keys")
|
||||
{
|
||||
let Some(provider_id) = admin_provider_id_for_keys(&request_context.request_path) else {
|
||||
let Some(provider_id) = admin_provider_id_for_keys(request_context.path()) else {
|
||||
return Ok(Some(
|
||||
(
|
||||
http::StatusCode::NOT_FOUND,
|
||||
@@ -145,15 +141,18 @@ pub(super) async fn maybe_handle(
|
||||
.into_response(),
|
||||
));
|
||||
};
|
||||
let skip = query_param_value(request_context.request_query_string.as_deref(), "skip")
|
||||
let skip = query_param_value(request_context.query_string(), "skip")
|
||||
.and_then(|value| value.parse::<usize>().ok())
|
||||
.unwrap_or(0);
|
||||
let limit = query_param_value(request_context.request_query_string.as_deref(), "limit")
|
||||
let limit = query_param_value(request_context.query_string(), "limit")
|
||||
.and_then(|value| value.parse::<usize>().ok())
|
||||
.filter(|value| *value > 0)
|
||||
.unwrap_or(100);
|
||||
return Ok(Some(
|
||||
match build_admin_provider_keys_payload(state, &provider_id, skip, limit).await {
|
||||
match state
|
||||
.build_admin_provider_keys_payload(&provider_id, skip, limit)
|
||||
.await
|
||||
{
|
||||
Some(payload) => Json(payload).into_response(),
|
||||
None => (
|
||||
http::StatusCode::NOT_FOUND,
|
||||
|
||||
Reference in New Issue
Block a user