mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-10 19:29:50 +08:00
Redesign sensitive info protection settings
This commit is contained in:
@@ -9,8 +9,8 @@ use crate::handlers::admin::shared::attach_admin_audit_response;
|
||||
use crate::handlers::admin::users::{
|
||||
default_admin_user_api_key_name, format_optional_unix_secs_iso8601,
|
||||
generate_admin_user_api_key_plaintext, hash_admin_user_api_key, masked_user_api_key_display,
|
||||
normalize_admin_optional_api_key_name, normalize_admin_user_api_formats,
|
||||
normalize_admin_user_string_list,
|
||||
normalize_admin_feature_settings, normalize_admin_optional_api_key_name,
|
||||
normalize_admin_user_api_formats, normalize_admin_user_string_list,
|
||||
};
|
||||
use crate::handlers::shared::normalize_optional_api_key_concurrent_limit;
|
||||
use crate::GatewayError;
|
||||
@@ -137,6 +137,10 @@ pub(super) async fn build_admin_create_api_key_response(
|
||||
"设置 auto_delete_on_expiry 前必须提供 expires_at",
|
||||
));
|
||||
}
|
||||
let feature_settings = match normalize_admin_feature_settings(payload.feature_settings) {
|
||||
Ok(value) => value,
|
||||
Err(detail) => return Ok(build_admin_api_keys_bad_request_response(detail)),
|
||||
};
|
||||
|
||||
let plaintext_key = generate_admin_user_api_key_plaintext();
|
||||
let Some(key_encrypted) = state.encrypt_catalog_secret_with_fallbacks(&plaintext_key) else {
|
||||
@@ -180,6 +184,14 @@ pub(super) async fn build_admin_create_api_key_response(
|
||||
Some(wallet) => wallet,
|
||||
None => return Ok(build_admin_api_keys_data_unavailable_response()),
|
||||
};
|
||||
let created = if feature_settings.is_some() {
|
||||
state
|
||||
.set_standalone_api_key_feature_settings(&created.api_key_id, feature_settings.clone())
|
||||
.await?
|
||||
.unwrap_or(created)
|
||||
} else {
|
||||
created
|
||||
};
|
||||
|
||||
Ok(attach_admin_audit_response(
|
||||
Json(json!({
|
||||
@@ -196,6 +208,7 @@ pub(super) async fn build_admin_create_api_key_response(
|
||||
"allowed_models": created.allowed_models,
|
||||
"expires_at": format_optional_unix_secs_iso8601(created.expires_at_unix_secs),
|
||||
"auto_delete_on_expiry": created.auto_delete_on_expiry,
|
||||
"feature_settings": created.feature_settings,
|
||||
"wallet": serialize_admin_system_users_export_wallet(Some(&wallet)),
|
||||
"message": "独立余额Key创建成功,请妥善保存完整密钥,后续将无法查看",
|
||||
}))
|
||||
@@ -245,6 +258,14 @@ pub(super) async fn build_admin_update_api_key_response(
|
||||
let null_auto_delete_on_expiry =
|
||||
patch.contains("auto_delete_on_expiry") && patch.is_null("auto_delete_on_expiry");
|
||||
let (field_presence, payload) = patch.into_parts();
|
||||
let feature_settings = if field_presence.contains("feature_settings") {
|
||||
match normalize_admin_feature_settings(payload.feature_settings.flatten()) {
|
||||
Ok(value) => Some(value),
|
||||
Err(detail) => return Ok(build_admin_api_keys_bad_request_response(detail)),
|
||||
}
|
||||
} else {
|
||||
None
|
||||
};
|
||||
if null_unlimited_balance {
|
||||
return Ok(build_admin_api_keys_bad_request_response(
|
||||
"unlimited_balance 必须是布尔值",
|
||||
@@ -387,6 +408,14 @@ pub(super) async fn build_admin_update_api_key_response(
|
||||
else {
|
||||
return Ok(build_admin_api_keys_data_unavailable_response());
|
||||
};
|
||||
let updated = if let Some(feature_settings) = feature_settings {
|
||||
state
|
||||
.set_standalone_api_key_feature_settings(&api_key_id, feature_settings)
|
||||
.await?
|
||||
.unwrap_or(updated)
|
||||
} else {
|
||||
updated
|
||||
};
|
||||
|
||||
if wallet.is_none() {
|
||||
wallet = state
|
||||
|
||||
@@ -10,7 +10,7 @@ use axum::{
|
||||
response::{IntoResponse, Response},
|
||||
Json,
|
||||
};
|
||||
use serde_json::json;
|
||||
use serde_json::{json, Value};
|
||||
|
||||
const ADMIN_API_KEYS_DATA_UNAVAILABLE_DETAIL: &str = "Admin standalone API key data unavailable";
|
||||
|
||||
@@ -27,6 +27,7 @@ pub(super) struct AdminStandaloneApiKeyCreateRequest {
|
||||
pub(super) expire_days: Option<i32>,
|
||||
pub(super) expires_at: Option<String>,
|
||||
pub(super) auto_delete_on_expiry: Option<bool>,
|
||||
pub(super) feature_settings: Option<Value>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Default, serde::Deserialize)]
|
||||
@@ -42,6 +43,7 @@ pub(super) struct AdminStandaloneApiKeyUpdateRequest {
|
||||
pub(super) expire_days: Option<i32>,
|
||||
pub(super) expires_at: Option<String>,
|
||||
pub(super) auto_delete_on_expiry: Option<bool>,
|
||||
pub(super) feature_settings: Option<Option<Value>>,
|
||||
}
|
||||
|
||||
pub(super) type AdminStandaloneApiKeyUpdatePatch =
|
||||
@@ -164,6 +166,7 @@ pub(super) fn build_admin_api_key_list_item_payload(
|
||||
"created_at": format_optional_unix_secs_iso8601(record.created_at_unix_secs),
|
||||
"updated_at": format_optional_unix_secs_iso8601(record.updated_at_unix_secs),
|
||||
"auto_delete_on_expiry": record.auto_delete_on_expiry,
|
||||
"feature_settings": record.feature_settings,
|
||||
"wallet": serialize_admin_system_users_export_wallet(wallet),
|
||||
})
|
||||
}
|
||||
@@ -193,6 +196,7 @@ pub(super) fn build_admin_api_key_detail_payload(
|
||||
"created_at": format_optional_unix_secs_iso8601(record.created_at_unix_secs),
|
||||
"updated_at": format_optional_unix_secs_iso8601(record.updated_at_unix_secs),
|
||||
"auto_delete_on_expiry": record.auto_delete_on_expiry,
|
||||
"feature_settings": record.feature_settings,
|
||||
"wallet": serialize_admin_system_users_export_wallet(wallet),
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user