refactor: 大规模模块拆分与重组,新增 aether-admin crate

- 新建独立 aether-admin crate 承载 admin 相关共享契约与纯辅助函数
- 拆分 ai_pipeline 下 kiro/private_envelope/conversion/planner 等大文件为子模块目录
- 重组 admin handlers 各业务域(billing/oauth/provider/system/users 等)为目录结构,移除 shared.rs/builders.rs 等反模式
- 移除 ai_pipeline runtime adapters 旧实现(claude/openai/gemini/kiro/vertex/antigravity 等),改由 provider transport 统一承载
- 移除 control_facade/execution_facade/auth_snapshot_facade 等冗余 facade 层
- 拆分 query/billing 与 query/monitoring 模块、state/runtime/payments 与 security 模块
- 扩展架构测试覆盖 admin_billing/admin_model/admin_users 等新模块
- 删除 docs/architecture/refactor-execution-plan.md 已完成的执行计划文档
This commit is contained in:
fawney19
2026-04-09 00:10:38 +08:00
parent 4fb9882b54
commit 4fc95adfb9
663 changed files with 48471 additions and 40232 deletions
@@ -0,0 +1,8 @@
mod providers;
mod support;
pub(crate) use self::providers::build_admin_system_export_providers_payload;
pub(crate) use self::support::{
decrypt_admin_system_export_secret, ADMIN_SYSTEM_CONFIG_EXPORT_VERSION,
ADMIN_SYSTEM_EXPORT_PAGE_LIMIT,
};
@@ -0,0 +1,179 @@
use super::support::{
collect_admin_system_export_provider_endpoint_formats,
decrypt_admin_system_export_provider_config, decrypt_admin_system_export_secret,
resolve_admin_system_export_key_api_formats, ADMIN_SYSTEM_EXPORT_PAGE_LIMIT,
};
use crate::handlers::admin::request::AdminAppState;
use crate::GatewayError;
use aether_data_contracts::repository::global_models::AdminProviderModelListQuery;
use serde_json::json;
use std::collections::BTreeMap;
pub(crate) async fn build_admin_system_export_providers_payload(
state: &AdminAppState<'_>,
global_model_name_by_id: &BTreeMap<String, String>,
) -> Result<Vec<serde_json::Value>, GatewayError> {
let providers = state.list_provider_catalog_providers(false).await?;
let provider_ids = providers
.iter()
.map(|provider| provider.id.clone())
.collect::<Vec<_>>();
let endpoints = state
.list_provider_catalog_endpoints_by_provider_ids(&provider_ids)
.await?;
let keys = state
.list_provider_catalog_keys_by_provider_ids(&provider_ids)
.await?;
let mut endpoints_by_provider = BTreeMap::<String, Vec<_>>::new();
for endpoint in endpoints {
endpoints_by_provider
.entry(endpoint.provider_id.clone())
.or_default()
.push(endpoint);
}
let mut keys_by_provider = BTreeMap::<String, Vec<_>>::new();
for key in keys {
keys_by_provider
.entry(key.provider_id.clone())
.or_default()
.push(key);
}
let mut provider_models_by_provider = BTreeMap::<String, Vec<_>>::new();
for provider in &providers {
let models = state
.list_admin_provider_models(&AdminProviderModelListQuery {
provider_id: provider.id.clone(),
is_active: None,
offset: 0,
limit: ADMIN_SYSTEM_EXPORT_PAGE_LIMIT,
})
.await?;
provider_models_by_provider.insert(provider.id.clone(), models);
}
Ok(providers
.iter()
.map(|provider| {
let endpoints = endpoints_by_provider.remove(&provider.id).unwrap_or_default();
let provider_endpoint_formats =
collect_admin_system_export_provider_endpoint_formats(&endpoints);
let endpoints_data = endpoints
.iter()
.map(|endpoint| {
json!({
"api_format": endpoint.api_format,
"base_url": endpoint.base_url,
"header_rules": endpoint.header_rules,
"body_rules": endpoint.body_rules,
"max_retries": endpoint.max_retries,
"is_active": endpoint.is_active,
"custom_path": endpoint.custom_path,
"config": endpoint.config,
"format_acceptance_config": endpoint.format_acceptance_config,
"proxy": endpoint.proxy,
})
})
.collect::<Vec<_>>();
let mut keys = keys_by_provider.remove(&provider.id).unwrap_or_default();
keys.sort_by(|left, right| {
left.internal_priority
.cmp(&right.internal_priority)
.then(
left.created_at_unix_secs
.unwrap_or(0)
.cmp(&right.created_at_unix_secs.unwrap_or(0)),
)
.then(left.id.cmp(&right.id))
});
let keys_data = keys
.iter()
.map(|key| {
let api_formats = resolve_admin_system_export_key_api_formats(
key.api_formats.as_ref(),
&provider_endpoint_formats,
);
let mut payload = json!({
"api_formats": api_formats,
"supported_endpoints": api_formats,
"auth_type": key.auth_type,
"name": key.name,
"note": key.note,
"rate_multipliers": key.rate_multipliers,
"internal_priority": key.internal_priority,
"global_priority_by_format": key.global_priority_by_format,
"rpm_limit": key.rpm_limit,
"allowed_models": key.allowed_models,
"capabilities": key.capabilities,
"cache_ttl_minutes": key.cache_ttl_minutes,
"max_probe_interval_minutes": key.max_probe_interval_minutes,
"is_active": key.is_active,
"proxy": key.proxy,
"fingerprint": key.fingerprint,
"auto_fetch_models": key.auto_fetch_models,
"locked_models": key.locked_models,
"model_include_patterns": key.model_include_patterns,
"model_exclude_patterns": key.model_exclude_patterns,
"api_key": decrypt_admin_system_export_secret(state, &key.encrypted_api_key)
.unwrap_or_default(),
});
if let Some(ciphertext) = key.encrypted_auth_config.as_deref() {
if let Some(plaintext) =
decrypt_admin_system_export_secret(state, ciphertext)
{
payload["auth_config"] = json!(plaintext);
}
}
payload
})
.collect::<Vec<_>>();
let models_data = provider_models_by_provider
.remove(&provider.id)
.unwrap_or_default()
.into_iter()
.map(|model| {
json!({
"provider_model_name": model.provider_model_name,
"provider_model_mappings": model.provider_model_mappings,
"price_per_request": model.price_per_request,
"tiered_pricing": model.tiered_pricing,
"supports_vision": model.supports_vision,
"supports_function_calling": model.supports_function_calling,
"supports_streaming": model.supports_streaming,
"supports_extended_thinking": model.supports_extended_thinking,
"supports_image_generation": model.supports_image_generation,
"is_active": model.is_active,
"config": model.config,
"global_model_name": global_model_name_by_id.get(&model.global_model_id),
})
})
.collect::<Vec<_>>();
json!({
"name": provider.name,
"description": provider.description,
"website": provider.website,
"provider_type": provider.provider_type,
"billing_type": provider.billing_type,
"monthly_quota_usd": provider.monthly_quota_usd,
"quota_reset_day": provider.quota_reset_day,
"provider_priority": provider.provider_priority,
"keep_priority_on_conversion": provider.keep_priority_on_conversion,
"enable_format_conversion": provider.enable_format_conversion,
"is_active": provider.is_active,
"concurrent_limit": provider.concurrent_limit,
"max_retries": provider.max_retries,
"proxy": provider.proxy,
"request_timeout": provider.request_timeout_secs,
"stream_first_byte_timeout": provider.stream_first_byte_timeout_secs,
"config": decrypt_admin_system_export_provider_config(state, provider.config.as_ref()),
"endpoints": endpoints_data,
"api_keys": keys_data,
"models": models_data,
})
})
.collect::<Vec<_>>())
}
@@ -0,0 +1,87 @@
use super::super::configs::is_sensitive_admin_system_config_key;
use crate::api::ai::admin_endpoint_signature_parts;
use crate::handlers::admin::request::AdminAppState;
use crate::handlers::shared::decrypt_catalog_secret_with_fallbacks;
use aether_data_contracts::repository::provider_catalog::StoredProviderCatalogEndpoint;
pub(crate) const ADMIN_SYSTEM_CONFIG_EXPORT_VERSION: &str = "2.2";
pub(crate) const ADMIN_SYSTEM_EXPORT_PAGE_LIMIT: usize = 10_000;
const PROVIDER_OPS_SENSITIVE_CREDENTIAL_FIELDS: &[&str] = &[
"api_key",
"password",
"refresh_token",
"session_token",
"session_cookie",
"token_cookie",
"auth_cookie",
"cookie_string",
"cookie",
];
pub(crate) fn decrypt_admin_system_export_secret(
state: &AdminAppState<'_>,
ciphertext: &str,
) -> Option<String> {
decrypt_catalog_secret_with_fallbacks(state.encryption_key(), ciphertext)
}
pub(super) fn normalize_admin_system_export_api_formats(
raw_formats: Option<&serde_json::Value>,
) -> Vec<String> {
aether_admin::system::normalize_admin_system_export_api_formats(raw_formats, |value| {
admin_endpoint_signature_parts(value).map(|(signature, _, _)| signature.to_string())
})
}
pub(super) fn resolve_admin_system_export_key_api_formats(
raw_formats: Option<&serde_json::Value>,
provider_endpoint_formats: &[String],
) -> Vec<String> {
aether_admin::system::resolve_admin_system_export_key_api_formats(
raw_formats,
provider_endpoint_formats,
|value| {
admin_endpoint_signature_parts(value).map(|(signature, _, _)| signature.to_string())
},
)
}
pub(super) fn collect_admin_system_export_provider_endpoint_formats(
endpoints: &[StoredProviderCatalogEndpoint],
) -> Vec<String> {
aether_admin::system::collect_admin_system_export_provider_endpoint_formats(
endpoints,
|value| {
admin_endpoint_signature_parts(value).map(|(signature, _, _)| signature.to_string())
},
)
}
pub(super) fn decrypt_admin_system_export_provider_config(
state: &AdminAppState<'_>,
config: Option<&serde_json::Value>,
) -> Option<serde_json::Value> {
let mut decrypted = config.cloned()?;
let Some(credentials) = decrypted
.get_mut("provider_ops")
.and_then(serde_json::Value::as_object_mut)
.and_then(|provider_ops| provider_ops.get_mut("connector"))
.and_then(serde_json::Value::as_object_mut)
.and_then(|connector| connector.get_mut("credentials"))
.and_then(serde_json::Value::as_object_mut)
else {
return Some(decrypted);
};
for field in PROVIDER_OPS_SENSITIVE_CREDENTIAL_FIELDS {
let Some(serde_json::Value::String(ciphertext)) = credentials.get(*field).cloned() else {
continue;
};
if let Some(plaintext) = decrypt_admin_system_export_secret(state, &ciphertext) {
credentials.insert((*field).to_string(), serde_json::Value::String(plaintext));
}
}
Some(decrypted)
}