mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-07 18:07:47 +08:00
feat(gateway): harden provider request execution
Preserve exact request payloads and model client surface and API operation explicitly. Add Anthropic compatibility profiles, bounded stream commitment, and scoped OAuth retry behavior across provider transports.
This commit is contained in:
@@ -71,6 +71,20 @@ pub(super) fn extract_request_credentials(
|
||||
}
|
||||
}
|
||||
|
||||
pub(in crate::control) fn resolve_gateway_credential_carrier(
|
||||
headers: &http::HeaderMap,
|
||||
uri: &Uri,
|
||||
auth_endpoint_signature: &str,
|
||||
) -> Option<GatewayCredentialCarrier> {
|
||||
extract_request_credentials(headers, uri, auth_endpoint_signature)
|
||||
.primary
|
||||
.map(|credential| match credential {
|
||||
GatewayPrimaryCredential::ProviderApiKey { carrier, .. }
|
||||
| GatewayPrimaryCredential::BearerToken { carrier, .. }
|
||||
| GatewayPrimaryCredential::CookieHeader { carrier, .. } => carrier,
|
||||
})
|
||||
}
|
||||
|
||||
fn has_trusted_gateway_marker(headers: &http::HeaderMap) -> bool {
|
||||
header_value_str(headers, crate::constants::GATEWAY_HEADER)
|
||||
.unwrap_or_default()
|
||||
|
||||
@@ -5,6 +5,7 @@ mod resolution;
|
||||
mod types;
|
||||
|
||||
pub(crate) use credentials::extract_requested_model;
|
||||
pub(super) use credentials::resolve_gateway_credential_carrier;
|
||||
pub(crate) use gate::{
|
||||
execution_plan_balance_capacity_rejection, request_model_local_rejection,
|
||||
should_buffer_request_for_local_auth, trusted_auth_local_rejection, GatewayLocalAuthRejection,
|
||||
@@ -14,3 +15,4 @@ pub(crate) use resolution::{
|
||||
GatewayAdminPrincipalContext, GatewayControlAuthContext,
|
||||
};
|
||||
pub(super) use resolution::{resolve_control_decision_auth, ControlDecisionAuthResolution};
|
||||
pub(crate) use types::GatewayCredentialCarrier;
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub(super) enum GatewayCredentialCarrier {
|
||||
pub(crate) enum GatewayCredentialCarrier {
|
||||
AuthorizationBearer,
|
||||
XApiKey,
|
||||
ApiKey,
|
||||
@@ -8,6 +8,26 @@ pub(super) enum GatewayCredentialCarrier {
|
||||
CookieHeader,
|
||||
}
|
||||
|
||||
impl GatewayCredentialCarrier {
|
||||
pub(crate) const fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
Self::AuthorizationBearer => "authorization_bearer",
|
||||
Self::XApiKey => "x_api_key",
|
||||
Self::ApiKey => "api_key",
|
||||
Self::XGoogApiKey => "x_goog_api_key",
|
||||
Self::QueryKey => "query_key",
|
||||
Self::CookieHeader => "cookie_header",
|
||||
}
|
||||
}
|
||||
|
||||
pub(crate) const fn request_auth_channel(self) -> &'static str {
|
||||
match self {
|
||||
Self::AuthorizationBearer | Self::CookieHeader => "bearer_like",
|
||||
Self::XApiKey | Self::ApiKey | Self::XGoogApiKey | Self::QueryKey => "api_key",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, PartialEq)]
|
||||
pub(super) struct GatewayTrustedAuthHeaders {
|
||||
pub(super) user_id: String,
|
||||
|
||||
Reference in New Issue
Block a user