mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-07 01:47:47 +08:00
refactor: 大规模模块拆分与重组,新增 aether-admin crate
- 新建独立 aether-admin crate 承载 admin 相关共享契约与纯辅助函数 - 拆分 ai_pipeline 下 kiro/private_envelope/conversion/planner 等大文件为子模块目录 - 重组 admin handlers 各业务域(billing/oauth/provider/system/users 等)为目录结构,移除 shared.rs/builders.rs 等反模式 - 移除 ai_pipeline runtime adapters 旧实现(claude/openai/gemini/kiro/vertex/antigravity 等),改由 provider transport 统一承载 - 移除 control_facade/execution_facade/auth_snapshot_facade 等冗余 facade 层 - 拆分 query/billing 与 query/monitoring 模块、state/runtime/payments 与 security 模块 - 扩展架构测试覆盖 admin_billing/admin_model/admin_users 等新模块 - 删除 docs/architecture/refactor-execution-plan.md 已完成的执行计划文档
This commit is contained in:
@@ -1,642 +0,0 @@
|
||||
use super::{
|
||||
build_admin_users_bad_request_response, build_admin_users_data_unavailable_response,
|
||||
build_admin_users_read_only_response, AdminCreateUserApiKeyRequest,
|
||||
AdminToggleUserApiKeyLockRequest, AdminUpdateUserApiKeyRequest,
|
||||
};
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::handlers::admin::shared::{
|
||||
attach_admin_audit_response, decrypt_catalog_secret_with_fallbacks,
|
||||
encrypt_catalog_secret_with_fallbacks, query_param_optional_bool,
|
||||
};
|
||||
use crate::{AppState, GatewayError};
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
fn admin_user_api_key_full_key_parts(request_path: &str) -> Option<(String, String)> {
|
||||
let raw = request_path.strip_prefix("/api/admin/users/")?;
|
||||
let (user_id, key_id) = raw.split_once("/api-keys/")?;
|
||||
let user_id = user_id.trim().trim_matches('/');
|
||||
let key_id = key_id
|
||||
.trim()
|
||||
.trim_matches('/')
|
||||
.strip_suffix("/full-key")?
|
||||
.trim()
|
||||
.trim_matches('/');
|
||||
if user_id.is_empty() || key_id.is_empty() || user_id.contains('/') || key_id.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some((user_id.to_string(), key_id.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
fn admin_user_api_key_parts(request_path: &str) -> Option<(String, String)> {
|
||||
let raw = request_path.strip_prefix("/api/admin/users/")?;
|
||||
let (user_id, key_id) = raw.split_once("/api-keys/")?;
|
||||
let user_id = user_id.trim().trim_matches('/');
|
||||
let key_id = key_id.trim().trim_matches('/');
|
||||
if user_id.is_empty() || key_id.is_empty() || user_id.contains('/') || key_id.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some((user_id.to_string(), key_id.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
fn admin_user_api_key_lock_parts(request_path: &str) -> Option<(String, String)> {
|
||||
let raw = request_path.strip_prefix("/api/admin/users/")?;
|
||||
let (user_id, key_id) = raw.split_once("/api-keys/")?;
|
||||
let user_id = user_id.trim().trim_matches('/');
|
||||
let key_id = key_id
|
||||
.trim()
|
||||
.trim_matches('/')
|
||||
.strip_suffix("/lock")?
|
||||
.trim()
|
||||
.trim_matches('/');
|
||||
if user_id.is_empty() || key_id.is_empty() || user_id.contains('/') || key_id.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some((user_id.to_string(), key_id.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
pub(crate) fn format_optional_unix_secs_iso8601(value: Option<u64>) -> Option<String> {
|
||||
let secs = value?;
|
||||
let secs = i64::try_from(secs).ok()?;
|
||||
chrono::DateTime::<chrono::Utc>::from_timestamp(secs, 0).map(|value| value.to_rfc3339())
|
||||
}
|
||||
|
||||
fn admin_user_id_from_api_keys_path(request_path: &str) -> Option<String> {
|
||||
request_path
|
||||
.strip_prefix("/api/admin/users/")?
|
||||
.strip_suffix("/api-keys")
|
||||
.map(|value| value.trim().trim_matches('/').to_string())
|
||||
.filter(|value| !value.is_empty() && !value.contains('/'))
|
||||
}
|
||||
|
||||
pub(crate) fn masked_user_api_key_display(state: &AppState, ciphertext: Option<&str>) -> String {
|
||||
let Some(ciphertext) = ciphertext.map(str::trim).filter(|value| !value.is_empty()) else {
|
||||
return "sk-****".to_string();
|
||||
};
|
||||
let Some(full_key) = decrypt_catalog_secret_with_fallbacks(state.encryption_key(), ciphertext)
|
||||
else {
|
||||
return "sk-****".to_string();
|
||||
};
|
||||
let prefix_len = full_key.len().min(10);
|
||||
let prefix = &full_key[..prefix_len];
|
||||
let suffix = if full_key.len() >= 4 {
|
||||
&full_key[full_key.len() - 4..]
|
||||
} else {
|
||||
""
|
||||
};
|
||||
format!("{prefix}...{suffix}")
|
||||
}
|
||||
|
||||
fn build_admin_user_api_key_detail_payload(
|
||||
state: &AppState,
|
||||
record: &aether_data::repository::auth::StoredAuthApiKeyExportRecord,
|
||||
is_locked: bool,
|
||||
) -> serde_json::Value {
|
||||
json!({
|
||||
"id": record.api_key_id,
|
||||
"name": record.name,
|
||||
"key_display": masked_user_api_key_display(state, record.key_encrypted.as_deref()),
|
||||
"is_active": record.is_active,
|
||||
"is_locked": is_locked,
|
||||
"total_requests": record.total_requests,
|
||||
"total_cost_usd": record.total_cost_usd,
|
||||
"rate_limit": record.rate_limit,
|
||||
"expires_at": format_optional_unix_secs_iso8601(record.expires_at_unix_secs),
|
||||
"last_used_at": serde_json::Value::Null,
|
||||
"created_at": serde_json::Value::Null,
|
||||
})
|
||||
}
|
||||
|
||||
pub(crate) fn normalize_admin_optional_api_key_name(
|
||||
value: Option<String>,
|
||||
) -> Result<Option<String>, String> {
|
||||
match value {
|
||||
None => Ok(None),
|
||||
Some(value) => {
|
||||
let trimmed = value.trim();
|
||||
if trimmed.is_empty() {
|
||||
return Err("API密钥名称不能为空".to_string());
|
||||
}
|
||||
Ok(Some(trimmed.chars().take(100).collect()))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn normalize_admin_api_key_providers(
|
||||
value: Option<Vec<String>>,
|
||||
) -> Result<Option<Vec<String>>, String> {
|
||||
let Some(values) = value else {
|
||||
return Ok(None);
|
||||
};
|
||||
let mut normalized = Vec::new();
|
||||
let mut seen = std::collections::BTreeSet::new();
|
||||
for provider_id in values {
|
||||
let provider_id = provider_id.trim();
|
||||
if provider_id.is_empty() {
|
||||
return Err("提供商ID不能为空".to_string());
|
||||
}
|
||||
if seen.insert(provider_id.to_string()) {
|
||||
normalized.push(provider_id.to_string());
|
||||
}
|
||||
}
|
||||
Ok(Some(normalized))
|
||||
}
|
||||
|
||||
pub(crate) fn generate_admin_user_api_key_plaintext() -> String {
|
||||
let first = uuid::Uuid::new_v4().simple().to_string();
|
||||
let second = uuid::Uuid::new_v4().simple().to_string();
|
||||
format!("sk-{}{}", first, &second[..16])
|
||||
}
|
||||
|
||||
pub(crate) fn hash_admin_user_api_key(value: &str) -> String {
|
||||
use sha2::Digest;
|
||||
|
||||
let mut hasher = sha2::Sha256::new();
|
||||
hasher.update(value.as_bytes());
|
||||
format!("{:x}", hasher.finalize())
|
||||
}
|
||||
|
||||
pub(crate) fn default_admin_user_api_key_name() -> String {
|
||||
format!("API Key {}", chrono::Utc::now().format("%Y%m%d%H%M%S"))
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_list_user_api_keys_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_api_keys_path(&request_context.request_path) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let active_filter =
|
||||
query_param_optional_bool(request_context.request_query_string.as_deref(), "is_active");
|
||||
let mut export_records = state
|
||||
.list_auth_api_key_export_records_by_user_ids(std::slice::from_ref(&user_id))
|
||||
.await?;
|
||||
if let Some(is_active) = active_filter {
|
||||
export_records.retain(|record| record.is_active == is_active);
|
||||
}
|
||||
|
||||
let snapshot_ids = export_records
|
||||
.iter()
|
||||
.map(|record| record.api_key_id.clone())
|
||||
.collect::<Vec<_>>();
|
||||
let snapshot_by_id = state
|
||||
.data
|
||||
.list_auth_api_key_snapshots_by_ids(&snapshot_ids)
|
||||
.await
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?
|
||||
.into_iter()
|
||||
.map(|snapshot| (snapshot.api_key_id.clone(), snapshot))
|
||||
.collect::<std::collections::BTreeMap<_, _>>();
|
||||
|
||||
let api_keys = export_records
|
||||
.into_iter()
|
||||
.map(|record| {
|
||||
let is_locked = snapshot_by_id
|
||||
.get(&record.api_key_id)
|
||||
.map(|snapshot| snapshot.api_key_is_locked)
|
||||
.unwrap_or(false);
|
||||
json!({
|
||||
"id": record.api_key_id,
|
||||
"name": record.name,
|
||||
"key_display": masked_user_api_key_display(state, record.key_encrypted.as_deref()),
|
||||
"is_active": record.is_active,
|
||||
"is_locked": is_locked,
|
||||
"total_requests": record.total_requests,
|
||||
"total_cost_usd": record.total_cost_usd,
|
||||
"rate_limit": record.rate_limit,
|
||||
"expires_at": format_optional_unix_secs_iso8601(record.expires_at_unix_secs),
|
||||
"last_used_at": serde_json::Value::Null,
|
||||
"created_at": serde_json::Value::Null,
|
||||
})
|
||||
})
|
||||
.collect::<Vec<_>>();
|
||||
|
||||
Ok(Json(json!({
|
||||
"api_keys": api_keys,
|
||||
"total": api_keys.len(),
|
||||
"user_email": user.email,
|
||||
"username": user.username,
|
||||
}))
|
||||
.into_response())
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_create_user_api_key_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.data.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法创建用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some(user_id) = admin_user_id_from_api_keys_path(&request_context.request_path) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
if state.find_user_auth_by_id(&user_id).await?.is_none() {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let payload = match serde_json::from_slice::<AdminCreateUserApiKeyRequest>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
if payload.allowed_api_formats.is_some()
|
||||
|| payload.allowed_models.is_some()
|
||||
|| payload.expire_days.is_some()
|
||||
|| payload.expires_at.is_some()
|
||||
|| payload.initial_balance_usd.is_some()
|
||||
|| payload.unlimited_balance.unwrap_or(false)
|
||||
|| payload.is_standalone.unwrap_or(false)
|
||||
|| payload.auto_delete_on_expiry.unwrap_or(false)
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "当前仅支持 name、rate_limit、allowed_providers 字段" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let name = match normalize_admin_optional_api_key_name(payload.name) {
|
||||
Ok(Some(value)) => value,
|
||||
Ok(None) => default_admin_user_api_key_name(),
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let allowed_providers = match normalize_admin_api_key_providers(payload.allowed_providers) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let rate_limit = payload.rate_limit.unwrap_or(0);
|
||||
if rate_limit < 0 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let plaintext_key = generate_admin_user_api_key_plaintext();
|
||||
let Some(key_encrypted) = encrypt_catalog_secret_with_fallbacks(state, &plaintext_key) else {
|
||||
return Ok((
|
||||
http::StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "detail": "API密钥加密失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let Some(created) = state
|
||||
.create_user_api_key(aether_data::repository::auth::CreateUserApiKeyRecord {
|
||||
user_id: user_id.clone(),
|
||||
api_key_id: uuid::Uuid::new_v4().to_string(),
|
||||
key_hash: hash_admin_user_api_key(&plaintext_key),
|
||||
key_encrypted: Some(key_encrypted),
|
||||
name: Some(name.clone()),
|
||||
rate_limit,
|
||||
concurrent_limit: 5,
|
||||
})
|
||||
.await?
|
||||
else {
|
||||
return Ok(build_admin_users_data_unavailable_response());
|
||||
};
|
||||
|
||||
let created = if allowed_providers.is_some() {
|
||||
match state
|
||||
.set_user_api_key_allowed_providers(&user_id, &created.api_key_id, allowed_providers)
|
||||
.await?
|
||||
{
|
||||
Some(updated) => updated,
|
||||
None => created,
|
||||
}
|
||||
} else {
|
||||
created
|
||||
};
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(json!({
|
||||
"id": created.api_key_id,
|
||||
"key": plaintext_key,
|
||||
"name": created.name,
|
||||
"key_display": masked_user_api_key_display(state, created.key_encrypted.as_deref()),
|
||||
"rate_limit": created.rate_limit,
|
||||
"expires_at": format_optional_unix_secs_iso8601(created.expires_at_unix_secs),
|
||||
"created_at": chrono::Utc::now().to_rfc3339(),
|
||||
"message": "API Key创建成功,请妥善保存完整密钥",
|
||||
}))
|
||||
.into_response(),
|
||||
"admin_user_api_key_created",
|
||||
"create_user_api_key",
|
||||
"user_api_key",
|
||||
&created.api_key_id,
|
||||
))
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_update_user_api_key_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.data.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法更新用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some((user_id, api_key_id)) = admin_user_api_key_parts(&request_context.request_path)
|
||||
else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let payload = match serde_json::from_slice::<AdminUpdateUserApiKeyRequest>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let name = match normalize_admin_optional_api_key_name(payload.name) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
if payload.rate_limit.is_some_and(|value| value < 0) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let Some(updated) = state
|
||||
.update_user_api_key_basic(aether_data::repository::auth::UpdateUserApiKeyBasicRecord {
|
||||
user_id,
|
||||
api_key_id: api_key_id.clone(),
|
||||
name,
|
||||
rate_limit: payload.rate_limit,
|
||||
})
|
||||
.await?
|
||||
else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let is_locked = state
|
||||
.data
|
||||
.list_auth_api_key_snapshots_by_ids(std::slice::from_ref(&api_key_id))
|
||||
.await
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?
|
||||
.into_iter()
|
||||
.find(|snapshot| snapshot.api_key_id == api_key_id)
|
||||
.map(|snapshot| snapshot.api_key_is_locked)
|
||||
.unwrap_or(false);
|
||||
let mut payload = build_admin_user_api_key_detail_payload(state, &updated, is_locked);
|
||||
payload["message"] = json!("API Key更新成功");
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(payload).into_response(),
|
||||
"admin_user_api_key_updated",
|
||||
"update_user_api_key",
|
||||
"user_api_key",
|
||||
&api_key_id,
|
||||
))
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_delete_user_api_key_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.data.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法删除用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some((user_id, api_key_id)) = admin_user_api_key_parts(&request_context.request_path)
|
||||
else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
|
||||
match state.delete_user_api_key(&user_id, &api_key_id).await? {
|
||||
true => Ok(attach_admin_audit_response(
|
||||
Json(json!({ "message": "API Key已删除" })).into_response(),
|
||||
"admin_user_api_key_deleted",
|
||||
"delete_user_api_key",
|
||||
"user_api_key",
|
||||
&api_key_id,
|
||||
)),
|
||||
false => Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response()),
|
||||
}
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_toggle_user_api_key_lock_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.data.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法锁定或解锁用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some((user_id, api_key_id)) = admin_user_api_key_lock_parts(&request_context.request_path)
|
||||
else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
|
||||
let Some(snapshot) = state
|
||||
.data
|
||||
.list_auth_api_key_snapshots_by_ids(std::slice::from_ref(&api_key_id))
|
||||
.await
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?
|
||||
.into_iter()
|
||||
.find(|snapshot| snapshot.user_id == user_id && snapshot.api_key_id == api_key_id)
|
||||
else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
if snapshot.api_key_is_standalone {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let desired_is_locked = match request_body {
|
||||
None => !snapshot.api_key_is_locked,
|
||||
Some(body) if body.is_empty() => !snapshot.api_key_is_locked,
|
||||
Some(body) => match serde_json::from_slice::<AdminToggleUserApiKeyLockRequest>(body) {
|
||||
Ok(payload) => payload.locked.unwrap_or(!snapshot.api_key_is_locked),
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
},
|
||||
};
|
||||
|
||||
if !state
|
||||
.set_user_api_key_locked(&user_id, &api_key_id, desired_is_locked)
|
||||
.await?
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(json!({
|
||||
"id": api_key_id,
|
||||
"is_locked": desired_is_locked,
|
||||
"message": if desired_is_locked {
|
||||
"API密钥已锁定"
|
||||
} else {
|
||||
"API密钥已解锁"
|
||||
},
|
||||
}))
|
||||
.into_response(),
|
||||
"admin_user_api_key_lock_toggled",
|
||||
"toggle_user_api_key_lock",
|
||||
"user_api_key",
|
||||
&api_key_id,
|
||||
))
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_reveal_user_api_key_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some((user_id, key_id)) = admin_user_api_key_full_key_parts(&request_context.request_path)
|
||||
else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
|
||||
let records = state
|
||||
.list_auth_api_key_export_records_by_user_ids(std::slice::from_ref(&user_id))
|
||||
.await?;
|
||||
let Some(record) = records
|
||||
.into_iter()
|
||||
.find(|record| record.api_key_id == key_id)
|
||||
else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let Some(ciphertext) = record.key_encrypted.as_deref().map(str::trim) else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "该密钥没有存储完整密钥信息" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
if ciphertext.is_empty() {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "该密钥没有存储完整密钥信息" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let Some(full_key) = decrypt_catalog_secret_with_fallbacks(state.encryption_key(), ciphertext)
|
||||
else {
|
||||
return Ok((
|
||||
http::StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "detail": "解密密钥失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(json!({ "key": full_key })).into_response(),
|
||||
"admin_user_api_key_revealed",
|
||||
"reveal_user_api_key",
|
||||
"user_api_key",
|
||||
&key_id,
|
||||
))
|
||||
}
|
||||
@@ -0,0 +1,117 @@
|
||||
use crate::handlers::admin::request::AdminAppState;
|
||||
use crate::handlers::admin::shared::{
|
||||
attach_admin_audit_response, decrypt_catalog_secret_with_fallbacks,
|
||||
};
|
||||
use axum::{body::Body, response::Response};
|
||||
use serde_json::json;
|
||||
use std::collections::BTreeSet;
|
||||
|
||||
pub(crate) fn format_optional_unix_secs_iso8601(value: Option<u64>) -> Option<String> {
|
||||
let secs = value?;
|
||||
let secs = i64::try_from(secs).ok()?;
|
||||
chrono::DateTime::<chrono::Utc>::from_timestamp(secs, 0).map(|value| value.to_rfc3339())
|
||||
}
|
||||
|
||||
pub(crate) fn masked_user_api_key_display(
|
||||
state: &AdminAppState<'_>,
|
||||
ciphertext: Option<&str>,
|
||||
) -> String {
|
||||
let Some(ciphertext) = ciphertext.map(str::trim).filter(|value| !value.is_empty()) else {
|
||||
return "sk-****".to_string();
|
||||
};
|
||||
let Some(full_key) = decrypt_catalog_secret_with_fallbacks(state.encryption_key(), ciphertext)
|
||||
else {
|
||||
return "sk-****".to_string();
|
||||
};
|
||||
let prefix_len = full_key.len().min(10);
|
||||
let prefix = &full_key[..prefix_len];
|
||||
let suffix = if full_key.len() >= 4 {
|
||||
&full_key[full_key.len() - 4..]
|
||||
} else {
|
||||
""
|
||||
};
|
||||
format!("{prefix}...{suffix}")
|
||||
}
|
||||
|
||||
pub(super) fn build_admin_user_api_key_detail_payload(
|
||||
state: &AdminAppState<'_>,
|
||||
record: &aether_data::repository::auth::StoredAuthApiKeyExportRecord,
|
||||
is_locked: bool,
|
||||
) -> serde_json::Value {
|
||||
json!({
|
||||
"id": record.api_key_id,
|
||||
"name": record.name,
|
||||
"key_display": masked_user_api_key_display(state, record.key_encrypted.as_deref()),
|
||||
"is_active": record.is_active,
|
||||
"is_locked": is_locked,
|
||||
"total_requests": record.total_requests,
|
||||
"total_cost_usd": record.total_cost_usd,
|
||||
"rate_limit": record.rate_limit,
|
||||
"expires_at": format_optional_unix_secs_iso8601(record.expires_at_unix_secs),
|
||||
"last_used_at": serde_json::Value::Null,
|
||||
"created_at": serde_json::Value::Null,
|
||||
})
|
||||
}
|
||||
|
||||
pub(crate) fn normalize_admin_optional_api_key_name(
|
||||
value: Option<String>,
|
||||
) -> Result<Option<String>, String> {
|
||||
match value {
|
||||
None => Ok(None),
|
||||
Some(value) => {
|
||||
let trimmed = value.trim();
|
||||
if trimmed.is_empty() {
|
||||
return Err("API密钥名称不能为空".to_string());
|
||||
}
|
||||
Ok(Some(trimmed.chars().take(100).collect()))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pub(super) fn normalize_admin_api_key_providers(
|
||||
value: Option<Vec<String>>,
|
||||
) -> Result<Option<Vec<String>>, String> {
|
||||
let Some(values) = value else {
|
||||
return Ok(None);
|
||||
};
|
||||
let mut normalized = Vec::new();
|
||||
let mut seen = BTreeSet::new();
|
||||
for provider_id in values {
|
||||
let provider_id = provider_id.trim();
|
||||
if provider_id.is_empty() {
|
||||
return Err("提供商ID不能为空".to_string());
|
||||
}
|
||||
if seen.insert(provider_id.to_string()) {
|
||||
normalized.push(provider_id.to_string());
|
||||
}
|
||||
}
|
||||
Ok(Some(normalized))
|
||||
}
|
||||
|
||||
pub(crate) fn generate_admin_user_api_key_plaintext() -> String {
|
||||
let first = uuid::Uuid::new_v4().simple().to_string();
|
||||
let second = uuid::Uuid::new_v4().simple().to_string();
|
||||
format!("sk-{}{}", first, &second[..16])
|
||||
}
|
||||
|
||||
pub(crate) fn hash_admin_user_api_key(value: &str) -> String {
|
||||
use sha2::Digest;
|
||||
|
||||
let mut hasher = sha2::Sha256::new();
|
||||
hasher.update(value.as_bytes());
|
||||
format!("{:x}", hasher.finalize())
|
||||
}
|
||||
|
||||
pub(crate) fn default_admin_user_api_key_name() -> String {
|
||||
format!("API Key {}", chrono::Utc::now().format("%Y%m%d%H%M%S"))
|
||||
}
|
||||
|
||||
pub(super) fn attach_audit_response(
|
||||
response: Response<Body>,
|
||||
action: &'static str,
|
||||
event_type: &'static str,
|
||||
object_type: &'static str,
|
||||
object_id: &str,
|
||||
) -> Response<Body> {
|
||||
attach_admin_audit_response(response, action, event_type, object_type, object_id)
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
mod helpers;
|
||||
mod paths;
|
||||
mod responses;
|
||||
|
||||
pub(crate) use helpers::{
|
||||
default_admin_user_api_key_name, format_optional_unix_secs_iso8601,
|
||||
generate_admin_user_api_key_plaintext, hash_admin_user_api_key, masked_user_api_key_display,
|
||||
normalize_admin_optional_api_key_name,
|
||||
};
|
||||
pub(super) use responses::{
|
||||
build_admin_create_user_api_key_response, build_admin_delete_user_api_key_response,
|
||||
build_admin_list_user_api_keys_response, build_admin_reveal_user_api_key_response,
|
||||
build_admin_toggle_user_api_key_lock_response, build_admin_update_user_api_key_response,
|
||||
};
|
||||
@@ -0,0 +1,57 @@
|
||||
pub(in super::super) fn admin_user_api_key_full_key_parts(
|
||||
request_path: &str,
|
||||
) -> Option<(String, String)> {
|
||||
let raw = request_path.strip_prefix("/api/admin/users/")?;
|
||||
let (user_id, key_id) = raw.split_once("/api-keys/")?;
|
||||
let user_id = user_id.trim().trim_matches('/');
|
||||
let key_id = key_id
|
||||
.trim()
|
||||
.trim_matches('/')
|
||||
.strip_suffix("/full-key")?
|
||||
.trim()
|
||||
.trim_matches('/');
|
||||
if user_id.is_empty() || key_id.is_empty() || user_id.contains('/') || key_id.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some((user_id.to_string(), key_id.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
pub(in super::super) fn admin_user_api_key_parts(request_path: &str) -> Option<(String, String)> {
|
||||
let raw = request_path.strip_prefix("/api/admin/users/")?;
|
||||
let (user_id, key_id) = raw.split_once("/api-keys/")?;
|
||||
let user_id = user_id.trim().trim_matches('/');
|
||||
let key_id = key_id.trim().trim_matches('/');
|
||||
if user_id.is_empty() || key_id.is_empty() || user_id.contains('/') || key_id.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some((user_id.to_string(), key_id.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
pub(in super::super) fn admin_user_api_key_lock_parts(
|
||||
request_path: &str,
|
||||
) -> Option<(String, String)> {
|
||||
let raw = request_path.strip_prefix("/api/admin/users/")?;
|
||||
let (user_id, key_id) = raw.split_once("/api-keys/")?;
|
||||
let user_id = user_id.trim().trim_matches('/');
|
||||
let key_id = key_id
|
||||
.trim()
|
||||
.trim_matches('/')
|
||||
.strip_suffix("/lock")?
|
||||
.trim()
|
||||
.trim_matches('/');
|
||||
if user_id.is_empty() || key_id.is_empty() || user_id.contains('/') || key_id.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some((user_id.to_string(), key_id.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
pub(in super::super) fn admin_user_id_from_api_keys_path(request_path: &str) -> Option<String> {
|
||||
request_path
|
||||
.strip_prefix("/api/admin/users/")?
|
||||
.strip_suffix("/api-keys")
|
||||
.map(|value| value.trim().trim_matches('/').to_string())
|
||||
.filter(|value| !value.is_empty() && !value.contains('/'))
|
||||
}
|
||||
@@ -0,0 +1,160 @@
|
||||
use super::super::super::{
|
||||
build_admin_users_bad_request_response, build_admin_users_data_unavailable_response,
|
||||
build_admin_users_read_only_response, AdminCreateUserApiKeyRequest,
|
||||
};
|
||||
use super::super::helpers::{
|
||||
attach_audit_response, default_admin_user_api_key_name, format_optional_unix_secs_iso8601,
|
||||
generate_admin_user_api_key_plaintext, hash_admin_user_api_key, masked_user_api_key_display,
|
||||
normalize_admin_api_key_providers, normalize_admin_optional_api_key_name,
|
||||
};
|
||||
use super::super::paths::admin_user_id_from_api_keys_path;
|
||||
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(crate) async fn build_admin_create_user_api_key_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法创建用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some(user_id) = admin_user_id_from_api_keys_path(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
if state.find_user_auth_by_id(&user_id).await?.is_none() {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let payload = match serde_json::from_slice::<AdminCreateUserApiKeyRequest>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
};
|
||||
if payload.allowed_api_formats.is_some()
|
||||
|| payload.allowed_models.is_some()
|
||||
|| payload.expire_days.is_some()
|
||||
|| payload.expires_at.is_some()
|
||||
|| payload.initial_balance_usd.is_some()
|
||||
|| payload.unlimited_balance.unwrap_or(false)
|
||||
|| payload.is_standalone.unwrap_or(false)
|
||||
|| payload.auto_delete_on_expiry.unwrap_or(false)
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "当前仅支持 name、rate_limit、allowed_providers 字段" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let name = match normalize_admin_optional_api_key_name(payload.name) {
|
||||
Ok(Some(value)) => value,
|
||||
Ok(None) => default_admin_user_api_key_name(),
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
};
|
||||
let allowed_providers = match normalize_admin_api_key_providers(payload.allowed_providers) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
};
|
||||
let rate_limit = payload.rate_limit.unwrap_or(0);
|
||||
if rate_limit < 0 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let plaintext_key = generate_admin_user_api_key_plaintext();
|
||||
let Some(key_encrypted) = state.encrypt_catalog_secret_with_fallbacks(&plaintext_key) else {
|
||||
return Ok((
|
||||
http::StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "detail": "API密钥加密失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let Some(created) = state
|
||||
.create_user_api_key(aether_data::repository::auth::CreateUserApiKeyRecord {
|
||||
user_id: user_id.clone(),
|
||||
api_key_id: uuid::Uuid::new_v4().to_string(),
|
||||
key_hash: hash_admin_user_api_key(&plaintext_key),
|
||||
key_encrypted: Some(key_encrypted),
|
||||
name: Some(name.clone()),
|
||||
rate_limit,
|
||||
concurrent_limit: 5,
|
||||
})
|
||||
.await?
|
||||
else {
|
||||
return Ok(build_admin_users_data_unavailable_response());
|
||||
};
|
||||
|
||||
let created = if allowed_providers.is_some() {
|
||||
match state
|
||||
.set_user_api_key_allowed_providers(&user_id, &created.api_key_id, allowed_providers)
|
||||
.await?
|
||||
{
|
||||
Some(updated) => updated,
|
||||
None => created,
|
||||
}
|
||||
} else {
|
||||
created
|
||||
};
|
||||
|
||||
Ok(attach_audit_response(
|
||||
Json(json!({
|
||||
"id": created.api_key_id,
|
||||
"key": plaintext_key,
|
||||
"name": created.name,
|
||||
"key_display": masked_user_api_key_display(state, created.key_encrypted.as_deref()),
|
||||
"rate_limit": created.rate_limit,
|
||||
"expires_at": format_optional_unix_secs_iso8601(created.expires_at_unix_secs),
|
||||
"created_at": chrono::Utc::now().to_rfc3339(),
|
||||
"message": "API Key创建成功,请妥善保存完整密钥",
|
||||
}))
|
||||
.into_response(),
|
||||
"admin_user_api_key_created",
|
||||
"create_user_api_key",
|
||||
"user_api_key",
|
||||
&created.api_key_id,
|
||||
))
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
use super::super::super::{
|
||||
build_admin_users_bad_request_response, build_admin_users_read_only_response,
|
||||
};
|
||||
use super::super::helpers::attach_audit_response;
|
||||
use super::super::paths::admin_user_api_key_parts;
|
||||
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(crate) async fn build_admin_delete_user_api_key_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法删除用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some((user_id, api_key_id)) = admin_user_api_key_parts(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
|
||||
match state.delete_user_api_key(&user_id, &api_key_id).await? {
|
||||
true => Ok(attach_audit_response(
|
||||
Json(json!({ "message": "API Key已删除" })).into_response(),
|
||||
"admin_user_api_key_deleted",
|
||||
"delete_user_api_key",
|
||||
"user_api_key",
|
||||
&api_key_id,
|
||||
)),
|
||||
false => Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response()),
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,79 @@
|
||||
use super::super::super::build_admin_users_bad_request_response;
|
||||
use super::super::helpers::{format_optional_unix_secs_iso8601, masked_user_api_key_display};
|
||||
use super::super::paths::admin_user_id_from_api_keys_path;
|
||||
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::handlers::admin::shared::query_param_optional_bool;
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(crate) async fn build_admin_list_user_api_keys_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_api_keys_path(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
axum::http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let active_filter = query_param_optional_bool(request_context.query_string(), "is_active");
|
||||
let mut export_records = state
|
||||
.list_auth_api_key_export_records_by_user_ids(std::slice::from_ref(&user_id))
|
||||
.await?;
|
||||
if let Some(is_active) = active_filter {
|
||||
export_records.retain(|record| record.is_active == is_active);
|
||||
}
|
||||
|
||||
let snapshot_ids = export_records
|
||||
.iter()
|
||||
.map(|record| record.api_key_id.clone())
|
||||
.collect::<Vec<_>>();
|
||||
let snapshot_by_id = state
|
||||
.list_auth_api_key_snapshots_by_ids(&snapshot_ids)
|
||||
.await?
|
||||
.into_iter()
|
||||
.map(|snapshot| (snapshot.api_key_id.clone(), snapshot))
|
||||
.collect::<std::collections::BTreeMap<_, _>>();
|
||||
|
||||
let api_keys = export_records
|
||||
.into_iter()
|
||||
.map(|record| {
|
||||
let is_locked = snapshot_by_id
|
||||
.get(&record.api_key_id)
|
||||
.map(|snapshot| snapshot.api_key_is_locked)
|
||||
.unwrap_or(false);
|
||||
json!({
|
||||
"id": record.api_key_id,
|
||||
"name": record.name,
|
||||
"key_display": masked_user_api_key_display(state, record.key_encrypted.as_deref()),
|
||||
"is_active": record.is_active,
|
||||
"is_locked": is_locked,
|
||||
"total_requests": record.total_requests,
|
||||
"total_cost_usd": record.total_cost_usd,
|
||||
"rate_limit": record.rate_limit,
|
||||
"expires_at": format_optional_unix_secs_iso8601(record.expires_at_unix_secs),
|
||||
"last_used_at": serde_json::Value::Null,
|
||||
"created_at": serde_json::Value::Null,
|
||||
})
|
||||
})
|
||||
.collect::<Vec<_>>();
|
||||
|
||||
Ok(Json(json!({
|
||||
"api_keys": api_keys,
|
||||
"total": api_keys.len(),
|
||||
"user_email": user.email,
|
||||
"username": user.username,
|
||||
}))
|
||||
.into_response())
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
mod create;
|
||||
mod delete;
|
||||
mod list;
|
||||
mod reveal;
|
||||
mod toggle_lock;
|
||||
mod update;
|
||||
|
||||
pub(in super::super::super) use create::build_admin_create_user_api_key_response;
|
||||
pub(in super::super::super) use delete::build_admin_delete_user_api_key_response;
|
||||
pub(in super::super::super) use list::build_admin_list_user_api_keys_response;
|
||||
pub(in super::super::super) use reveal::build_admin_reveal_user_api_key_response;
|
||||
pub(in super::super::super) use toggle_lock::build_admin_toggle_user_api_key_lock_response;
|
||||
pub(in super::super::super) use update::build_admin_update_user_api_key_response;
|
||||
@@ -0,0 +1,69 @@
|
||||
use super::super::super::build_admin_users_bad_request_response;
|
||||
use super::super::helpers::attach_audit_response;
|
||||
use super::super::paths::admin_user_api_key_full_key_parts;
|
||||
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(crate) async fn build_admin_reveal_user_api_key_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some((user_id, key_id)) = admin_user_api_key_full_key_parts(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
|
||||
let records = state
|
||||
.list_auth_api_key_export_records_by_user_ids(std::slice::from_ref(&user_id))
|
||||
.await?;
|
||||
let Some(record) = records
|
||||
.into_iter()
|
||||
.find(|record| record.api_key_id == key_id)
|
||||
else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let Some(ciphertext) = record.key_encrypted.as_deref().map(str::trim) else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "该密钥没有存储完整密钥信息" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
if ciphertext.is_empty() {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "该密钥没有存储完整密钥信息" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let Some(full_key) = state.decrypt_catalog_secret_with_fallbacks(ciphertext) else {
|
||||
return Ok((
|
||||
http::StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "detail": "解密密钥失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
Ok(attach_audit_response(
|
||||
Json(json!({ "key": full_key })).into_response(),
|
||||
"admin_user_api_key_revealed",
|
||||
"reveal_user_api_key",
|
||||
"user_api_key",
|
||||
&key_id,
|
||||
))
|
||||
}
|
||||
@@ -0,0 +1,98 @@
|
||||
use super::super::super::{
|
||||
build_admin_users_bad_request_response, build_admin_users_read_only_response,
|
||||
AdminToggleUserApiKeyLockRequest,
|
||||
};
|
||||
use super::super::helpers::attach_audit_response;
|
||||
use super::super::paths::admin_user_api_key_lock_parts;
|
||||
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(crate) async fn build_admin_toggle_user_api_key_lock_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法锁定或解锁用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some((user_id, api_key_id)) = admin_user_api_key_lock_parts(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
|
||||
let Some(snapshot) = state
|
||||
.list_auth_api_key_snapshots_by_ids(std::slice::from_ref(&api_key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.find(|snapshot| snapshot.user_id == user_id && snapshot.api_key_id == api_key_id)
|
||||
else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
if snapshot.api_key_is_standalone {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let desired_is_locked = match request_body {
|
||||
None => !snapshot.api_key_is_locked,
|
||||
Some(body) if body.is_empty() => !snapshot.api_key_is_locked,
|
||||
Some(body) => match serde_json::from_slice::<AdminToggleUserApiKeyLockRequest>(body) {
|
||||
Ok(payload) => payload.locked.unwrap_or(!snapshot.api_key_is_locked),
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
},
|
||||
};
|
||||
|
||||
if !state
|
||||
.set_user_api_key_locked(&user_id, &api_key_id, desired_is_locked)
|
||||
.await?
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
Ok(attach_audit_response(
|
||||
Json(json!({
|
||||
"id": api_key_id,
|
||||
"is_locked": desired_is_locked,
|
||||
"message": if desired_is_locked {
|
||||
"API密钥已锁定"
|
||||
} else {
|
||||
"API密钥已解锁"
|
||||
},
|
||||
}))
|
||||
.into_response(),
|
||||
"admin_user_api_key_lock_toggled",
|
||||
"toggle_user_api_key_lock",
|
||||
"user_api_key",
|
||||
&api_key_id,
|
||||
))
|
||||
}
|
||||
@@ -0,0 +1,104 @@
|
||||
use super::super::super::{
|
||||
build_admin_users_bad_request_response, build_admin_users_read_only_response,
|
||||
AdminUpdateUserApiKeyRequest,
|
||||
};
|
||||
use super::super::helpers::{
|
||||
attach_audit_response, build_admin_user_api_key_detail_payload,
|
||||
normalize_admin_optional_api_key_name,
|
||||
};
|
||||
use super::super::paths::admin_user_api_key_parts;
|
||||
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(crate) async fn build_admin_update_user_api_key_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.has_auth_api_key_writer() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法更新用户 API Key",
|
||||
));
|
||||
}
|
||||
|
||||
let Some((user_id, api_key_id)) = admin_user_api_key_parts(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 key_id",
|
||||
));
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let payload = match serde_json::from_slice::<AdminUpdateUserApiKeyRequest>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
};
|
||||
let name = match normalize_admin_optional_api_key_name(payload.name) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
};
|
||||
if payload.rate_limit.is_some_and(|value| value < 0) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let Some(updated) = state
|
||||
.update_user_api_key_basic(aether_data::repository::auth::UpdateUserApiKeyBasicRecord {
|
||||
user_id,
|
||||
api_key_id: api_key_id.clone(),
|
||||
name,
|
||||
rate_limit: payload.rate_limit,
|
||||
})
|
||||
.await?
|
||||
else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "API Key不存在或不属于该用户" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let is_locked = state
|
||||
.list_auth_api_key_snapshots_by_ids(std::slice::from_ref(&api_key_id))
|
||||
.await?
|
||||
.into_iter()
|
||||
.find(|snapshot| snapshot.api_key_id == api_key_id)
|
||||
.map(|snapshot| snapshot.api_key_is_locked)
|
||||
.unwrap_or(false);
|
||||
let mut payload = build_admin_user_api_key_detail_payload(state, &updated, is_locked);
|
||||
payload["message"] = json!("API Key更新成功");
|
||||
Ok(attach_audit_response(
|
||||
Json(payload).into_response(),
|
||||
"admin_user_api_key_updated",
|
||||
"update_user_api_key",
|
||||
"user_api_key",
|
||||
&api_key_id,
|
||||
))
|
||||
}
|
||||
@@ -1,768 +0,0 @@
|
||||
use super::{
|
||||
admin_default_user_initial_gift, build_admin_users_bad_request_response,
|
||||
build_admin_users_data_unavailable_response, build_admin_users_read_only_response,
|
||||
format_optional_datetime_iso8601, normalize_admin_optional_user_email,
|
||||
normalize_admin_user_api_formats, normalize_admin_user_role, normalize_admin_user_string_list,
|
||||
normalize_admin_username, validate_admin_user_password, AdminCreateUserRequest,
|
||||
AdminUpdateUserFieldPresence, AdminUpdateUserRequest,
|
||||
};
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::handlers::admin::shared::{
|
||||
attach_admin_audit_response, query_param_optional_bool, query_param_value,
|
||||
};
|
||||
use crate::{AppState, GatewayError};
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
async fn admin_user_password_policy(state: &AppState) -> Result<String, GatewayError> {
|
||||
let config = state
|
||||
.read_system_config_json_value("password_policy_level")
|
||||
.await?;
|
||||
Ok(
|
||||
match config
|
||||
.as_ref()
|
||||
.and_then(|value| value.as_str())
|
||||
.unwrap_or("weak")
|
||||
.trim()
|
||||
.to_ascii_lowercase()
|
||||
.as_str()
|
||||
{
|
||||
"medium" => "medium".to_string(),
|
||||
"strong" => "strong".to_string(),
|
||||
_ => "weak".to_string(),
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
async fn find_admin_export_user(
|
||||
state: &AppState,
|
||||
user_id: &str,
|
||||
) -> Result<Option<aether_data::repository::users::StoredUserExportRow>, GatewayError> {
|
||||
state.find_export_user_by_id(user_id).await
|
||||
}
|
||||
|
||||
fn build_admin_user_payload(
|
||||
user: &aether_data::repository::users::StoredUserAuthRecord,
|
||||
rate_limit: Option<i32>,
|
||||
unlimited: bool,
|
||||
) -> serde_json::Value {
|
||||
json!({
|
||||
"id": user.id,
|
||||
"email": user.email,
|
||||
"username": user.username,
|
||||
"role": user.role,
|
||||
"allowed_providers": user.allowed_providers,
|
||||
"allowed_api_formats": user.allowed_api_formats,
|
||||
"allowed_models": user.allowed_models,
|
||||
"rate_limit": rate_limit,
|
||||
"unlimited": unlimited,
|
||||
"is_active": user.is_active,
|
||||
"created_at": format_optional_datetime_iso8601(user.created_at),
|
||||
"updated_at": serde_json::Value::Null,
|
||||
"last_login_at": format_optional_datetime_iso8601(user.last_login_at),
|
||||
})
|
||||
}
|
||||
|
||||
fn admin_user_id_from_detail_path(request_path: &str) -> Option<String> {
|
||||
let value = request_path
|
||||
.strip_prefix("/api/admin/users/")?
|
||||
.trim()
|
||||
.trim_matches('/')
|
||||
.to_string();
|
||||
if value.is_empty() || value.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some(value)
|
||||
}
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_list_users_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let skip = query_param_value(request_context.request_query_string.as_deref(), "skip")
|
||||
.and_then(|value| value.parse::<usize>().ok())
|
||||
.unwrap_or(0);
|
||||
let limit = query_param_value(request_context.request_query_string.as_deref(), "limit")
|
||||
.and_then(|value| value.parse::<usize>().ok())
|
||||
.unwrap_or(100)
|
||||
.clamp(1, 1000);
|
||||
let role = query_param_value(request_context.request_query_string.as_deref(), "role")
|
||||
.map(|value| value.trim().to_ascii_lowercase())
|
||||
.filter(|value| !value.is_empty());
|
||||
let is_active =
|
||||
query_param_optional_bool(request_context.request_query_string.as_deref(), "is_active");
|
||||
|
||||
let paged_rows = state
|
||||
.list_export_users_page(&aether_data::repository::users::UserExportListQuery {
|
||||
skip,
|
||||
limit,
|
||||
role: role.clone(),
|
||||
is_active,
|
||||
})
|
||||
.await?;
|
||||
let user_ids = paged_rows
|
||||
.iter()
|
||||
.map(|row| row.id.clone())
|
||||
.collect::<Vec<_>>();
|
||||
let auth_by_user_id = state
|
||||
.list_user_auth_by_ids(&user_ids)
|
||||
.await?
|
||||
.into_iter()
|
||||
.map(|user| (user.id.clone(), user))
|
||||
.collect::<std::collections::BTreeMap<_, _>>();
|
||||
let wallet_by_user_id = state
|
||||
.list_wallet_snapshots_by_user_ids(&user_ids)
|
||||
.await?
|
||||
.into_iter()
|
||||
.filter_map(|wallet| wallet.user_id.clone().map(|user_id| (user_id, wallet)))
|
||||
.collect::<std::collections::BTreeMap<_, _>>();
|
||||
|
||||
let mut payload = Vec::with_capacity(paged_rows.len());
|
||||
for row in paged_rows {
|
||||
let auth = auth_by_user_id.get(&row.id);
|
||||
let unlimited = wallet_by_user_id
|
||||
.get(&row.id)
|
||||
.is_some_and(|wallet| wallet.limit_mode.eq_ignore_ascii_case("unlimited"));
|
||||
payload.push(json!({
|
||||
"id": row.id,
|
||||
"email": row.email,
|
||||
"username": row.username,
|
||||
"role": row.role,
|
||||
"allowed_providers": row.allowed_providers,
|
||||
"allowed_api_formats": row.allowed_api_formats,
|
||||
"allowed_models": row.allowed_models,
|
||||
"rate_limit": row.rate_limit,
|
||||
"unlimited": unlimited,
|
||||
"is_active": row.is_active,
|
||||
"created_at": format_optional_datetime_iso8601(auth.as_ref().and_then(|user| user.created_at)),
|
||||
"updated_at": serde_json::Value::Null,
|
||||
"last_login_at": format_optional_datetime_iso8601(
|
||||
auth.as_ref().and_then(|user| user.last_login_at),
|
||||
),
|
||||
}));
|
||||
}
|
||||
|
||||
Ok(Json(payload).into_response())
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_get_user_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_detail_path(&request_context.request_path) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let wallet = state
|
||||
.find_wallet(aether_data::repository::wallet::WalletLookupKey::UserId(
|
||||
&user_id,
|
||||
))
|
||||
.await?;
|
||||
let export_row = find_admin_export_user(state, &user_id).await?;
|
||||
let unlimited = wallet
|
||||
.as_ref()
|
||||
.is_some_and(|wallet| wallet.limit_mode.eq_ignore_ascii_case("unlimited"));
|
||||
Ok(Json(build_admin_user_payload(
|
||||
&user,
|
||||
export_row.as_ref().and_then(|row| row.rate_limit),
|
||||
unlimited,
|
||||
))
|
||||
.into_response())
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_create_user_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.has_auth_user_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法创建用户",
|
||||
));
|
||||
}
|
||||
if !state.has_auth_wallet_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法初始化用户钱包",
|
||||
));
|
||||
}
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let payload = match serde_json::from_slice::<AdminCreateUserRequest>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
|
||||
let email = match normalize_admin_optional_user_email(payload.email.as_deref()) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let username = match normalize_admin_username(&payload.username) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let role = match normalize_admin_user_role(payload.role.as_deref()) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let password_policy = admin_user_password_policy(state).await?;
|
||||
if let Err(detail) = validate_admin_user_password(&payload.password, &password_policy) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if payload.rate_limit.is_some_and(|value| value < 0) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if payload
|
||||
.initial_gift_usd
|
||||
.is_some_and(|value| !value.is_finite() || !(0.0..=10000.0).contains(&value))
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "初始赠款必须在 0-10000 范围内" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
let allowed_providers =
|
||||
match normalize_admin_user_string_list(payload.allowed_providers, "allowed_providers") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let allowed_api_formats = match normalize_admin_user_api_formats(payload.allowed_api_formats) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let allowed_models =
|
||||
match normalize_admin_user_string_list(payload.allowed_models, "allowed_models") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
|
||||
if let Some(email) = email.as_deref() {
|
||||
if state.find_user_auth_by_identifier(email).await?.is_some() {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("邮箱已存在: {email}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
if state
|
||||
.find_user_auth_by_identifier(&username)
|
||||
.await?
|
||||
.is_some()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("用户名已存在: {username}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let password_hash = match bcrypt::hash(&payload.password, bcrypt::DEFAULT_COST) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "密码长度不能超过72字节" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let initial_gift_usd = if payload.unlimited {
|
||||
0.0
|
||||
} else if let Some(value) = payload.initial_gift_usd {
|
||||
value
|
||||
} else {
|
||||
admin_default_user_initial_gift(
|
||||
state
|
||||
.read_system_config_json_value("default_user_initial_gift_usd")
|
||||
.await?
|
||||
.as_ref(),
|
||||
)
|
||||
};
|
||||
|
||||
let Some(user) = state
|
||||
.create_local_auth_user_with_settings(
|
||||
email,
|
||||
false,
|
||||
username,
|
||||
password_hash,
|
||||
role,
|
||||
allowed_providers,
|
||||
allowed_api_formats,
|
||||
allowed_models,
|
||||
payload.rate_limit,
|
||||
)
|
||||
.await?
|
||||
else {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法创建用户",
|
||||
));
|
||||
};
|
||||
|
||||
if state
|
||||
.initialize_auth_user_wallet(&user.id, initial_gift_usd, payload.unlimited)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法初始化用户钱包",
|
||||
));
|
||||
}
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(build_admin_user_payload(
|
||||
&user,
|
||||
payload.rate_limit,
|
||||
payload.unlimited,
|
||||
))
|
||||
.into_response(),
|
||||
"admin_user_created",
|
||||
"create_user",
|
||||
"user",
|
||||
&user.id,
|
||||
))
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_update_user_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_detail_path(&request_context.request_path) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(_existing_user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let raw_payload = match serde_json::from_slice::<serde_json::Value>(request_body) {
|
||||
Ok(serde_json::Value::Object(map)) => map,
|
||||
_ => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let field_presence = AdminUpdateUserFieldPresence {
|
||||
allowed_providers: raw_payload.contains_key("allowed_providers"),
|
||||
allowed_api_formats: raw_payload.contains_key("allowed_api_formats"),
|
||||
allowed_models: raw_payload.contains_key("allowed_models"),
|
||||
};
|
||||
let payload = match serde_json::from_value::<AdminUpdateUserRequest>(serde_json::Value::Object(
|
||||
raw_payload.clone(),
|
||||
)) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
|
||||
let email = match payload.email.as_deref() {
|
||||
Some(value) => match normalize_admin_optional_user_email(Some(value)) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
},
|
||||
None => None,
|
||||
};
|
||||
if let Some(email) = email.as_deref() {
|
||||
if state
|
||||
.is_other_user_auth_email_taken(email, &user_id)
|
||||
.await?
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("邮箱已存在: {email}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
let username = match payload.username.as_deref() {
|
||||
Some(value) => match normalize_admin_username(value) {
|
||||
Ok(value) => Some(value),
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
},
|
||||
None => None,
|
||||
};
|
||||
if let Some(username) = username.as_deref() {
|
||||
if state
|
||||
.is_other_user_auth_username_taken(username, &user_id)
|
||||
.await?
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("用户名已存在: {username}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
let role = match payload.role.as_deref() {
|
||||
Some(value) => match normalize_admin_user_role(Some(value)) {
|
||||
Ok(value) => Some(value),
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
},
|
||||
None => None,
|
||||
};
|
||||
if payload.rate_limit.is_some_and(|value| value < 0) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
let allowed_providers = if field_presence.allowed_providers {
|
||||
match normalize_admin_user_string_list(payload.allowed_providers, "allowed_providers") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
}
|
||||
} else {
|
||||
None
|
||||
};
|
||||
let allowed_api_formats = if field_presence.allowed_api_formats {
|
||||
match normalize_admin_user_api_formats(payload.allowed_api_formats) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
}
|
||||
} else {
|
||||
None
|
||||
};
|
||||
let allowed_models = if field_presence.allowed_models {
|
||||
match normalize_admin_user_string_list(payload.allowed_models, "allowed_models") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
}
|
||||
} else {
|
||||
None
|
||||
};
|
||||
let needs_auth_user_write = email.is_some()
|
||||
|| username.is_some()
|
||||
|| payload.password.is_some()
|
||||
|| role.is_some()
|
||||
|| field_presence.allowed_providers
|
||||
|| field_presence.allowed_api_formats
|
||||
|| field_presence.allowed_models
|
||||
|| payload.rate_limit.is_some()
|
||||
|| payload.is_active.is_some();
|
||||
if needs_auth_user_write && !state.has_auth_user_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法更新用户",
|
||||
));
|
||||
}
|
||||
if payload.unlimited.is_some() && !state.has_auth_wallet_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法更新用户钱包",
|
||||
));
|
||||
}
|
||||
|
||||
if email.is_some() || username.is_some() {
|
||||
if state
|
||||
.update_local_auth_user_profile(&user_id, email.clone(), username.clone())
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
if let Some(password) = payload.password.as_deref() {
|
||||
let password_policy = admin_user_password_policy(state).await?;
|
||||
if let Err(detail) = validate_admin_user_password(password, &password_policy) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
let password_hash = match bcrypt::hash(password, bcrypt::DEFAULT_COST) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "密码长度不能超过72字节" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
if state
|
||||
.update_local_auth_user_password_hash(&user_id, password_hash, chrono::Utc::now())
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
if role.is_some()
|
||||
|| field_presence.allowed_providers
|
||||
|| field_presence.allowed_api_formats
|
||||
|| field_presence.allowed_models
|
||||
|| payload.rate_limit.is_some()
|
||||
|| payload.is_active.is_some()
|
||||
{
|
||||
if state
|
||||
.update_local_auth_user_admin_fields(
|
||||
&user_id,
|
||||
role,
|
||||
field_presence.allowed_providers,
|
||||
allowed_providers,
|
||||
field_presence.allowed_api_formats,
|
||||
allowed_api_formats,
|
||||
field_presence.allowed_models,
|
||||
allowed_models,
|
||||
payload.rate_limit,
|
||||
payload.is_active,
|
||||
)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
if let Some(unlimited) = payload.unlimited {
|
||||
match state
|
||||
.find_wallet(aether_data::repository::wallet::WalletLookupKey::UserId(
|
||||
&user_id,
|
||||
))
|
||||
.await?
|
||||
{
|
||||
Some(wallet) => {
|
||||
let desired_limit_mode = if unlimited { "unlimited" } else { "finite" };
|
||||
if !wallet.limit_mode.eq_ignore_ascii_case(desired_limit_mode) {
|
||||
if state
|
||||
.update_auth_user_wallet_limit_mode(&user_id, desired_limit_mode)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok(build_admin_users_data_unavailable_response());
|
||||
}
|
||||
}
|
||||
}
|
||||
None => {
|
||||
if state
|
||||
.initialize_auth_user_wallet(&user_id, 0.0, unlimited)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok(build_admin_users_data_unavailable_response());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let wallet = state
|
||||
.find_wallet(aether_data::repository::wallet::WalletLookupKey::UserId(
|
||||
&user_id,
|
||||
))
|
||||
.await?;
|
||||
let unlimited = wallet
|
||||
.as_ref()
|
||||
.is_some_and(|wallet| wallet.limit_mode.eq_ignore_ascii_case("unlimited"));
|
||||
let export_row = find_admin_export_user(state, &user_id).await?;
|
||||
let rate_limit = export_row
|
||||
.as_ref()
|
||||
.and_then(|row| row.rate_limit)
|
||||
.or(payload.rate_limit);
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(build_admin_user_payload(&user, rate_limit, unlimited)).into_response(),
|
||||
"admin_user_updated",
|
||||
"update_user",
|
||||
"user",
|
||||
&user_id,
|
||||
))
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_delete_user_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_detail_path(&request_context.request_path) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
if user.role.eq_ignore_ascii_case("admin") && state.count_active_admin_users().await? <= 1 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "不能删除最后一个管理员账户" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if state.count_user_pending_refunds(&user_id).await? > 0 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "用户存在未完结退款,禁止删除" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if state.count_user_pending_payment_orders(&user_id).await? > 0 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "用户存在未完结充值订单,禁止删除" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
if !state.delete_local_auth_user(&user_id).await? {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(json!({ "message": "用户删除成功" })).into_response(),
|
||||
"admin_user_deleted",
|
||||
"delete_user",
|
||||
"user",
|
||||
&user_id,
|
||||
))
|
||||
}
|
||||
@@ -0,0 +1,225 @@
|
||||
use super::super::{
|
||||
admin_default_user_initial_gift, build_admin_users_read_only_response,
|
||||
normalize_admin_optional_user_email, normalize_admin_user_api_formats,
|
||||
normalize_admin_user_role, normalize_admin_user_string_list, normalize_admin_username,
|
||||
validate_admin_user_password, AdminCreateUserRequest,
|
||||
};
|
||||
use super::support::{admin_user_password_policy, build_admin_user_payload};
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::handlers::admin::shared::attach_admin_audit_response;
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(in super::super) async fn build_admin_create_user_response(
|
||||
state: &AdminAppState<'_>,
|
||||
_request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
if !state.has_auth_user_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法创建用户",
|
||||
));
|
||||
}
|
||||
if !state.has_auth_wallet_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法初始化用户钱包",
|
||||
));
|
||||
}
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let payload = match serde_json::from_slice::<AdminCreateUserRequest>(request_body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
|
||||
let email = match normalize_admin_optional_user_email(payload.email.as_deref()) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let username = match normalize_admin_username(&payload.username) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let role = match normalize_admin_user_role(payload.role.as_deref()) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let password_policy = admin_user_password_policy(state).await?;
|
||||
if let Err(detail) = validate_admin_user_password(&payload.password, &password_policy) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if payload.rate_limit.is_some_and(|value| value < 0) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if payload
|
||||
.initial_gift_usd
|
||||
.is_some_and(|value| !value.is_finite() || !(0.0..=10000.0).contains(&value))
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "初始赠款必须在 0-10000 范围内" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
let allowed_providers =
|
||||
match normalize_admin_user_string_list(payload.allowed_providers, "allowed_providers") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let allowed_api_formats = match normalize_admin_user_api_formats(payload.allowed_api_formats) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let allowed_models =
|
||||
match normalize_admin_user_string_list(payload.allowed_models, "allowed_models") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
|
||||
if let Some(email) = email.as_deref() {
|
||||
if state.find_user_auth_by_identifier(email).await?.is_some() {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("邮箱已存在: {email}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
if state
|
||||
.find_user_auth_by_identifier(&username)
|
||||
.await?
|
||||
.is_some()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("用户名已存在: {username}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
let password_hash = match bcrypt::hash(&payload.password, bcrypt::DEFAULT_COST) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "密码长度不能超过72字节" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let initial_gift_usd = if payload.unlimited {
|
||||
0.0
|
||||
} else if let Some(value) = payload.initial_gift_usd {
|
||||
value
|
||||
} else {
|
||||
admin_default_user_initial_gift(
|
||||
state
|
||||
.read_system_config_json_value("default_user_initial_gift_usd")
|
||||
.await?
|
||||
.as_ref(),
|
||||
)
|
||||
};
|
||||
|
||||
let Some(user) = state
|
||||
.create_local_auth_user_with_settings(
|
||||
email,
|
||||
false,
|
||||
username,
|
||||
password_hash,
|
||||
role,
|
||||
allowed_providers,
|
||||
allowed_api_formats,
|
||||
allowed_models,
|
||||
payload.rate_limit,
|
||||
)
|
||||
.await?
|
||||
else {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法创建用户",
|
||||
));
|
||||
};
|
||||
|
||||
if state
|
||||
.initialize_auth_user_wallet(&user.id, initial_gift_usd, payload.unlimited)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法初始化用户钱包",
|
||||
));
|
||||
}
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(build_admin_user_payload(
|
||||
&user,
|
||||
payload.rate_limit,
|
||||
payload.unlimited,
|
||||
))
|
||||
.into_response(),
|
||||
"admin_user_created",
|
||||
"create_user",
|
||||
"user",
|
||||
&user.id,
|
||||
))
|
||||
}
|
||||
@@ -0,0 +1,66 @@
|
||||
use super::super::build_admin_users_bad_request_response;
|
||||
use super::support::admin_user_id_from_detail_path;
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::handlers::admin::shared::attach_admin_audit_response;
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(in super::super) async fn build_admin_delete_user_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_detail_path(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
if user.role.eq_ignore_ascii_case("admin") && state.count_active_admin_users().await? <= 1 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "不能删除最后一个管理员账户" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if state.count_user_pending_refunds(&user_id).await? > 0 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "用户存在未完结退款,禁止删除" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
if state.count_user_pending_payment_orders(&user_id).await? > 0 {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "用户存在未完结充值订单,禁止删除" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
if !state.delete_local_auth_user(&user_id).await? {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(json!({ "message": "用户删除成功" })).into_response(),
|
||||
"admin_user_deleted",
|
||||
"delete_user",
|
||||
"user",
|
||||
&user_id,
|
||||
))
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
mod create;
|
||||
mod delete;
|
||||
mod reads;
|
||||
mod support;
|
||||
mod update;
|
||||
|
||||
pub(super) use create::build_admin_create_user_response;
|
||||
pub(super) use delete::build_admin_delete_user_response;
|
||||
pub(super) use reads::{build_admin_get_user_response, build_admin_list_users_response};
|
||||
pub(super) use update::build_admin_update_user_response;
|
||||
@@ -0,0 +1,116 @@
|
||||
use super::super::{build_admin_users_bad_request_response, format_optional_datetime_iso8601};
|
||||
use super::support::{
|
||||
admin_user_id_from_detail_path, build_admin_user_payload, find_admin_export_user,
|
||||
};
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::handlers::admin::shared::{query_param_optional_bool, query_param_value};
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
pub(in super::super) async fn build_admin_list_users_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let skip = query_param_value(request_context.query_string(), "skip")
|
||||
.and_then(|value| value.parse::<usize>().ok())
|
||||
.unwrap_or(0);
|
||||
let limit = query_param_value(request_context.query_string(), "limit")
|
||||
.and_then(|value| value.parse::<usize>().ok())
|
||||
.unwrap_or(100)
|
||||
.clamp(1, 1000);
|
||||
let role = query_param_value(request_context.query_string(), "role")
|
||||
.map(|value| value.trim().to_ascii_lowercase())
|
||||
.filter(|value| !value.is_empty());
|
||||
let is_active = query_param_optional_bool(request_context.query_string(), "is_active");
|
||||
|
||||
let paged_rows = state
|
||||
.list_export_users_page(&aether_data::repository::users::UserExportListQuery {
|
||||
skip,
|
||||
limit,
|
||||
role: role.clone(),
|
||||
is_active,
|
||||
})
|
||||
.await?;
|
||||
let user_ids = paged_rows
|
||||
.iter()
|
||||
.map(|row| row.id.clone())
|
||||
.collect::<Vec<_>>();
|
||||
let auth_by_user_id = state
|
||||
.list_user_auth_by_ids(&user_ids)
|
||||
.await?
|
||||
.into_iter()
|
||||
.map(|user| (user.id.clone(), user))
|
||||
.collect::<BTreeMap<_, _>>();
|
||||
let wallet_by_user_id = state
|
||||
.list_wallet_snapshots_by_user_ids(&user_ids)
|
||||
.await?
|
||||
.into_iter()
|
||||
.filter_map(|wallet| wallet.user_id.clone().map(|user_id| (user_id, wallet)))
|
||||
.collect::<BTreeMap<_, _>>();
|
||||
|
||||
let mut payload = Vec::with_capacity(paged_rows.len());
|
||||
for row in paged_rows {
|
||||
let auth = auth_by_user_id.get(&row.id);
|
||||
let unlimited = wallet_by_user_id
|
||||
.get(&row.id)
|
||||
.is_some_and(|wallet| wallet.limit_mode.eq_ignore_ascii_case("unlimited"));
|
||||
payload.push(json!({
|
||||
"id": row.id,
|
||||
"email": row.email,
|
||||
"username": row.username,
|
||||
"role": row.role,
|
||||
"allowed_providers": row.allowed_providers,
|
||||
"allowed_api_formats": row.allowed_api_formats,
|
||||
"allowed_models": row.allowed_models,
|
||||
"rate_limit": row.rate_limit,
|
||||
"unlimited": unlimited,
|
||||
"is_active": row.is_active,
|
||||
"created_at": format_optional_datetime_iso8601(auth.as_ref().and_then(|user| user.created_at)),
|
||||
"updated_at": serde_json::Value::Null,
|
||||
"last_login_at": format_optional_datetime_iso8601(
|
||||
auth.as_ref().and_then(|user| user.last_login_at),
|
||||
),
|
||||
}));
|
||||
}
|
||||
|
||||
Ok(Json(payload).into_response())
|
||||
}
|
||||
|
||||
pub(in super::super) async fn build_admin_get_user_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_detail_path(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
|
||||
let wallet = state
|
||||
.find_wallet(aether_data::repository::wallet::WalletLookupKey::UserId(
|
||||
&user_id,
|
||||
))
|
||||
.await?;
|
||||
let export_row = find_admin_export_user(state, &user_id).await?;
|
||||
let unlimited = wallet
|
||||
.as_ref()
|
||||
.is_some_and(|wallet| wallet.limit_mode.eq_ignore_ascii_case("unlimited"));
|
||||
Ok(Json(build_admin_user_payload(
|
||||
&user,
|
||||
export_row.as_ref().and_then(|row| row.rate_limit),
|
||||
unlimited,
|
||||
))
|
||||
.into_response())
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
use super::super::format_optional_datetime_iso8601;
|
||||
use crate::handlers::admin::request::AdminAppState;
|
||||
use crate::GatewayError;
|
||||
use serde_json::json;
|
||||
|
||||
pub(super) async fn admin_user_password_policy(
|
||||
state: &AdminAppState<'_>,
|
||||
) -> Result<String, GatewayError> {
|
||||
let config = state
|
||||
.read_system_config_json_value("password_policy_level")
|
||||
.await?;
|
||||
Ok(
|
||||
match config
|
||||
.as_ref()
|
||||
.and_then(|value| value.as_str())
|
||||
.unwrap_or("weak")
|
||||
.trim()
|
||||
.to_ascii_lowercase()
|
||||
.as_str()
|
||||
{
|
||||
"medium" => "medium".to_string(),
|
||||
"strong" => "strong".to_string(),
|
||||
_ => "weak".to_string(),
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
pub(super) async fn find_admin_export_user(
|
||||
state: &AdminAppState<'_>,
|
||||
user_id: &str,
|
||||
) -> Result<Option<aether_data::repository::users::StoredUserExportRow>, GatewayError> {
|
||||
state.find_export_user_by_id(user_id).await
|
||||
}
|
||||
|
||||
pub(super) fn build_admin_user_payload(
|
||||
user: &aether_data::repository::users::StoredUserAuthRecord,
|
||||
rate_limit: Option<i32>,
|
||||
unlimited: bool,
|
||||
) -> serde_json::Value {
|
||||
json!({
|
||||
"id": user.id,
|
||||
"email": user.email,
|
||||
"username": user.username,
|
||||
"role": user.role,
|
||||
"allowed_providers": user.allowed_providers,
|
||||
"allowed_api_formats": user.allowed_api_formats,
|
||||
"allowed_models": user.allowed_models,
|
||||
"rate_limit": rate_limit,
|
||||
"unlimited": unlimited,
|
||||
"is_active": user.is_active,
|
||||
"created_at": format_optional_datetime_iso8601(user.created_at),
|
||||
"updated_at": serde_json::Value::Null,
|
||||
"last_login_at": format_optional_datetime_iso8601(user.last_login_at),
|
||||
})
|
||||
}
|
||||
|
||||
pub(super) fn admin_user_id_from_detail_path(request_path: &str) -> Option<String> {
|
||||
let value = request_path
|
||||
.strip_prefix("/api/admin/users/")?
|
||||
.trim()
|
||||
.trim_matches('/')
|
||||
.to_string();
|
||||
if value.is_empty() || value.contains('/') {
|
||||
None
|
||||
} else {
|
||||
Some(value)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,343 @@
|
||||
use super::super::{
|
||||
build_admin_users_bad_request_response, build_admin_users_data_unavailable_response,
|
||||
build_admin_users_read_only_response, normalize_admin_optional_user_email,
|
||||
normalize_admin_user_api_formats, normalize_admin_user_role, normalize_admin_user_string_list,
|
||||
normalize_admin_username, validate_admin_user_password, AdminUpdateUserFieldPresence,
|
||||
AdminUpdateUserRequest,
|
||||
};
|
||||
use super::support::{
|
||||
admin_user_id_from_detail_path, admin_user_password_policy, build_admin_user_payload,
|
||||
find_admin_export_user,
|
||||
};
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::handlers::admin::shared::attach_admin_audit_response;
|
||||
use crate::GatewayError;
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
pub(in super::super) async fn build_admin_update_user_response(
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_detail_path(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
let Some(_existing_user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let Some(request_body) = request_body else {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let raw_payload = match serde_json::from_slice::<serde_json::Value>(request_body) {
|
||||
Ok(serde_json::Value::Object(map)) => map,
|
||||
_ => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
let field_presence = AdminUpdateUserFieldPresence {
|
||||
allowed_providers: raw_payload.contains_key("allowed_providers"),
|
||||
allowed_api_formats: raw_payload.contains_key("allowed_api_formats"),
|
||||
allowed_models: raw_payload.contains_key("allowed_models"),
|
||||
};
|
||||
let payload = match serde_json::from_value::<AdminUpdateUserRequest>(serde_json::Value::Object(
|
||||
raw_payload.clone(),
|
||||
)) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "请求数据验证失败" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
|
||||
let email = match payload.email.as_deref() {
|
||||
Some(value) => match normalize_admin_optional_user_email(Some(value)) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
},
|
||||
None => None,
|
||||
};
|
||||
if let Some(email) = email.as_deref() {
|
||||
if state
|
||||
.is_other_user_auth_email_taken(email, &user_id)
|
||||
.await?
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("邮箱已存在: {email}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
let username = match payload.username.as_deref() {
|
||||
Some(value) => match normalize_admin_username(value) {
|
||||
Ok(value) => Some(value),
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
},
|
||||
None => None,
|
||||
};
|
||||
if let Some(username) = username.as_deref() {
|
||||
if state
|
||||
.is_other_user_auth_username_taken(username, &user_id)
|
||||
.await?
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": format!("用户名已存在: {username}") })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
let role = match payload.role.as_deref() {
|
||||
Some(value) => match normalize_admin_user_role(Some(value)) {
|
||||
Ok(value) => Some(value),
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
},
|
||||
None => None,
|
||||
};
|
||||
if payload.rate_limit.is_some_and(|value| value < 0) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "rate_limit 必须大于等于 0" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
let allowed_providers = if field_presence.allowed_providers {
|
||||
match normalize_admin_user_string_list(payload.allowed_providers, "allowed_providers") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
}
|
||||
} else {
|
||||
None
|
||||
};
|
||||
let allowed_api_formats = if field_presence.allowed_api_formats {
|
||||
match normalize_admin_user_api_formats(payload.allowed_api_formats) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
}
|
||||
} else {
|
||||
None
|
||||
};
|
||||
let allowed_models = if field_presence.allowed_models {
|
||||
match normalize_admin_user_string_list(payload.allowed_models, "allowed_models") {
|
||||
Ok(value) => value,
|
||||
Err(detail) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
}
|
||||
} else {
|
||||
None
|
||||
};
|
||||
let needs_auth_user_write = email.is_some()
|
||||
|| username.is_some()
|
||||
|| payload.password.is_some()
|
||||
|| role.is_some()
|
||||
|| field_presence.allowed_providers
|
||||
|| field_presence.allowed_api_formats
|
||||
|| field_presence.allowed_models
|
||||
|| payload.rate_limit.is_some()
|
||||
|| payload.is_active.is_some();
|
||||
if needs_auth_user_write && !state.has_auth_user_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法更新用户",
|
||||
));
|
||||
}
|
||||
if payload.unlimited.is_some() && !state.has_auth_wallet_write_capability() {
|
||||
return Ok(build_admin_users_read_only_response(
|
||||
"当前为只读模式,无法更新用户钱包",
|
||||
));
|
||||
}
|
||||
|
||||
if email.is_some() || username.is_some() {
|
||||
if state
|
||||
.update_local_auth_user_profile(&user_id, email.clone(), username.clone())
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
if let Some(password) = payload.password.as_deref() {
|
||||
let password_policy = admin_user_password_policy(state).await?;
|
||||
if let Err(detail) = validate_admin_user_password(password, &password_policy) {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": detail })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
let password_hash = match bcrypt::hash(password, bcrypt::DEFAULT_COST) {
|
||||
Ok(value) => value,
|
||||
Err(_) => {
|
||||
return Ok((
|
||||
http::StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "detail": "密码长度不能超过72字节" })),
|
||||
)
|
||||
.into_response())
|
||||
}
|
||||
};
|
||||
if state
|
||||
.update_local_auth_user_password_hash(&user_id, password_hash, chrono::Utc::now())
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
if role.is_some()
|
||||
|| field_presence.allowed_providers
|
||||
|| field_presence.allowed_api_formats
|
||||
|| field_presence.allowed_models
|
||||
|| payload.rate_limit.is_some()
|
||||
|| payload.is_active.is_some()
|
||||
{
|
||||
if state
|
||||
.update_local_auth_user_admin_fields(
|
||||
&user_id,
|
||||
role,
|
||||
field_presence.allowed_providers,
|
||||
allowed_providers,
|
||||
field_presence.allowed_api_formats,
|
||||
allowed_api_formats,
|
||||
field_presence.allowed_models,
|
||||
allowed_models,
|
||||
payload.rate_limit,
|
||||
payload.is_active,
|
||||
)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
}
|
||||
}
|
||||
|
||||
if let Some(unlimited) = payload.unlimited {
|
||||
match state
|
||||
.find_wallet(aether_data::repository::wallet::WalletLookupKey::UserId(
|
||||
&user_id,
|
||||
))
|
||||
.await?
|
||||
{
|
||||
Some(wallet) => {
|
||||
let desired_limit_mode = if unlimited { "unlimited" } else { "finite" };
|
||||
if !wallet.limit_mode.eq_ignore_ascii_case(desired_limit_mode) {
|
||||
if state
|
||||
.update_auth_user_wallet_limit_mode(&user_id, desired_limit_mode)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok(build_admin_users_data_unavailable_response());
|
||||
}
|
||||
}
|
||||
}
|
||||
None => {
|
||||
if state
|
||||
.initialize_auth_user_wallet(&user_id, 0.0, unlimited)
|
||||
.await?
|
||||
.is_none()
|
||||
{
|
||||
return Ok(build_admin_users_data_unavailable_response());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let Some(user) = state.find_user_auth_by_id(&user_id).await? else {
|
||||
return Ok((
|
||||
http::StatusCode::NOT_FOUND,
|
||||
Json(json!({ "detail": "用户不存在" })),
|
||||
)
|
||||
.into_response());
|
||||
};
|
||||
let wallet = state
|
||||
.find_wallet(aether_data::repository::wallet::WalletLookupKey::UserId(
|
||||
&user_id,
|
||||
))
|
||||
.await?;
|
||||
let unlimited = wallet
|
||||
.as_ref()
|
||||
.is_some_and(|wallet| wallet.limit_mode.eq_ignore_ascii_case("unlimited"));
|
||||
let export_row = find_admin_export_user(state, &user_id).await?;
|
||||
let rate_limit = export_row
|
||||
.as_ref()
|
||||
.and_then(|row| row.rate_limit)
|
||||
.or(payload.rate_limit);
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(build_admin_user_payload(&user, rate_limit, unlimited)).into_response(),
|
||||
"admin_user_updated",
|
||||
"update_user",
|
||||
"user",
|
||||
&user_id,
|
||||
))
|
||||
}
|
||||
@@ -1,11 +1,10 @@
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::{AppState, GatewayError};
|
||||
use axum::{body::Body, response::Response};
|
||||
use crate::handlers::admin::request::{AdminRouteRequest, AdminRouteResult};
|
||||
|
||||
const ADMIN_USERS_DATA_UNAVAILABLE_DETAIL: &str = "Admin user management data unavailable";
|
||||
|
||||
mod api_keys;
|
||||
mod lifecycle;
|
||||
mod route_seam;
|
||||
mod routes;
|
||||
mod sessions;
|
||||
mod shared;
|
||||
@@ -40,10 +39,7 @@ use self::shared::{
|
||||
pub(crate) use self::shared::{normalize_admin_user_api_formats, normalize_admin_user_string_list};
|
||||
|
||||
pub(crate) async fn maybe_build_local_admin_users_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
routes::maybe_build_local_admin_users_routes_response(state, request_context, request_body)
|
||||
.await
|
||||
request: AdminRouteRequest<'_>,
|
||||
) -> AdminRouteResult {
|
||||
route_seam::maybe_build_local_admin_users_response(request).await
|
||||
}
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
use super::routes;
|
||||
use crate::handlers::admin::request::{AdminRouteRequest, AdminRouteResult};
|
||||
|
||||
pub(crate) async fn maybe_build_local_admin_users_response(
|
||||
request: AdminRouteRequest<'_>,
|
||||
) -> AdminRouteResult {
|
||||
routes::maybe_build_local_admin_users_routes_response(
|
||||
&request.state(),
|
||||
&request.request_context(),
|
||||
request.request_body(),
|
||||
)
|
||||
.await
|
||||
}
|
||||
@@ -8,65 +8,65 @@ use super::{
|
||||
build_admin_update_user_api_key_response, build_admin_update_user_response,
|
||||
build_admin_users_data_unavailable_response,
|
||||
};
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::{AppState, GatewayError};
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::GatewayError;
|
||||
use axum::{body::Body, http, response::Response};
|
||||
|
||||
fn is_admin_users_route(request_context: &GatewayPublicRequestContext) -> bool {
|
||||
let path = request_context.request_path.as_str();
|
||||
(request_context.request_method == http::Method::GET
|
||||
fn is_admin_users_route(request_context: &AdminRequestContext<'_>) -> bool {
|
||||
let path = request_context.path();
|
||||
(request_context.method() == http::Method::GET
|
||||
&& matches!(path, "/api/admin/users" | "/api/admin/users/"))
|
||||
|| (request_context.request_method == http::Method::POST
|
||||
|| (request_context.method() == http::Method::POST
|
||||
&& matches!(path, "/api/admin/users" | "/api/admin/users/"))
|
||||
|| ((request_context.request_method == http::Method::GET
|
||||
|| request_context.request_method == http::Method::PUT
|
||||
|| request_context.request_method == http::Method::DELETE)
|
||||
|| ((request_context.method() == http::Method::GET
|
||||
|| request_context.method() == http::Method::PUT
|
||||
|| request_context.method() == http::Method::DELETE)
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& !path.ends_with("/sessions")
|
||||
&& !path.contains("/sessions/")
|
||||
&& !path.ends_with("/api-keys")
|
||||
&& !path.contains("/api-keys/")
|
||||
&& path.matches('/').count() == 4)
|
||||
|| (request_context.request_method == http::Method::GET
|
||||
|| (request_context.method() == http::Method::GET
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& path.ends_with("/sessions")
|
||||
&& path.matches('/').count() == 5)
|
||||
|| (request_context.request_method == http::Method::DELETE
|
||||
|| (request_context.method() == http::Method::DELETE
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& path.ends_with("/sessions")
|
||||
&& path.matches('/').count() == 5)
|
||||
|| (request_context.request_method == http::Method::DELETE
|
||||
|| (request_context.method() == http::Method::DELETE
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& path.contains("/sessions/")
|
||||
&& path.matches('/').count() == 6)
|
||||
|| ((request_context.request_method == http::Method::GET
|
||||
|| request_context.request_method == http::Method::POST)
|
||||
|| ((request_context.method() == http::Method::GET
|
||||
|| request_context.method() == http::Method::POST)
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& path.ends_with("/api-keys")
|
||||
&& path.matches('/').count() == 5)
|
||||
|| ((request_context.request_method == http::Method::DELETE
|
||||
|| request_context.request_method == http::Method::PUT)
|
||||
|| ((request_context.method() == http::Method::DELETE
|
||||
|| request_context.method() == http::Method::PUT)
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& path.contains("/api-keys/")
|
||||
&& !path.ends_with("/lock")
|
||||
&& !path.ends_with("/full-key")
|
||||
&& path.matches('/').count() == 6)
|
||||
|| (request_context.request_method == http::Method::PATCH
|
||||
|| (request_context.method() == http::Method::PATCH
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& path.ends_with("/lock")
|
||||
&& path.matches('/').count() == 7)
|
||||
|| (request_context.request_method == http::Method::GET
|
||||
|| (request_context.method() == http::Method::GET
|
||||
&& path.starts_with("/api/admin/users/")
|
||||
&& path.ends_with("/full-key")
|
||||
&& path.matches('/').count() == 7)
|
||||
}
|
||||
|
||||
pub(super) async fn maybe_build_local_admin_users_routes_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
request_body: Option<&axum::body::Bytes>,
|
||||
) -> Result<Option<Response<Body>>, GatewayError> {
|
||||
let Some(decision) = request_context.control_decision.as_ref() else {
|
||||
let Some(decision) = request_context.decision() else {
|
||||
return Ok(None);
|
||||
};
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
use super::{build_admin_users_bad_request_response, format_optional_datetime_iso8601};
|
||||
use crate::control::GatewayPublicRequestContext;
|
||||
use crate::handlers::admin::request::{AdminAppState, AdminRequestContext};
|
||||
use crate::handlers::admin::shared::attach_admin_audit_response;
|
||||
use crate::{AppState, GatewayError, GatewayUserSessionView};
|
||||
use crate::{GatewayError, GatewayUserSessionView};
|
||||
use axum::{
|
||||
body::Body,
|
||||
http,
|
||||
@@ -44,10 +44,10 @@ fn format_required_session_datetime_iso8601(session: &GatewayUserSessionView) ->
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_list_user_sessions_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_sessions_path(&request_context.request_path) else {
|
||||
let Some(user_id) = admin_user_id_from_sessions_path(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
|
||||
@@ -89,11 +89,10 @@ pub(super) async fn build_admin_list_user_sessions_response(
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_delete_user_session_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some((user_id, session_id)) = admin_user_session_parts(&request_context.request_path)
|
||||
else {
|
||||
let Some((user_id, session_id)) = admin_user_session_parts(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response(
|
||||
"缺少 user_id 或 session_id",
|
||||
));
|
||||
@@ -138,10 +137,10 @@ pub(super) async fn build_admin_delete_user_session_response(
|
||||
}
|
||||
|
||||
pub(super) async fn build_admin_delete_user_sessions_response(
|
||||
state: &AppState,
|
||||
request_context: &GatewayPublicRequestContext,
|
||||
state: &AdminAppState<'_>,
|
||||
request_context: &AdminRequestContext<'_>,
|
||||
) -> Result<Response<Body>, GatewayError> {
|
||||
let Some(user_id) = admin_user_id_from_sessions_path(&request_context.request_path) else {
|
||||
let Some(user_id) = admin_user_id_from_sessions_path(request_context.path()) else {
|
||||
return Ok(build_admin_users_bad_request_response("缺少 user_id"));
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user