mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-07 18:07:47 +08:00
Merge origin/main into fix/gemini-cli-v1internal
This commit is contained in:
@@ -186,6 +186,9 @@ fn select_primary_credential(
|
||||
if signature.starts_with("gemini:") {
|
||||
return select_gemini_credential(bundle);
|
||||
}
|
||||
if signature.starts_with("antigravity:") {
|
||||
return select_antigravity_credential(bundle);
|
||||
}
|
||||
if signature.starts_with("claude:") {
|
||||
return select_claude_messages_credential(bundle);
|
||||
}
|
||||
@@ -196,6 +199,20 @@ fn select_primary_credential(
|
||||
select_generic_credential(bundle)
|
||||
}
|
||||
|
||||
fn select_antigravity_credential(
|
||||
bundle: &GatewayCredentialBundle,
|
||||
) -> Option<GatewayPrimaryCredential> {
|
||||
first_provider_api_key(
|
||||
bundle,
|
||||
&[
|
||||
GatewayCredentialCarrier::XApiKey,
|
||||
GatewayCredentialCarrier::ApiKey,
|
||||
],
|
||||
)
|
||||
.or_else(|| first_bearer_token(bundle))
|
||||
.or_else(|| select_cookie_credential(bundle))
|
||||
}
|
||||
|
||||
fn select_openai_credential(bundle: &GatewayCredentialBundle) -> Option<GatewayPrimaryCredential> {
|
||||
first_provider_api_key(
|
||||
bundle,
|
||||
@@ -459,6 +476,29 @@ mod tests {
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn prefers_antigravity_aether_api_key_over_google_bearer() {
|
||||
let mut headers = http::HeaderMap::new();
|
||||
headers.insert(
|
||||
http::header::AUTHORIZATION,
|
||||
"Bearer google-oauth-access-token".parse().unwrap(),
|
||||
);
|
||||
headers.insert("x-api-key", "sk-aether-antigravity".parse().unwrap());
|
||||
|
||||
let extracted = extract_request_credentials(
|
||||
&headers,
|
||||
&uri("/v1internal:streamGenerateContent?alt=sse"),
|
||||
"antigravity:v1internal",
|
||||
);
|
||||
assert_eq!(
|
||||
extracted.primary,
|
||||
Some(GatewayPrimaryCredential::ProviderApiKey {
|
||||
raw: "sk-aether-antigravity".to_string(),
|
||||
carrier: GatewayCredentialCarrier::XApiKey,
|
||||
})
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn prefers_gemini_query_key_over_header_key() {
|
||||
let mut headers = http::HeaderMap::new();
|
||||
|
||||
@@ -16,16 +16,48 @@ use crate::{AppState, GatewayError};
|
||||
use super::super::GatewayControlDecision;
|
||||
use super::credentials::{
|
||||
build_auth_context_cache_key, current_unix_secs, extract_request_credentials,
|
||||
extract_trusted_admin_headers,
|
||||
extract_trusted_admin_headers, hash_api_key,
|
||||
};
|
||||
use super::gate::GatewayLocalAuthRejection;
|
||||
use super::principal::derive_principal_candidate;
|
||||
use super::types::{GatewayPrincipalCandidate, GatewayTrustedAuthHeaders};
|
||||
use super::types::{
|
||||
GatewayCredentialCarrier, GatewayPrincipalCandidate, GatewayTrustedAuthHeaders,
|
||||
};
|
||||
use crate::headers::header_value_str;
|
||||
|
||||
const AUTH_CONTEXT_CACHE_TTL: Duration = Duration::from_secs(60);
|
||||
const AUTH_CONTEXT_CACHE_MAX_ENTRIES: usize = 256;
|
||||
|
||||
#[derive(Debug, Clone, Deserialize)]
|
||||
struct AntigravityBearerBridgeConfig {
|
||||
#[serde(default)]
|
||||
enabled: bool,
|
||||
#[serde(default)]
|
||||
auth_user_id: String,
|
||||
#[serde(default)]
|
||||
auth_api_key_id: String,
|
||||
#[serde(default)]
|
||||
bearer_sha256_allowlist: Vec<String>,
|
||||
#[serde(default)]
|
||||
allow_unverified_google_bearer: bool,
|
||||
}
|
||||
|
||||
impl AntigravityBearerBridgeConfig {
|
||||
fn bearer_validation_mode(&self, raw_bearer: &str) -> Option<&'static str> {
|
||||
if !self.bearer_sha256_allowlist.is_empty() {
|
||||
let bearer_hash = hash_api_key(raw_bearer);
|
||||
return self
|
||||
.bearer_sha256_allowlist
|
||||
.iter()
|
||||
.any(|allowed| allowed.trim().eq_ignore_ascii_case(&bearer_hash))
|
||||
.then_some("sha256_allowlist");
|
||||
}
|
||||
|
||||
self.allow_unverified_google_bearer
|
||||
.then_some("explicit_unverified")
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Deserialize, Serialize)]
|
||||
pub(crate) struct GatewayControlAuthContext {
|
||||
pub(crate) user_id: String,
|
||||
@@ -607,14 +639,117 @@ pub(super) async fn resolve_data_backed_auth_context(
|
||||
.await,
|
||||
))
|
||||
}
|
||||
Some(
|
||||
GatewayPrincipalCandidate::DeferredBearerToken { .. }
|
||||
| GatewayPrincipalCandidate::DeferredCookieHeader { .. },
|
||||
) => Ok(None),
|
||||
Some(GatewayPrincipalCandidate::DeferredBearerToken { raw, carrier }) => {
|
||||
if let Some(auth_context) = resolve_antigravity_bearer_bridge_auth_context(
|
||||
state,
|
||||
signature,
|
||||
raw.as_str(),
|
||||
carrier,
|
||||
now_unix_secs,
|
||||
)
|
||||
.await?
|
||||
{
|
||||
return Ok(Some(auth_context));
|
||||
}
|
||||
Ok(None)
|
||||
}
|
||||
Some(GatewayPrincipalCandidate::DeferredCookieHeader { .. }) => Ok(None),
|
||||
None => Ok(None),
|
||||
}
|
||||
}
|
||||
|
||||
async fn resolve_antigravity_bearer_bridge_auth_context(
|
||||
state: &AppState,
|
||||
auth_endpoint_signature: &str,
|
||||
raw_bearer: &str,
|
||||
carrier: GatewayCredentialCarrier,
|
||||
now_unix_secs: u64,
|
||||
) -> Result<Option<GatewayControlAuthContext>, GatewayError> {
|
||||
if carrier != GatewayCredentialCarrier::AuthorizationBearer
|
||||
|| !auth_endpoint_signature
|
||||
.trim()
|
||||
.eq_ignore_ascii_case("antigravity:v1internal")
|
||||
{
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
let Some(config_value) = state
|
||||
.read_system_config_json_value(crate::constants::ANTIGRAVITY_BEARER_BRIDGE_CONFIG_KEY)
|
||||
.await?
|
||||
else {
|
||||
return Ok(None);
|
||||
};
|
||||
if config_value.is_null() {
|
||||
return Ok(None);
|
||||
}
|
||||
let config: AntigravityBearerBridgeConfig =
|
||||
serde_json::from_value(config_value).map_err(|err| {
|
||||
GatewayError::Internal(format!(
|
||||
"{} invalid: {err}",
|
||||
crate::constants::ANTIGRAVITY_BEARER_BRIDGE_CONFIG_KEY
|
||||
))
|
||||
})?;
|
||||
if !config.enabled {
|
||||
return Ok(None);
|
||||
}
|
||||
let Some(validation_mode) = config.bearer_validation_mode(raw_bearer) else {
|
||||
return Ok(None);
|
||||
};
|
||||
let user_id = config.auth_user_id.trim();
|
||||
let api_key_id = config.auth_api_key_id.trim();
|
||||
if user_id.is_empty() || api_key_id.is_empty() {
|
||||
return Err(GatewayError::Internal(format!(
|
||||
"{} requires auth_user_id and auth_api_key_id",
|
||||
crate::constants::ANTIGRAVITY_BEARER_BRIDGE_CONFIG_KEY
|
||||
)));
|
||||
}
|
||||
|
||||
let snapshot = state
|
||||
.data
|
||||
.read_auth_api_key_snapshot(user_id, api_key_id, now_unix_secs)
|
||||
.await
|
||||
.map_err(|err| GatewayError::Internal(err.to_string()))?;
|
||||
let Some(snapshot) = snapshot else {
|
||||
return Ok(Some(GatewayControlAuthContext {
|
||||
user_id: user_id.to_string(),
|
||||
api_key_id: api_key_id.to_string(),
|
||||
username: None,
|
||||
api_key_name: None,
|
||||
balance_remaining: None,
|
||||
access_allowed: false,
|
||||
user_rate_limit: None,
|
||||
api_key_rate_limit: None,
|
||||
api_key_is_standalone: false,
|
||||
admin_bypass_limits: false,
|
||||
local_rejection: Some(GatewayLocalAuthRejection::InvalidApiKey),
|
||||
allowed_models: None,
|
||||
ip_rules: None,
|
||||
}));
|
||||
};
|
||||
|
||||
let wallet_access = resolve_wallet_auth_gate(state, &snapshot).await?;
|
||||
let auth_context = build_data_backed_auth_context(
|
||||
state,
|
||||
snapshot,
|
||||
auth_endpoint_signature,
|
||||
None,
|
||||
None,
|
||||
wallet_access,
|
||||
)
|
||||
.await;
|
||||
info!(
|
||||
event_name = "antigravity_bearer_bridge_auth_context_resolved",
|
||||
log_type = "event",
|
||||
validation_mode,
|
||||
user_id = auth_context.user_id.as_str(),
|
||||
api_key_id = auth_context.api_key_id.as_str(),
|
||||
access_allowed = auth_context.access_allowed,
|
||||
has_local_rejection = auth_context.local_rejection.is_some(),
|
||||
"resolved Antigravity bearer bridge auth context"
|
||||
);
|
||||
Ok(Some(auth_context))
|
||||
}
|
||||
|
||||
async fn resolve_trusted_auth_context(
|
||||
state: &AppState,
|
||||
auth_endpoint_signature: &str,
|
||||
@@ -712,7 +847,12 @@ async fn build_data_backed_auth_context(
|
||||
})
|
||||
} else if snapshot
|
||||
.effective_allowed_api_formats()
|
||||
.is_some_and(|allowed| !contains_api_format_or_alias(allowed, auth_endpoint_signature))
|
||||
.is_some_and(|allowed| {
|
||||
!contains_api_format_or_alias(
|
||||
allowed,
|
||||
auth_gate_api_format(auth_endpoint_signature).as_str(),
|
||||
)
|
||||
})
|
||||
{
|
||||
Some(GatewayLocalAuthRejection::ApiFormatNotAllowed {
|
||||
api_format: auth_endpoint_signature.to_string(),
|
||||
@@ -747,6 +887,15 @@ fn normalize_api_format_alias(value: &str) -> String {
|
||||
crate::ai_serving::normalize_api_format_alias(value)
|
||||
}
|
||||
|
||||
fn auth_gate_api_format(auth_endpoint_signature: &str) -> String {
|
||||
let normalized = normalize_api_format_alias(auth_endpoint_signature);
|
||||
if normalized == "antigravity:v1internal" {
|
||||
"gemini:generate_content".to_string()
|
||||
} else {
|
||||
normalized
|
||||
}
|
||||
}
|
||||
|
||||
fn api_format_matches(left: &str, right: &str) -> bool {
|
||||
aether_scheduler_core::api_format_matches_allowed_value(left, right)
|
||||
}
|
||||
@@ -1261,6 +1410,58 @@ mod tests {
|
||||
assert_eq!(auth_context.local_rejection, None);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn data_backed_auth_context_allows_antigravity_v1internal_for_gemini_generate_content_keys(
|
||||
) {
|
||||
let api_key = "sk-test-antigravity-v1internal";
|
||||
let mut snapshot = sample_snapshot("key-ant-v1internal", "user-ant-v1internal");
|
||||
snapshot.user_allowed_providers = Some(vec!["antigravity".to_string()]);
|
||||
snapshot.api_key_allowed_providers = Some(vec!["antigravity".to_string()]);
|
||||
snapshot.user_allowed_api_formats = Some(vec!["gemini:generate_content".to_string()]);
|
||||
snapshot.api_key_allowed_api_formats = Some(vec!["gemini:generate_content".to_string()]);
|
||||
let repository = Arc::new(InMemoryAuthApiKeySnapshotRepository::seed(vec![(
|
||||
Some(hash_api_key(api_key)),
|
||||
snapshot,
|
||||
)]));
|
||||
let provider_catalog = Arc::new(InMemoryProviderCatalogReadRepository::seed(
|
||||
vec![sample_provider(
|
||||
"provider-antigravity-1",
|
||||
"Antigravity",
|
||||
"antigravity",
|
||||
)],
|
||||
vec![sample_endpoint(
|
||||
"endpoint-antigravity-1",
|
||||
"provider-antigravity-1",
|
||||
"gemini:generate_content",
|
||||
)],
|
||||
Vec::new(),
|
||||
));
|
||||
let data = GatewayDataState::with_auth_api_key_reader_for_tests(repository)
|
||||
.with_provider_catalog_reader(provider_catalog);
|
||||
let state = AppState::new()
|
||||
.expect("state should build")
|
||||
.with_data_state_for_tests(data);
|
||||
|
||||
let mut headers = HeaderMap::new();
|
||||
headers.insert("x-api-key", api_key.parse().unwrap());
|
||||
headers.insert(
|
||||
http::header::AUTHORIZATION,
|
||||
"Bearer google-oauth-access-token".parse().unwrap(),
|
||||
);
|
||||
|
||||
let auth_context = resolve_data_backed_auth_context(
|
||||
&state,
|
||||
&headers,
|
||||
&uri("/v1internal:streamGenerateContent?alt=sse"),
|
||||
Some("antigravity:v1internal"),
|
||||
)
|
||||
.await
|
||||
.expect("resolution should succeed")
|
||||
.expect("auth context should exist");
|
||||
|
||||
assert_eq!(auth_context.local_rejection, None);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn data_backed_auth_context_allows_provider_id_for_convertible_endpoint_format() {
|
||||
let api_key = "sk-test-provider-convertible-endpoint";
|
||||
|
||||
@@ -23,6 +23,65 @@ pub(super) fn classify_admin_system_family_route(
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::GET && normalized_path == "/api/admin/system/releases" {
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"releases",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::GET
|
||||
&& normalized_path == "/api/admin/system/update-capability"
|
||||
{
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"update_capability",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::POST && normalized_path == "/api/admin/system/prepare-update"
|
||||
{
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"prepare_update",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::POST && normalized_path == "/api/admin/system/apply-update" {
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"apply_update",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::POST && normalized_path == "/api/admin/system/rollback" {
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"rollback",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::GET && normalized_path == "/api/admin/system/update-status" {
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"update_status",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::GET && normalized_path == "/api/admin/system/update-history" {
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"update_history",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::GET && normalized_path == "/api/admin/system/aws-regions" {
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
@@ -71,6 +130,15 @@ pub(super) fn classify_admin_system_family_route(
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::POST && normalized_path == "/api/admin/system/backups/s3/run"
|
||||
{
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
"system_manage",
|
||||
"s3_backup_run",
|
||||
"admin:system",
|
||||
false,
|
||||
))
|
||||
} else if method == http::Method::POST && normalized_path == "/api/admin/system/config/import" {
|
||||
Some(classified(
|
||||
"admin_proxy",
|
||||
|
||||
@@ -8,7 +8,9 @@ pub(super) fn classify_ai_public_route(
|
||||
normalized_path: &str,
|
||||
headers: &http::HeaderMap,
|
||||
) -> Option<ClassifiedRoute> {
|
||||
if method == http::Method::POST && normalized_path == "/v1/chat/completions" {
|
||||
if let Some(route) = classify_antigravity_v1internal_route(method, normalized_path) {
|
||||
Some(route)
|
||||
} else if method == http::Method::POST && normalized_path == "/v1/chat/completions" {
|
||||
Some(classified(
|
||||
"ai_public",
|
||||
"openai",
|
||||
@@ -167,3 +169,34 @@ fn is_gemini_files_method(method: &http::Method, normalized_path: &str) -> bool
|
||||
|| ((method == http::Method::GET || method == http::Method::DELETE)
|
||||
&& normalized_path.starts_with("/v1beta/files"))
|
||||
}
|
||||
|
||||
fn classify_antigravity_v1internal_route(
|
||||
method: &http::Method,
|
||||
normalized_path: &str,
|
||||
) -> Option<ClassifiedRoute> {
|
||||
if method != http::Method::POST {
|
||||
return None;
|
||||
}
|
||||
|
||||
let action = normalized_path.strip_prefix("/v1internal:")?;
|
||||
let (route_kind, execution_runtime_candidate) = match action {
|
||||
"loadCodeAssist" => ("load_code_assist", false),
|
||||
"fetchAvailableModels" => ("fetch_available_models", false),
|
||||
"fetchUserInfo" => ("fetch_user_info", false),
|
||||
"fetchAdminControls" => ("fetch_admin_controls", false),
|
||||
"setUserSettings" => ("set_user_settings", false),
|
||||
"listExperiments" => ("list_experiments", false),
|
||||
"recordCodeAssistMetrics" => ("record_code_assist_metrics", false),
|
||||
"streamGenerateContent" => ("stream_generate_content", true),
|
||||
_ => return None,
|
||||
};
|
||||
|
||||
Some(classified_with_request_auth_channel(
|
||||
"ai_public",
|
||||
"antigravity",
|
||||
route_kind,
|
||||
"bearer_like",
|
||||
"antigravity:v1internal",
|
||||
execution_runtime_candidate,
|
||||
))
|
||||
}
|
||||
|
||||
@@ -797,7 +797,6 @@ pub(super) fn classify_public_support_route(
|
||||
} else if method == http::Method::GET
|
||||
&& (has_single_segment_after_prefix(normalized_path, "/install/")
|
||||
|| has_single_segment_after_prefix(normalized_path, "/install-tunnel/")
|
||||
|| has_single_segment_after_prefix(normalized_path, "/install-proxy/")
|
||||
|| has_single_segment_after_prefix(normalized_path, "/i/"))
|
||||
{
|
||||
Some(classified(
|
||||
|
||||
@@ -175,6 +175,25 @@ fn classifies_admin_system_data_export_as_admin_proxy_route() {
|
||||
assert!(!decision.is_execution_runtime_candidate());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn classifies_admin_system_s3_backup_start_as_admin_proxy_route() {
|
||||
let headers = headers(&[]);
|
||||
let uri: Uri = "/api/admin/system/backups/s3/run"
|
||||
.parse()
|
||||
.expect("uri should parse");
|
||||
let decision =
|
||||
classify_control_route(&http::Method::POST, &uri, &headers).expect("route should classify");
|
||||
|
||||
assert_eq!(decision.route_class.as_deref(), Some("admin_proxy"));
|
||||
assert_eq!(decision.route_family.as_deref(), Some("system_manage"));
|
||||
assert_eq!(decision.route_kind.as_deref(), Some("s3_backup_run"));
|
||||
assert_eq!(
|
||||
decision.auth_endpoint_signature.as_deref(),
|
||||
Some("admin:system")
|
||||
);
|
||||
assert!(!decision.is_execution_runtime_candidate());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn classifies_admin_system_maintenance_write_routes_as_admin_proxy_route() {
|
||||
let headers = headers(&[]);
|
||||
@@ -238,6 +257,55 @@ fn classifies_admin_system_check_update_as_admin_proxy_route() {
|
||||
assert!(!decision.is_execution_runtime_candidate());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn classifies_admin_system_update_routes_as_admin_proxy_routes() {
|
||||
let headers = headers(&[]);
|
||||
let cases = [
|
||||
(
|
||||
http::Method::GET,
|
||||
"/api/admin/system/update-capability",
|
||||
"update_capability",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/system/prepare-update",
|
||||
"prepare_update",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/system/apply-update",
|
||||
"apply_update",
|
||||
),
|
||||
(http::Method::POST, "/api/admin/system/rollback", "rollback"),
|
||||
(http::Method::GET, "/api/admin/system/releases", "releases"),
|
||||
(
|
||||
http::Method::GET,
|
||||
"/api/admin/system/update-history",
|
||||
"update_history",
|
||||
),
|
||||
(
|
||||
http::Method::GET,
|
||||
"/api/admin/system/update-status",
|
||||
"update_status",
|
||||
),
|
||||
];
|
||||
|
||||
for (method, path, expected_kind) in cases {
|
||||
let uri: Uri = path.parse().expect("uri should parse");
|
||||
let decision =
|
||||
classify_control_route(&method, &uri, &headers).expect("route should classify");
|
||||
|
||||
assert_eq!(decision.route_class.as_deref(), Some("admin_proxy"));
|
||||
assert_eq!(decision.route_family.as_deref(), Some("system_manage"));
|
||||
assert_eq!(decision.route_kind.as_deref(), Some(expected_kind));
|
||||
assert_eq!(
|
||||
decision.auth_endpoint_signature.as_deref(),
|
||||
Some("admin:system")
|
||||
);
|
||||
assert!(!decision.is_execution_runtime_candidate());
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn classifies_admin_system_aws_regions_as_admin_proxy_route() {
|
||||
let headers = headers(&[]);
|
||||
|
||||
@@ -291,3 +291,86 @@ fn classifies_gemini_predict_long_running_as_video_route() {
|
||||
);
|
||||
assert!(decision.is_execution_runtime_candidate());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn classifies_antigravity_v1internal_control_plane_routes() {
|
||||
let headers = headers(&[
|
||||
("authorization", "Bearer ant-access-token"),
|
||||
("user-agent", "antigravity/cli/1.0.2 linux/arm64"),
|
||||
]);
|
||||
|
||||
for (path, route_kind) in [
|
||||
("/v1internal:loadCodeAssist", "load_code_assist"),
|
||||
("/v1internal:fetchAvailableModels", "fetch_available_models"),
|
||||
("/v1internal:fetchUserInfo", "fetch_user_info"),
|
||||
("/v1internal:fetchAdminControls", "fetch_admin_controls"),
|
||||
("/v1internal:setUserSettings", "set_user_settings"),
|
||||
("/v1internal:listExperiments", "list_experiments"),
|
||||
(
|
||||
"/v1internal:recordCodeAssistMetrics",
|
||||
"record_code_assist_metrics",
|
||||
),
|
||||
] {
|
||||
let uri: Uri = path.parse().expect("uri should parse");
|
||||
let decision = classify_control_route(&http::Method::POST, &uri, &headers)
|
||||
.expect("route should classify");
|
||||
|
||||
assert_eq!(decision.route_class.as_deref(), Some("ai_public"));
|
||||
assert_eq!(decision.route_family.as_deref(), Some("antigravity"));
|
||||
assert_eq!(decision.route_kind.as_deref(), Some(route_kind));
|
||||
assert_eq!(
|
||||
decision.request_auth_channel.as_deref(),
|
||||
Some("bearer_like")
|
||||
);
|
||||
assert_eq!(
|
||||
decision.auth_endpoint_signature.as_deref(),
|
||||
Some("antigravity:v1internal")
|
||||
);
|
||||
assert!(
|
||||
!decision.is_execution_runtime_candidate(),
|
||||
"control-plane route {path} must be handled by local facade before execution runtime"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn classifies_antigravity_stream_generate_content_as_execution_route() {
|
||||
let headers = headers(&[
|
||||
("authorization", "Bearer ant-access-token"),
|
||||
("user-agent", "antigravity/cli/1.0.2 linux/arm64"),
|
||||
]);
|
||||
let uri: Uri = "/v1internal:streamGenerateContent?alt=sse"
|
||||
.parse()
|
||||
.expect("uri should parse");
|
||||
let decision =
|
||||
classify_control_route(&http::Method::POST, &uri, &headers).expect("route should classify");
|
||||
|
||||
assert_eq!(decision.route_class.as_deref(), Some("ai_public"));
|
||||
assert_eq!(decision.route_family.as_deref(), Some("antigravity"));
|
||||
assert_eq!(
|
||||
decision.route_kind.as_deref(),
|
||||
Some("stream_generate_content")
|
||||
);
|
||||
assert_eq!(
|
||||
decision.request_auth_channel.as_deref(),
|
||||
Some("bearer_like")
|
||||
);
|
||||
assert_eq!(
|
||||
decision.auth_endpoint_signature.as_deref(),
|
||||
Some("antigravity:v1internal")
|
||||
);
|
||||
assert!(decision.is_execution_runtime_candidate());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_unknown_antigravity_v1internal_route() {
|
||||
let headers = headers(&[
|
||||
("authorization", "Bearer ant-access-token"),
|
||||
("user-agent", "antigravity/cli/1.0.2 linux/arm64"),
|
||||
]);
|
||||
let uri: Uri = "/v1internal:deleteEverything"
|
||||
.parse()
|
||||
.expect("uri should parse");
|
||||
|
||||
assert!(classify_control_route(&http::Method::POST, &uri, &headers).is_none());
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user