feat(gateway): harden failover and payload handling

Retry pre-response transport failures across candidates with an explicit stop policy, and propagate end-to-end timing into usage records and UI diagnostics.

Remove legacy body, import, cookie, PII, and tunnel replay caps while preserving optional operator-configured gateway limits.
This commit is contained in:
elky
2026-07-30 01:03:27 +08:00
parent a97acc07fc
commit a04673a90d
80 changed files with 3640 additions and 1236 deletions
+1 -1
View File
@@ -62,7 +62,7 @@ impl ResourceBudget {
ResourceClass::Interactive => Self::interactive(),
ResourceClass::Streaming => Self::streaming(),
ResourceClass::Upload => Self {
body_bytes: 64 * 1024 * 1024,
body_bytes: 0,
..Self::interactive()
},
ResourceClass::Background => Self {
@@ -61,4 +61,17 @@ mod tests {
AdmissionDecision::Reject(AdmissionRejectReason::InvalidRequest)
);
}
#[test]
fn default_policy_admits_uploads_above_the_legacy_body_limit() {
let decision = DefaultAdmissionPolicy.decide(AdmissionRequest {
trace_id: "trace-upload",
class: ResourceClass::Upload,
body_bytes: 64 * 1024 * 1024 + 1,
});
let AdmissionDecision::Admit(budget) = decision else {
panic!("upload body should be admitted without a size limit");
};
assert_eq!(budget.body_bytes, 0);
}
}