Merge origin/main into main

Integrate upstream updates while preserving the local analytics dashboards and schema-only migration changes.

Combine user account analysis with upstream user/group usage statistics in separate tabs, retain all migration versions, and keep the deleted audit document removed.

Validation: gateway all-target cargo check, frontend type check and 57 focused tests, 48 migration tests, schema composition checks, and diff whitespace checks.
This commit is contained in:
elky
2026-10-02 11:57:18 +08:00
343 changed files with 27929 additions and 2549 deletions
@@ -1,6 +1,7 @@
use http::Uri;
use crate::control::management_token_required_permission;
use crate::control::{management_token_required_permission, GatewayPublicRequestContext};
use crate::handlers::shared::local_proxy_route_requires_buffered_body;
use super::{classify_control_route, headers};
@@ -206,6 +207,10 @@ fn classifies_admin_system_maintenance_write_routes_as_admin_proxy_route() {
"/api/admin/system/important-notification/test",
"important_notification_test",
),
(
"/api/admin/system/cleanup/usage/manual",
"cleanup_usage_manual",
),
("/api/admin/system/cleanup", "cleanup"),
("/api/admin/system/purge/config", "purge_config"),
("/api/admin/system/purge/users", "purge_users"),
@@ -235,6 +240,28 @@ fn classifies_admin_system_maintenance_write_routes_as_admin_proxy_route() {
Some("admin:system")
);
assert!(!decision.is_execution_runtime_candidate());
if matches!(
expected_kind,
"config_import"
| "users_import"
| "data_import"
| "smtp_test"
| "important_notification_test"
| "cleanup_usage_manual"
) {
let context = GatewayPublicRequestContext::from_request_parts(
"trace-system-maintenance-write",
&http::Method::POST,
&uri,
&headers,
Some(decision),
);
assert!(
local_proxy_route_requires_buffered_body(&context),
"POST {path} should buffer request body"
);
}
}
}
@@ -303,6 +330,20 @@ fn classifies_admin_system_update_routes_as_admin_proxy_routes() {
Some("admin:system")
);
assert!(!decision.is_execution_runtime_candidate());
if matches!(expected_kind, "prepare_update" | "apply_update") {
let context = GatewayPublicRequestContext::from_request_parts(
"trace-system-update-write",
&method,
&uri,
&headers,
Some(decision),
);
assert!(
local_proxy_route_requires_buffered_body(&context),
"{method} {path} should buffer request body"
);
}
}
}
@@ -197,6 +197,28 @@ fn classifies_admin_stats_leaderboard_models_as_admin_proxy_route() {
assert!(!decision.is_execution_runtime_candidate());
}
#[test]
fn classifies_admin_stats_leaderboard_user_groups_as_admin_proxy_route() {
let headers = headers(&[]);
let uri: Uri = "/api/admin/stats/leaderboard/user-groups"
.parse()
.expect("uri should parse");
let decision =
classify_control_route(&http::Method::GET, &uri, &headers).expect("route should classify");
assert_eq!(decision.route_class.as_deref(), Some("admin_proxy"));
assert_eq!(decision.route_family.as_deref(), Some("stats_manage"));
assert_eq!(
decision.route_kind.as_deref(),
Some("leaderboard_user_groups")
);
assert_eq!(
decision.auth_endpoint_signature.as_deref(),
Some("admin:stats")
);
assert!(!decision.is_execution_runtime_candidate());
}
#[test]
fn classifies_admin_stats_leaderboard_users_as_admin_proxy_route() {
let headers = headers(&[]);