feat(security): harden gateway boundaries and usage policies

Consolidate subscription usage policy enforcement, privacy-safe persistence, and gateway security hardening into one reviewable change.

Includes bounded HTTP and execution envelopes, header and protocol guards, DNS and relay validation, authentication and secret projection hardening, secure backup/install paths, and regression coverage.
This commit is contained in:
elky
2026-09-04 03:45:52 +08:00
parent ddcbeb3ae9
commit 579f2c7cc1
1019 changed files with 190437 additions and 26080 deletions
@@ -1,5 +1,8 @@
use std::sync::{Arc, Mutex};
use aether_data::repository::auth::{
InMemoryAuthApiKeySnapshotRepository, StoredAuthApiKeySnapshot,
};
use aether_data::repository::video_tasks::InMemoryVideoTaskRepository;
use aether_data_contracts::repository::video_tasks::{
UpsertVideoTask, VideoTaskStatus, VideoTaskWriteRepository,
@@ -9,9 +12,43 @@ use axum::routing::any;
use axum::{extract::Request, Json, Router};
use http::StatusCode;
use serde_json::json;
use sha2::{Digest, Sha256};
use super::{build_router_with_state, build_state_with_execution_runtime_override, start_server};
fn hash_api_key(value: &str) -> String {
let mut hasher = Sha256::new();
hasher.update(value.as_bytes());
format!("{:x}", hasher.finalize())
}
fn sample_auth_snapshot(api_key_id: &str, user_id: &str) -> StoredAuthApiKeySnapshot {
StoredAuthApiKeySnapshot::new(
user_id.to_string(),
"video-user".to_string(),
Some("[email protected]".to_string()),
"user".to_string(),
"local".to_string(),
true,
false,
None,
None,
None,
api_key_id.to_string(),
Some("default".to_string()),
true,
false,
false,
Some(60),
Some(5),
Some(4_102_444_800),
None,
None,
None,
)
.expect("auth snapshot should build")
}
#[tokio::test]
async fn gateway_reads_openai_video_task_via_data_read_side_without_hitting_public_route() {
let public_hits = Arc::new(Mutex::new(0usize));
@@ -92,15 +129,25 @@ async fn gateway_reads_openai_video_task_via_data_read_side_without_hitting_publ
})
.await
.expect("upsert should succeed");
let auth_repository = Arc::new(InMemoryAuthApiKeySnapshotRepository::seed(vec![(
Some(hash_api_key("client-video-read-owner-key")),
sample_auth_snapshot("api-key-video-db-rotated-123", "user-video-db-123"),
)]));
let gateway = build_router_with_state(
build_state_with_execution_runtime_override(upstream_url.clone())
.with_video_task_data_reader_for_tests(repository),
.with_data_state_for_tests(
crate::data::GatewayDataState::with_auth_and_video_task_repository_for_tests(
auth_repository,
repository,
),
),
);
let (gateway_url, gateway_handle) = start_server(gateway).await;
let response = reqwest::Client::new()
.get(format!("{gateway_url}/v1/videos/task-db-123"))
.bearer_auth("client-video-read-owner-key")
.send()
.await
.expect("request should succeed");
@@ -211,10 +258,19 @@ async fn gateway_reads_gemini_video_task_via_data_read_side_without_hitting_publ
})
.await
.expect("upsert should succeed");
let auth_repository = Arc::new(InMemoryAuthApiKeySnapshotRepository::seed(vec![(
Some(hash_api_key("client-gemini-video-read-owner-key")),
sample_auth_snapshot("api-key-video-db-rotated-123", "user-video-db-123"),
)]));
let gateway = build_router_with_state(
build_state_with_execution_runtime_override(upstream_url.clone())
.with_video_task_data_reader_for_tests(repository),
.with_data_state_for_tests(
crate::data::GatewayDataState::with_auth_and_video_task_repository_for_tests(
auth_repository,
repository,
),
),
);
let (gateway_url, gateway_handle) = start_server(gateway).await;
@@ -222,6 +278,7 @@ async fn gateway_reads_gemini_video_task_via_data_read_side_without_hitting_publ
.get(format!(
"{gateway_url}/v1beta/models/veo-3/operations/localshort123"
))
.header("x-goog-api-key", "client-gemini-video-read-owner-key")
.send()
.await
.expect("request should succeed");
@@ -239,3 +296,118 @@ async fn gateway_reads_gemini_video_task_via_data_read_side_without_hitting_publ
gateway_handle.abort();
upstream_handle.abort();
}
#[tokio::test]
async fn gateway_hides_data_backed_video_task_from_non_owner() {
let public_hits = Arc::new(Mutex::new(0usize));
let public_hits_clone = Arc::clone(&public_hits);
let upstream = Router::new()
.route(
"/api/internal/gateway/resolve",
any(|_request: Request| async move {
Json(json!({
"action": "proxy_public",
"route_class": "ai_public",
"route_family": "openai",
"route_kind": "video",
"auth_endpoint_signature": "openai:video",
"execution_runtime_candidate": true,
"auth_context": {
"user_id": "user-video-foreign",
"api_key_id": "key-video-foreign",
"access_allowed": true
},
"public_path": "/v1/videos/task-owned-123"
}))
}),
)
.route(
"/v1/videos/task-owned-123",
any(move |_request: Request| {
let public_hits_inner = Arc::clone(&public_hits_clone);
async move {
*public_hits_inner.lock().expect("mutex should lock") += 1;
(StatusCode::IM_A_TEAPOT, Body::from("public-route-hit"))
}
}),
);
let (upstream_url, upstream_handle) = start_server(upstream).await;
let repository = Arc::new(InMemoryVideoTaskRepository::default());
repository
.upsert(UpsertVideoTask {
id: "task-owned-123".to_string(),
short_id: None,
request_id: "request-owned-123".to_string(),
user_id: Some("user-video-owner".to_string()),
api_key_id: Some("key-video-owner".to_string()),
username: None,
api_key_name: None,
external_task_id: Some("ext-owned-123".to_string()),
provider_id: Some("provider-owned-123".to_string()),
endpoint_id: Some("endpoint-owned-123".to_string()),
key_id: Some("provider-key-owned-123".to_string()),
client_api_format: Some("openai:video".to_string()),
provider_api_format: Some("openai:video".to_string()),
format_converted: false,
model: Some("sora-2".to_string()),
prompt: Some("private video".to_string()),
original_request_body: Some(json!({"prompt": "private video"})),
duration_seconds: Some(4),
resolution: Some("720p".to_string()),
aspect_ratio: Some("16:9".to_string()),
size: Some("1280x720".to_string()),
status: VideoTaskStatus::Processing,
progress_percent: 50,
progress_message: None,
retry_count: 0,
poll_interval_seconds: 10,
next_poll_at_unix_secs: Some(124),
poll_count: 1,
max_poll_count: 360,
created_at_unix_ms: 123,
submitted_at_unix_secs: Some(123),
completed_at_unix_secs: None,
updated_at_unix_secs: 124,
error_code: None,
error_message: None,
video_url: None,
request_metadata: None,
})
.await
.expect("upsert should succeed");
let auth_repository = Arc::new(InMemoryAuthApiKeySnapshotRepository::seed(vec![(
Some(hash_api_key("client-video-read-foreign-key")),
sample_auth_snapshot("key-video-foreign", "user-video-foreign"),
)]));
let gateway = build_router_with_state(
build_state_with_execution_runtime_override(upstream_url.clone())
.with_data_state_for_tests(
crate::data::GatewayDataState::with_auth_and_video_task_repository_for_tests(
auth_repository,
repository,
),
),
);
let (gateway_url, gateway_handle) = start_server(gateway).await;
let response = reqwest::Client::new()
.get(format!("{gateway_url}/v1/videos/task-owned-123"))
.bearer_auth("client-video-read-foreign-key")
.send()
.await
.expect("request should succeed");
assert_eq!(response.status(), StatusCode::NOT_FOUND);
assert_eq!(
response
.json::<serde_json::Value>()
.await
.expect("json body"),
json!({"detail": "Video task not found"})
);
assert_eq!(*public_hits.lock().expect("mutex should lock"), 0);
gateway_handle.abort();
upstream_handle.abort();
}