feat(gateway): harden provider request execution

Preserve exact request payloads and model client surface and API operation explicitly.

Add Anthropic compatibility profiles, bounded stream commitment, and scoped OAuth retry behavior across provider transports.
This commit is contained in:
elky
2026-07-27 09:36:31 +08:00
parent 79b70f7b5c
commit 531cf11025
152 changed files with 13984 additions and 2075 deletions
@@ -460,22 +460,16 @@ fn key_auth_channel_matches(row: &CandidateSelectionRow, api_format: &str) -> bo
matches!(auth_type.as_str(), "oauth" | "api_key" | "bearer")
&& api_format == "openai:chat"
}
"vertex_ai" => {
(auth_type == "api_key"
&& matches!(
api_format.as_str(),
"gemini:generate_content" | "gemini:embedding"
))
|| (matches!(auth_type.as_str(), "service_account" | "vertex_ai")
&& matches!(
api_format.as_str(),
"claude:messages" | "gemini:generate_content" | "gemini:embedding"
))
}
"vertex_ai" => vertex_key_auth_channel_matches(&auth_type, &api_format),
_ => auth_type != "oauth",
}
}
fn vertex_key_auth_channel_matches(auth_type: &str, api_format: &str) -> bool {
matches!(auth_type, "api_key" | "service_account" | "vertex_ai")
&& matches!(api_format, "gemini:generate_content" | "gemini:embedding")
}
fn dedupe_candidate_selection_rows(
rows: Vec<StoredMinimalCandidateSelectionRow>,
) -> Vec<StoredMinimalCandidateSelectionRow> {
@@ -797,7 +791,7 @@ fn sql_match_aliases(api_formats: &[String]) -> Vec<String> {
#[cfg(test)]
mod tests {
use super::MysqlMinimalCandidateSelectionReadRepository;
use super::{vertex_key_auth_channel_matches, MysqlMinimalCandidateSelectionReadRepository};
#[tokio::test]
async fn repository_builds_from_lazy_pool() {
@@ -809,4 +803,22 @@ mod tests {
let _repository = MysqlMinimalCandidateSelectionReadRepository::new(pool);
}
#[test]
fn vertex_auth_matrix_rejects_retired_claude_format() {
for auth_type in ["api_key", "service_account", "vertex_ai"] {
assert!(!vertex_key_auth_channel_matches(
auth_type,
"claude:messages"
));
assert!(vertex_key_auth_channel_matches(
auth_type,
"gemini:generate_content"
));
assert!(vertex_key_auth_channel_matches(
auth_type,
"gemini:embedding"
));
}
}
}
@@ -1281,6 +1281,19 @@ WHERE id = ?
"provider catalog OAuth api_key update must not be empty".to_string(),
));
}
if update.expected_credential.as_ref().is_some_and(|expected| {
expected
.encrypted_api_key
.as_deref()
.is_some_and(|value| value.trim().is_empty())
|| expected.auth_type.trim().is_empty()
|| expected.provider_id.trim().is_empty()
|| expected.provider_type.trim().is_empty()
}) {
return Err(DataLayerError::InvalidInput(
"provider catalog OAuth credential fence must not contain empty fields".to_string(),
));
}
if !update.status_snapshot_patch.is_object() {
return Err(DataLayerError::InvalidInput(
"provider catalog status snapshot patch must be an object".to_string(),
@@ -1335,8 +1348,24 @@ WHERE id = ?
)
.push(" WHERE id = ")
.push_bind(&update.key_id)
.push(" AND auth_config <=> ")
.push(" AND BINARY auth_config <=> BINARY ")
.push_bind(update.expected_encrypted_auth_config.as_deref());
if let Some(expected) = update.expected_credential.as_ref() {
builder
.push(" AND BINARY api_key <=> BINARY ")
.push_bind(expected.encrypted_api_key.as_deref())
.push(" AND BINARY auth_type = BINARY ")
.push_bind(&expected.auth_type)
.push(" AND BINARY provider_id = BINARY ")
.push_bind(&expected.provider_id)
.push(
" AND EXISTS (SELECT 1 FROM providers WHERE \
BINARY providers.id = BINARY provider_api_keys.provider_id \
AND BINARY providers.provider_type = BINARY ",
)
.push_bind(&expected.provider_type)
.push(")");
}
let rows_affected = builder
.build()
.execute(&self.pool)