Merge remote-tracking branch 'origin/pr/451' into aether-rust-pioneer

This commit is contained in:
fawney19
2026-05-14 02:10:37 +08:00
43 changed files with 7770 additions and 126 deletions
@@ -782,6 +782,19 @@ async fn gateway_handles_admin_modules_status_locally_with_trusted_admin_princip
assert_eq!(payload["oauth"]["active"], json!(true));
assert_eq!(payload["oauth"]["config_validated"], json!(true));
assert_eq!(payload["management_tokens"]["active"], json!(true));
assert_eq!(payload["chat_pii_redaction"]["enabled"], json!(false));
assert_eq!(
payload["chat_pii_redaction"]["display_name"],
"敏感信息替换保护"
);
assert_eq!(
payload["chat_pii_redaction"]["config_validated"],
json!(true)
);
assert_eq!(
payload["chat_pii_redaction"]["admin_route"],
"/admin/modules/chat-pii-redaction"
);
assert_eq!(
payload["notification_email"]["config_validated"],
json!(true)
@@ -908,6 +921,63 @@ async fn gateway_handles_admin_module_status_detail_locally_with_trusted_admin_p
upstream_handle.abort();
}
#[tokio::test]
async fn gateway_handles_chat_pii_redaction_module_status_detail_locally_with_trusted_admin_principal(
) {
let upstream_hits = Arc::new(Mutex::new(0usize));
let upstream_hits_clone = Arc::clone(&upstream_hits);
let upstream = Router::new().route(
"/api/admin/modules/status/chat_pii_redaction",
any(move |_request: Request| {
let upstream_hits_inner = Arc::clone(&upstream_hits_clone);
async move {
*upstream_hits_inner.lock().expect("mutex should lock") += 1;
(StatusCode::OK, Body::from("unexpected upstream hit"))
}
}),
);
let auth_module_repository = Arc::new(InMemoryAuthModuleReadRepository::default());
let data_state = GatewayDataState::with_auth_module_reader_for_tests(auth_module_repository)
.with_system_config_values_for_tests(vec![(
"module.chat_pii_redaction.enabled".to_string(),
json!(true),
)]);
let (upstream_url, upstream_handle) = start_server(upstream).await;
let gateway = build_router_with_state(
AppState::new()
.expect("gateway should build")
.with_data_state_for_tests(data_state),
);
let (gateway_url, gateway_handle) = start_server(gateway).await;
let response = reqwest::Client::new()
.get(format!(
"{gateway_url}/api/admin/modules/status/chat_pii_redaction"
))
.header(crate::constants::GATEWAY_HEADER, "rust-phase3b")
.header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123")
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
.send()
.await
.expect("request should succeed");
assert_eq!(response.status(), StatusCode::OK);
let payload: serde_json::Value = response.json().await.expect("json body should parse");
assert_eq!(payload["name"], "chat_pii_redaction");
assert_eq!(payload["display_name"], "敏感信息替换保护");
assert_eq!(payload["enabled"], json!(true));
assert_eq!(payload["active"], json!(true));
assert_eq!(payload["config_validated"], json!(true));
assert_eq!(payload["admin_route"], "/admin/modules/chat-pii-redaction");
assert_eq!(*upstream_hits.lock().expect("mutex should lock"), 0);
gateway_handle.abort();
upstream_handle.abort();
}
#[tokio::test]
async fn gateway_sets_admin_module_enabled_locally_with_trusted_admin_principal() {
let upstream_hits = Arc::new(Mutex::new(0usize));
@@ -131,7 +131,7 @@ async fn gateway_handles_admin_providers_locally_with_trusted_admin_principal()
.expect("gateway should build")
.with_data_state_for_tests(
GatewayDataState::with_provider_catalog_repository_for_tests(
provider_catalog_repository,
provider_catalog_repository.clone(),
),
),
);
@@ -240,6 +240,7 @@ async fn gateway_handles_admin_provider_summary_locally_with_trusted_admin_princ
"claude_code_advanced": {"pool_size": 3},
"pool_advanced": {"enabled": true},
"failover_rules": {"strategy": "ordered"},
"chat_pii_redaction": {"enabled": true},
"provider_ops": {"architecture_id": "anyrouter"}
})),
);
@@ -351,6 +352,7 @@ async fn gateway_handles_admin_provider_summary_locally_with_trusted_admin_princ
);
assert_eq!(payload["ops_configured"], true);
assert_eq!(payload["ops_architecture_id"], "anyrouter");
assert_eq!(payload["chat_pii_redaction"], json!({"enabled": true}));
assert_eq!(payload["created_at"], "2024-03-21T05:46:40Z");
assert_eq!(payload["updated_at"], "2024-03-21T05:48:20Z");
assert_eq!(
@@ -774,6 +776,20 @@ async fn gateway_updates_admin_provider_locally_with_trusted_admin_principal() {
let provider_catalog_repository = Arc::new(InMemoryProviderCatalogReadRepository::seed(
vec![
sample_provider("provider-openai", "openai", 10)
.with_transport_fields(
true,
false,
false,
None,
None,
None,
None,
None,
Some(json!({
"pool_advanced": {},
"failover_rules": {"strategy": "ordered"}
})),
)
.with_timestamps(Some(1_711_000_000), Some(1_711_000_100)),
sample_provider("provider-other", "other", 20),
],
@@ -792,7 +808,7 @@ async fn gateway_updates_admin_provider_locally_with_trusted_admin_principal() {
.expect("gateway should build")
.with_data_state_for_tests(
GatewayDataState::with_provider_catalog_repository_for_tests(
provider_catalog_repository,
provider_catalog_repository.clone(),
),
),
);
@@ -817,10 +833,11 @@ async fn gateway_updates_admin_provider_locally_with_trusted_admin_principal() {
"request_timeout": 55.0,
"stream_first_byte_timeout": 11.0,
"enable_format_conversion": false,
"config": {"provider_ops": {"architecture_id": "cubence"}},
"config": {
"provider_ops": {"architecture_id": "cubence"},
"chat_pii_redaction": {"enabled": true}
},
"claude_code_advanced": {"pool_size": 2},
"pool_advanced": {},
"failover_rules": {"strategy": "ordered"},
"proxy": {"url": "https://proxy.example"}
}))
.send()
@@ -847,8 +864,88 @@ async fn gateway_updates_admin_provider_locally_with_trusted_admin_principal() {
assert_eq!(payload["claude_code_advanced"], json!({"pool_size": 2}));
assert_eq!(payload["pool_advanced"], json!({}));
assert_eq!(payload["failover_rules"], json!({"strategy": "ordered"}));
assert_eq!(payload["chat_pii_redaction"], json!({"enabled": true}));
assert_eq!(payload["ops_configured"], true);
assert_eq!(payload["ops_architecture_id"], "cubence");
let disable_response = reqwest::Client::new()
.patch(format!("{gateway_url}/api/admin/providers/provider-openai"))
.header(crate::constants::GATEWAY_HEADER, "rust-phase3b")
.header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123")
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
.json(&json!({
"config": {
"chat_pii_redaction": {"enabled": false}
}
}))
.send()
.await
.expect("request should succeed");
let disable_status = disable_response.status();
let disable_body = disable_response.text().await.expect("body should read");
assert_eq!(disable_status, StatusCode::OK, "body={disable_body}");
let disable_payload: serde_json::Value =
serde_json::from_str(&disable_body).expect("json body should parse");
assert_eq!(
disable_payload["chat_pii_redaction"],
json!({"enabled": false})
);
assert_eq!(disable_payload["pool_advanced"], json!({}));
assert_eq!(
disable_payload["failover_rules"],
json!({"strategy": "ordered"})
);
assert_eq!(disable_payload["ops_architecture_id"], "cubence");
let invalid_response = reqwest::Client::new()
.patch(format!("{gateway_url}/api/admin/providers/provider-openai"))
.header(crate::constants::GATEWAY_HEADER, "rust-phase3b")
.header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123")
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
.json(&json!({
"config": {
"chat_pii_redaction": {"enabled": true, "entities": ["email"]}
}
}))
.send()
.await
.expect("request should succeed");
assert_eq!(invalid_response.status(), StatusCode::BAD_REQUEST);
let providers = provider_catalog_repository
.list_providers(false)
.await
.expect("providers should list");
let updated_provider = providers
.iter()
.find(|provider| provider.id == "provider-openai")
.expect("provider should exist");
assert_eq!(
updated_provider
.config
.as_ref()
.and_then(|value| value.get("chat_pii_redaction"))
.cloned(),
Some(json!({"enabled": false}))
);
assert_eq!(
updated_provider
.config
.as_ref()
.and_then(|value| value.get("pool_advanced"))
.cloned(),
Some(json!({}))
);
assert_eq!(
updated_provider
.config
.as_ref()
.and_then(|value| value.get("failover_rules"))
.cloned(),
Some(json!({"strategy": "ordered"}))
);
assert_eq!(*upstream_hits.lock().expect("mutex should lock"), 0);
gateway_handle.abort();
@@ -901,6 +998,7 @@ async fn gateway_creates_admin_provider_locally_with_trusted_admin_principal() {
"website": "codex.example",
"keep_priority_on_conversion": true,
"max_retries": 7,
"config": {"chat_pii_redaction": {"enabled": true}},
"pool_advanced": {},
"failover_rules": {"strategy": "ordered"},
"proxy": {"url": "https://proxy.example"}
@@ -943,6 +1041,38 @@ async fn gateway_creates_admin_provider_locally_with_trusted_admin_principal() {
.cloned(),
Some(json!({}))
);
assert_eq!(
created
.config
.as_ref()
.and_then(|value| value.get("chat_pii_redaction"))
.cloned(),
Some(json!({"enabled": true}))
);
assert_eq!(
created
.config
.as_ref()
.and_then(|value| value.get("failover_rules"))
.cloned(),
Some(json!({"strategy": "ordered"}))
);
let invalid_response = reqwest::Client::new()
.post(format!("{gateway_url}/api/admin/providers/"))
.header(crate::constants::GATEWAY_HEADER, "rust-phase3b")
.header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123")
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
.json(&json!({
"name": "invalid-redaction-provider",
"provider_type": "custom",
"config": {"chat_pii_redaction": {"enabled": true, "entities": ["email"]}}
}))
.send()
.await
.expect("request should succeed");
assert_eq!(invalid_response.status(), StatusCode::BAD_REQUEST);
let endpoints = provider_catalog_repository
.list_endpoints_by_provider_ids(std::slice::from_ref(&created.id))
@@ -1324,6 +1324,260 @@ async fn gateway_handles_admin_system_model_directives_default_as_disabled() {
gateway_handle.abort();
}
#[tokio::test]
async fn gateway_validates_chat_pii_redaction_system_config_locally_with_trusted_admin_principal() {
let upstream_hits = Arc::new(Mutex::new(0usize));
let upstream_hits_clone = Arc::clone(&upstream_hits);
let upstream = Router::new().route(
"/api/admin/system/configs/module.chat_pii_redaction.cache_ttl_seconds",
any(move |_request: Request| {
let upstream_hits_inner = Arc::clone(&upstream_hits_clone);
async move {
*upstream_hits_inner.lock().expect("mutex should lock") += 1;
(StatusCode::OK, Body::from("unexpected upstream hit"))
}
}),
);
let data_state =
GatewayDataState::disabled()
.with_system_config_values_for_tests(Vec::<(String, serde_json::Value)>::new());
let (upstream_url, upstream_handle) = start_server(upstream).await;
let gateway = build_router_with_state(
AppState::new()
.expect("gateway should build")
.with_data_state_for_tests(data_state),
);
let (gateway_url, gateway_handle) = start_server(gateway).await;
let client = reqwest::Client::new();
let get_config = |key: &'static str| {
let client = client.clone();
let gateway_url = gateway_url.clone();
async move {
let response = client
.get(format!("{gateway_url}/api/admin/system/configs/{key}"))
.header(crate::constants::GATEWAY_HEADER, "rust-phase3b")
.header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123")
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
.send()
.await
.expect("request should succeed");
assert_eq!(response.status(), StatusCode::OK, "key={key}");
response
.json::<serde_json::Value>()
.await
.expect("json body should parse")
}
};
let put_config = |key: &'static str, value: serde_json::Value| {
let client = client.clone();
let gateway_url = gateway_url.clone();
async move {
client
.put(format!("{gateway_url}/api/admin/system/configs/{key}"))
.header(crate::constants::GATEWAY_HEADER, "rust-phase3b")
.header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123")
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
.json(&json!({ "value": value }))
.send()
.await
.expect("request should succeed")
}
};
assert_eq!(
get_config("module.chat_pii_redaction.enabled").await["value"],
json!(false)
);
assert_eq!(
get_config("module.chat_pii_redaction.provider_scope").await["value"],
json!("selected_providers")
);
assert_eq!(
get_config("module.chat_pii_redaction.inject_model_instruction").await["value"],
json!(true)
);
assert_eq!(
get_config("module.chat_pii_redaction.cache_ttl_seconds").await["value"],
json!(300)
);
assert_eq!(
get_config("module.chat_pii_redaction.entities").await["value"],
json!([
"email",
"cn_phone",
"global_phone",
"cn_id",
"payment_card",
"ipv4",
"ipv6",
"api_key",
"access_token",
"secret_key",
"bearer_token",
"jwt"
])
);
let enabled_response = put_config("module.chat_pii_redaction.enabled", json!(true)).await;
assert_eq!(enabled_response.status(), StatusCode::OK);
let enabled_payload: serde_json::Value = enabled_response
.json()
.await
.expect("json body should parse");
assert_eq!(enabled_payload["value"], json!(true));
let scope_response = put_config(
"module.chat_pii_redaction.provider_scope",
json!("all_providers"),
)
.await;
assert_eq!(scope_response.status(), StatusCode::OK);
let scope_payload: serde_json::Value =
scope_response.json().await.expect("json body should parse");
assert_eq!(scope_payload["value"], json!("all_providers"));
let selected_entities_response = put_config(
"module.chat_pii_redaction.entities",
json!(["email", "jwt", "cn_phone"]),
)
.await;
assert_eq!(selected_entities_response.status(), StatusCode::OK);
let selected_entities_payload: serde_json::Value = selected_entities_response
.json()
.await
.expect("json body should parse");
assert_eq!(
selected_entities_payload["value"],
json!(["email", "cn_phone", "jwt"])
);
let ttl_response = put_config("module.chat_pii_redaction.cache_ttl_seconds", json!(3600)).await;
assert_eq!(ttl_response.status(), StatusCode::OK);
let ttl_payload: serde_json::Value = ttl_response.json().await.expect("json body should parse");
assert_eq!(ttl_payload["value"], json!(3600));
let instruction_response = put_config(
"module.chat_pii_redaction.inject_model_instruction",
json!(false),
)
.await;
assert_eq!(instruction_response.status(), StatusCode::OK);
let instruction_payload: serde_json::Value = instruction_response
.json()
.await
.expect("json body should parse");
assert_eq!(instruction_payload["value"], json!(false));
let invalid_scope_response = put_config(
"module.chat_pii_redaction.provider_scope",
json!("enabled_providers"),
)
.await;
assert_eq!(invalid_scope_response.status(), StatusCode::BAD_REQUEST);
let invalid_entities_response = put_config(
"module.chat_pii_redaction.entities",
json!(["email", "name"]),
)
.await;
assert_eq!(invalid_entities_response.status(), StatusCode::BAD_REQUEST);
let invalid_ttl_response =
put_config("module.chat_pii_redaction.cache_ttl_seconds", json!(600)).await;
assert_eq!(invalid_ttl_response.status(), StatusCode::BAD_REQUEST);
let invalid_instruction_response = put_config(
"module.chat_pii_redaction.inject_model_instruction",
json!("yes"),
)
.await;
assert_eq!(
invalid_instruction_response.status(),
StatusCode::BAD_REQUEST
);
let enabled_default_response =
put_config("module.chat_pii_redaction.enabled", serde_json::Value::Null).await;
assert_eq!(enabled_default_response.status(), StatusCode::OK);
let enabled_default_payload: serde_json::Value = enabled_default_response
.json()
.await
.expect("json body should parse");
assert_eq!(enabled_default_payload["value"], json!(false));
let scope_default_response = put_config(
"module.chat_pii_redaction.provider_scope",
serde_json::Value::Null,
)
.await;
assert_eq!(scope_default_response.status(), StatusCode::OK);
let scope_default_payload: serde_json::Value = scope_default_response
.json()
.await
.expect("json body should parse");
assert_eq!(scope_default_payload["value"], json!("selected_providers"));
let entities_default_response = put_config(
"module.chat_pii_redaction.entities",
serde_json::Value::Null,
)
.await;
assert_eq!(entities_default_response.status(), StatusCode::OK);
let entities_default_payload: serde_json::Value = entities_default_response
.json()
.await
.expect("json body should parse");
assert_eq!(
entities_default_payload["value"],
json!([
"email",
"cn_phone",
"global_phone",
"cn_id",
"payment_card",
"ipv4",
"ipv6",
"api_key",
"access_token",
"secret_key",
"bearer_token",
"jwt"
])
);
let ttl_default_response = put_config(
"module.chat_pii_redaction.cache_ttl_seconds",
serde_json::Value::Null,
)
.await;
assert_eq!(ttl_default_response.status(), StatusCode::OK);
let ttl_default_payload: serde_json::Value = ttl_default_response
.json()
.await
.expect("json body should parse");
assert_eq!(ttl_default_payload["value"], json!(300));
let instruction_default_response = put_config(
"module.chat_pii_redaction.inject_model_instruction",
serde_json::Value::Null,
)
.await;
assert_eq!(instruction_default_response.status(), StatusCode::OK);
let instruction_default_payload: serde_json::Value = instruction_default_response
.json()
.await
.expect("json body should parse");
assert_eq!(instruction_default_payload["value"], json!(true));
assert_eq!(*upstream_hits.lock().expect("mutex should lock"), 0);
gateway_handle.abort();
upstream_handle.abort();
}
#[tokio::test]
async fn gateway_handles_admin_system_provider_priority_mode_locally_with_bearer_admin_session() {
let upstream_hits = Arc::new(Mutex::new(0usize));