feat(gateway): harden provider request execution

Preserve exact request payloads and model client surface and API operation explicitly.

Add Anthropic compatibility profiles, bounded stream commitment, and scoped OAuth retry behavior across provider transports.
This commit is contained in:
elky
2026-07-27 09:36:31 +08:00
parent 79b70f7b5c
commit 531cf11025
152 changed files with 13984 additions and 2075 deletions
@@ -5,10 +5,10 @@ pub use snapshot::ProviderCatalogSnapshot;
pub use types::{
ProviderCatalogKeyAdaptiveState, ProviderCatalogKeyAdaptiveStateUpdate,
ProviderCatalogKeyHealthStateUpdate, ProviderCatalogKeyListOrder, ProviderCatalogKeyListQuery,
ProviderCatalogKeyOAuthRuntimeStateCasUpdate, ProviderCatalogKeyRuntimeMetadataUpdate,
ProviderCatalogKeyStatusSnapshotUpdate, ProviderCatalogReadRepository,
ProviderCatalogUpstreamMetadataNamespaceUpdate, ProviderCatalogWriteRepository,
StoredProviderCatalogEndpoint, StoredProviderCatalogKey,
ProviderCatalogKeyOAuthCredentialFence, ProviderCatalogKeyOAuthRuntimeStateCasUpdate,
ProviderCatalogKeyRuntimeMetadataUpdate, ProviderCatalogKeyStatusSnapshotUpdate,
ProviderCatalogReadRepository, ProviderCatalogUpstreamMetadataNamespaceUpdate,
ProviderCatalogWriteRepository, StoredProviderCatalogEndpoint, StoredProviderCatalogKey,
StoredProviderCatalogKeyMaintenanceSummary, StoredProviderCatalogKeyPage,
StoredProviderCatalogKeyStats, StoredProviderCatalogProvider,
};
@@ -67,13 +67,28 @@ pub struct ProviderCatalogKeyStatusSnapshotUpdate {
pub updated_at_unix_secs: Option<u64>,
}
/// Credential context observed before an OAuth refresh started. Repositories
/// compare every field atomically with the runtime-state update so an
/// administrator replacement cannot be overwritten by an older refresh.
#[derive(Debug, Clone, PartialEq, serde::Serialize, serde::Deserialize)]
pub struct ProviderCatalogKeyOAuthCredentialFence {
/// Exact nullable ciphertext stored in `provider_api_keys.api_key`.
pub encrypted_api_key: Option<String>,
pub auth_type: String,
pub provider_id: String,
pub provider_type: String,
}
/// Agent/runtime-owned OAuth state update fenced by the exact encrypted
/// auth_config observed before the refresh started. Repositories must update
/// only these fields and return `false` when the expected config changed.
/// auth_config and, when supplied, credential context observed before the
/// refresh started. Repositories must update only these fields and return
/// `false` when an expected value changed.
#[derive(Debug, Clone, PartialEq, serde::Serialize, serde::Deserialize)]
pub struct ProviderCatalogKeyOAuthRuntimeStateCasUpdate {
pub key_id: String,
pub expected_encrypted_auth_config: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub expected_credential: Option<ProviderCatalogKeyOAuthCredentialFence>,
pub encrypted_auth_config: String,
/// Optional access-token ciphertext replacement owned by refresh success.
#[serde(default, skip_serializing_if = "Option::is_none")]