mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-08 02:17:46 +08:00
feat(gateway): harden provider request execution
Preserve exact request payloads and model client surface and API operation explicitly. Add Anthropic compatibility profiles, bounded stream commitment, and scoped OAuth retry behavior across provider transports.
This commit is contained in:
@@ -460,22 +460,16 @@ fn key_auth_channel_matches(row: &CandidateSelectionRow, api_format: &str) -> bo
|
||||
matches!(auth_type.as_str(), "oauth" | "api_key" | "bearer")
|
||||
&& api_format == "openai:chat"
|
||||
}
|
||||
"vertex_ai" => {
|
||||
(auth_type == "api_key"
|
||||
&& matches!(
|
||||
api_format.as_str(),
|
||||
"gemini:generate_content" | "gemini:embedding"
|
||||
))
|
||||
|| (matches!(auth_type.as_str(), "service_account" | "vertex_ai")
|
||||
&& matches!(
|
||||
api_format.as_str(),
|
||||
"claude:messages" | "gemini:generate_content" | "gemini:embedding"
|
||||
))
|
||||
}
|
||||
"vertex_ai" => vertex_key_auth_channel_matches(&auth_type, &api_format),
|
||||
_ => auth_type != "oauth",
|
||||
}
|
||||
}
|
||||
|
||||
fn vertex_key_auth_channel_matches(auth_type: &str, api_format: &str) -> bool {
|
||||
matches!(auth_type, "api_key" | "service_account" | "vertex_ai")
|
||||
&& matches!(api_format, "gemini:generate_content" | "gemini:embedding")
|
||||
}
|
||||
|
||||
fn dedupe_candidate_selection_rows(
|
||||
rows: Vec<StoredMinimalCandidateSelectionRow>,
|
||||
) -> Vec<StoredMinimalCandidateSelectionRow> {
|
||||
@@ -797,7 +791,7 @@ fn sql_match_aliases(api_formats: &[String]) -> Vec<String> {
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::MysqlMinimalCandidateSelectionReadRepository;
|
||||
use super::{vertex_key_auth_channel_matches, MysqlMinimalCandidateSelectionReadRepository};
|
||||
|
||||
#[tokio::test]
|
||||
async fn repository_builds_from_lazy_pool() {
|
||||
@@ -809,4 +803,22 @@ mod tests {
|
||||
|
||||
let _repository = MysqlMinimalCandidateSelectionReadRepository::new(pool);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn vertex_auth_matrix_rejects_retired_claude_format() {
|
||||
for auth_type in ["api_key", "service_account", "vertex_ai"] {
|
||||
assert!(!vertex_key_auth_channel_matches(
|
||||
auth_type,
|
||||
"claude:messages"
|
||||
));
|
||||
assert!(vertex_key_auth_channel_matches(
|
||||
auth_type,
|
||||
"gemini:generate_content"
|
||||
));
|
||||
assert!(vertex_key_auth_channel_matches(
|
||||
auth_type,
|
||||
"gemini:embedding"
|
||||
));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1281,6 +1281,19 @@ WHERE id = ?
|
||||
"provider catalog OAuth api_key update must not be empty".to_string(),
|
||||
));
|
||||
}
|
||||
if update.expected_credential.as_ref().is_some_and(|expected| {
|
||||
expected
|
||||
.encrypted_api_key
|
||||
.as_deref()
|
||||
.is_some_and(|value| value.trim().is_empty())
|
||||
|| expected.auth_type.trim().is_empty()
|
||||
|| expected.provider_id.trim().is_empty()
|
||||
|| expected.provider_type.trim().is_empty()
|
||||
}) {
|
||||
return Err(DataLayerError::InvalidInput(
|
||||
"provider catalog OAuth credential fence must not contain empty fields".to_string(),
|
||||
));
|
||||
}
|
||||
if !update.status_snapshot_patch.is_object() {
|
||||
return Err(DataLayerError::InvalidInput(
|
||||
"provider catalog status snapshot patch must be an object".to_string(),
|
||||
@@ -1335,8 +1348,24 @@ WHERE id = ?
|
||||
)
|
||||
.push(" WHERE id = ")
|
||||
.push_bind(&update.key_id)
|
||||
.push(" AND auth_config <=> ")
|
||||
.push(" AND BINARY auth_config <=> BINARY ")
|
||||
.push_bind(update.expected_encrypted_auth_config.as_deref());
|
||||
if let Some(expected) = update.expected_credential.as_ref() {
|
||||
builder
|
||||
.push(" AND BINARY api_key <=> BINARY ")
|
||||
.push_bind(expected.encrypted_api_key.as_deref())
|
||||
.push(" AND BINARY auth_type = BINARY ")
|
||||
.push_bind(&expected.auth_type)
|
||||
.push(" AND BINARY provider_id = BINARY ")
|
||||
.push_bind(&expected.provider_id)
|
||||
.push(
|
||||
" AND EXISTS (SELECT 1 FROM providers WHERE \
|
||||
BINARY providers.id = BINARY provider_api_keys.provider_id \
|
||||
AND BINARY providers.provider_type = BINARY ",
|
||||
)
|
||||
.push_bind(&expected.provider_type)
|
||||
.push(")");
|
||||
}
|
||||
let rows_affected = builder
|
||||
.build()
|
||||
.execute(&self.pool)
|
||||
|
||||
Reference in New Issue
Block a user