mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-10 11:19:50 +08:00
fix(kiro,pool,model): 对齐 Kiro 管理链路并修复全局模型删除行为 (#305)
* feat(pool): 号池支持跳过额度耗尽账号 - 新增 pool_advanced.skip_exhausted_accounts 开关及高级设置 UI, 默认关闭并兼容旧配置 - 为 Codex/Kiro 增加额度耗尽判定, 接入请求侧候选跳过并新增 account_quota_exhausted skip reason - 号池列表将额度耗尽账号标记为 blocked/额度耗尽, 并补充前后端相关测试 * fix(kiro): 对齐账号管理与 provider-query 的 Rust 行为 - 修复 Kiro 单条导入误走 import-refresh-token 的前端分流, 并为误用路径返回明确错误提示 - 为 Kiro 导入与本地请求链补齐 bearer 兼容, 同步放开账号启停等 Key 更新操作的 auth_type 校验 - 实现 Kiro provider-query 本地模型测试与 failover 执行链, 并修复结果弹窗在无 trace 时无法展示 attempts/响应体的问题 * fix(model): 删除全局模型时级联清理关联提供商模型 - 对齐 Python 版本删除逻辑, GlobalModel 删除前先在事务内清理关联的 Provider Model 记录 - 修复已绑定 Provider 的模型在 Rust SQL 仓库下会被外键约束拦住、无法正常删除的问题 - 增加管理端回归测试, 覆盖绑定 Provider Model 的 GlobalModel 删除场景 * fix(kiro,ci): 恢复 Kiro OAuth 持久化并修复 Rust CI * Fix oauth-managed provider key semantics --------- Co-authored-by: fawney19 <[email protected]>
This commit is contained in:
@@ -13,8 +13,8 @@ pub(crate) fn normalize_provider_type_input(value: &str) -> Result<String, Strin
|
||||
pub(crate) fn normalize_auth_type(value: Option<&str>) -> Result<String, String> {
|
||||
let auth_type = value.unwrap_or("api_key").trim().to_ascii_lowercase();
|
||||
match auth_type.as_str() {
|
||||
"api_key" | "service_account" | "oauth" => Ok(auth_type),
|
||||
_ => Err("auth_type 仅支持 api_key / service_account / oauth".to_string()),
|
||||
"api_key" | "service_account" | "oauth" | "bearer" => Ok(auth_type),
|
||||
_ => Err("auth_type 仅支持 api_key / service_account / oauth / bearer".to_string()),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -63,7 +63,7 @@ pub(crate) fn validate_vertex_api_formats(
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::normalize_pool_advanced_config;
|
||||
use super::{normalize_auth_type, normalize_pool_advanced_config};
|
||||
use serde_json::json;
|
||||
|
||||
#[test]
|
||||
@@ -85,4 +85,12 @@ mod tests {
|
||||
"pool_advanced 必须是 JSON 对象"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn normalize_auth_type_supports_bearer() {
|
||||
assert_eq!(
|
||||
normalize_auth_type(Some("bearer")).expect("bearer should normalize"),
|
||||
"bearer"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -8,17 +8,37 @@ fn normalize_reveal_auth_type(value: &str) -> &str {
|
||||
|
||||
use crate::handlers::admin::request::AdminAppState;
|
||||
use crate::handlers::admin::shared::parse_catalog_auth_config_json;
|
||||
use crate::provider_key_auth::provider_key_auth_semantics;
|
||||
use aether_data_contracts::repository::provider_catalog::StoredProviderCatalogKey;
|
||||
use chrono::{SecondsFormat, Utc};
|
||||
use serde_json::json;
|
||||
|
||||
fn reveal_provider_type_from_auth_config(
|
||||
auth_config: Option<&serde_json::Map<String, serde_json::Value>>,
|
||||
) -> String {
|
||||
auth_config
|
||||
.and_then(|value| value.get("provider_type"))
|
||||
.and_then(serde_json::Value::as_str)
|
||||
.map(str::trim)
|
||||
.filter(|value| !value.is_empty())
|
||||
.unwrap_or_default()
|
||||
.to_string()
|
||||
}
|
||||
|
||||
pub(crate) fn build_admin_reveal_key_payload(
|
||||
state: &AdminAppState<'_>,
|
||||
key: &StoredProviderCatalogKey,
|
||||
) -> Result<serde_json::Value, String> {
|
||||
let auth_type = normalize_reveal_auth_type(&key.auth_type);
|
||||
let parsed_auth_config = state.parse_catalog_auth_config_json(key);
|
||||
let provider_type = reveal_provider_type_from_auth_config(parsed_auth_config.as_ref());
|
||||
let auth_semantics = provider_key_auth_semantics(key, provider_type.as_str());
|
||||
let auth_type = if auth_semantics.oauth_managed() {
|
||||
"oauth"
|
||||
} else {
|
||||
normalize_reveal_auth_type(&key.auth_type)
|
||||
};
|
||||
if matches!(auth_type, "service_account") {
|
||||
if let Some(auth_config) = state.parse_catalog_auth_config_json(key) {
|
||||
if let Some(auth_config) = parsed_auth_config {
|
||||
return Ok(json!({
|
||||
"auth_type": auth_type,
|
||||
"auth_config": auth_config,
|
||||
@@ -92,11 +112,6 @@ pub(crate) async fn build_admin_export_key_payload(
|
||||
state: &AdminAppState<'_>,
|
||||
key: &StoredProviderCatalogKey,
|
||||
) -> Result<serde_json::Value, String> {
|
||||
let auth_type = normalize_reveal_auth_type(&key.auth_type);
|
||||
if auth_type != "oauth" {
|
||||
return Err("仅 OAuth 类型的 Key 支持导出".to_string());
|
||||
}
|
||||
|
||||
let ciphertext = key
|
||||
.encrypted_auth_config
|
||||
.as_deref()
|
||||
@@ -136,6 +151,9 @@ pub(crate) async fn build_admin_export_key_payload(
|
||||
.map(|provider| provider.provider_type)
|
||||
.unwrap_or_default()
|
||||
};
|
||||
if !provider_key_auth_semantics(key, provider_type.as_str()).can_export_oauth() {
|
||||
return Err("仅 OAuth 管理账号支持导出".to_string());
|
||||
}
|
||||
|
||||
let mut payload =
|
||||
provider_oauth_export_payload(&provider_type, &auth_config, key.upstream_metadata.as_ref());
|
||||
|
||||
Reference in New Issue
Block a user