mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-04 00:17:45 +08:00
ci(gateway): slim pool scheduler fixtures and backup candidates
This commit is contained in:
@@ -799,6 +799,7 @@ mod tests {
|
||||
use aes_gcm::aead::{Aead, AeadCore, KeyInit, OsRng, Payload};
|
||||
use aes_gcm::Aes256Gcm;
|
||||
use aether_crypto::DEVELOPMENT_ENCRYPTION_KEY;
|
||||
use base64::Engine as _;
|
||||
use bytes::Bytes;
|
||||
use chrono::{DateTime, Utc};
|
||||
use serde_json::json;
|
||||
@@ -1243,8 +1244,18 @@ mod tests {
|
||||
assert_eq!(restored.key_id, None);
|
||||
assert_eq!(restored.export_version.as_deref(), Some("2.3"));
|
||||
|
||||
// 17 个互不相同的合法 base64-32 字节直接密钥:本段只验证“legacy 候选 >16 → TooManyLegacyKeys”,
|
||||
// 不测口令强度、不解密。直接密钥走 decode_direct_fernet_key(生产已支持路径),跳过 PBKDF2,
|
||||
// 避免本用例为计数语义再付 17×10 万次迭代;上半段 DEVELOPMENT_ENCRYPTION_KEY 真实 v1 兼容
|
||||
// 与 wrong-legacy-secret 派生路径保持不变。
|
||||
let too_many: Vec<_> = (0..17)
|
||||
.map(|index| BackupDecryptionKey::historical(format!("legacy-{index}")).unwrap())
|
||||
.map(|index| {
|
||||
let mut material = [0u8; 32];
|
||||
material[0] = index as u8 + 1;
|
||||
material[31] = index as u8 + 1;
|
||||
let secret = base64::engine::general_purpose::STANDARD.encode(material);
|
||||
BackupDecryptionKey::historical(secret).unwrap()
|
||||
})
|
||||
.collect();
|
||||
assert!(matches!(
|
||||
restore_backup_json(
|
||||
|
||||
@@ -5146,15 +5146,6 @@ mod tests {
|
||||
))
|
||||
}
|
||||
|
||||
fn provider_catalog_credential_state() -> AppState {
|
||||
AppState::new()
|
||||
.expect("credential state should build")
|
||||
.with_data_state_for_tests(
|
||||
GatewayDataState::disabled()
|
||||
.with_encryption_key_for_tests(aether_crypto::DEVELOPMENT_ENCRYPTION_KEY),
|
||||
)
|
||||
}
|
||||
|
||||
fn large_pool_fixture(
|
||||
key_count: usize,
|
||||
provider_config: Option<serde_json::Value>,
|
||||
@@ -5205,18 +5196,12 @@ mod tests {
|
||||
)
|
||||
.expect("endpoint transport should build");
|
||||
|
||||
let credential_state = provider_catalog_credential_state();
|
||||
// 这些用例只验证池扫描、跳过计数和游标预算,不会发起请求或读取凭据。
|
||||
// 留空凭据可跳过无关的 Fernet 加解密,同时避免复用绑定密文破坏 key_id AAD。
|
||||
let mut keys = Vec::with_capacity(key_count);
|
||||
let mut rows = Vec::with_capacity(key_count);
|
||||
for index in 0..key_count {
|
||||
let key_id = format!("key-{index:05}");
|
||||
let encrypted_api_key = credential_state
|
||||
.seal_provider_catalog_key_api_key(
|
||||
"provider-pool",
|
||||
&key_id,
|
||||
&format!("secret-{index}"),
|
||||
)
|
||||
.expect("api key should encrypt");
|
||||
let mut key = StoredProviderCatalogKey::new(
|
||||
key_id.clone(),
|
||||
"provider-pool".to_string(),
|
||||
@@ -5228,7 +5213,7 @@ mod tests {
|
||||
.expect("key should build")
|
||||
.with_transport_fields(
|
||||
Some(json!(["openai:chat"])),
|
||||
encrypted_api_key,
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
@@ -5363,10 +5348,8 @@ mod tests {
|
||||
.expect("endpoint transport should build")
|
||||
}
|
||||
|
||||
/// 这些测试只检查池调度状态,不涉及凭据解密,因此不构造无关的密文。
|
||||
fn sample_codex_pool_key(provider_id: &str, key_id: &str) -> StoredProviderCatalogKey {
|
||||
let encrypted_api_key = provider_catalog_credential_state()
|
||||
.seal_provider_catalog_key_api_key(provider_id, key_id, &format!("secret-{key_id}"))
|
||||
.expect("api key should encrypt");
|
||||
let mut key = StoredProviderCatalogKey::new(
|
||||
key_id.to_string(),
|
||||
provider_id.to_string(),
|
||||
@@ -5378,7 +5361,7 @@ mod tests {
|
||||
.expect("key should build")
|
||||
.with_transport_fields(
|
||||
Some(json!(["openai:responses"])),
|
||||
encrypted_api_key,
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
Some(json!({"openai:responses": 1})),
|
||||
|
||||
Reference in New Issue
Block a user