fix(kiro,pool,model): 对齐 Kiro 管理链路并修复全局模型删除行为 (#305)

* feat(pool): 号池支持跳过额度耗尽账号

- 新增 pool_advanced.skip_exhausted_accounts 开关及高级设置 UI, 默认关闭并兼容旧配置
- 为 Codex/Kiro 增加额度耗尽判定, 接入请求侧候选跳过并新增 account_quota_exhausted skip reason
- 号池列表将额度耗尽账号标记为 blocked/额度耗尽, 并补充前后端相关测试

* fix(kiro): 对齐账号管理与 provider-query 的 Rust 行为

- 修复 Kiro 单条导入误走 import-refresh-token 的前端分流, 并为误用路径返回明确错误提示
- 为 Kiro 导入与本地请求链补齐 bearer 兼容, 同步放开账号启停等 Key 更新操作的 auth_type 校验
- 实现 Kiro provider-query 本地模型测试与 failover 执行链, 并修复结果弹窗在无 trace 时无法展示 attempts/响应体的问题

* fix(model): 删除全局模型时级联清理关联提供商模型

- 对齐 Python 版本删除逻辑, GlobalModel 删除前先在事务内清理关联的 Provider Model 记录
- 修复已绑定 Provider 的模型在 Rust SQL 仓库下会被外键约束拦住、无法正常删除的问题
- 增加管理端回归测试, 覆盖绑定 Provider Model 的 GlobalModel 删除场景

* fix(kiro,ci): 恢复 Kiro OAuth 持久化并修复 Rust CI

* Fix oauth-managed provider key semantics

---------

Co-authored-by: fawney19 <elky0401@gmail.com>
This commit is contained in:
Entropy.Xu
2026-04-17 12:57:06 +08:00
committed by GitHub
parent 96a25d058b
commit ac1a126756
43 changed files with 2909 additions and 168 deletions

View File

@@ -53,12 +53,7 @@ pub fn resolve_local_kiro_bearer_auth(
if transport.key.decrypted_auth_config.is_some() {
return None;
}
if !transport
.key
.auth_type
.trim()
.eq_ignore_ascii_case("bearer")
{
if !kiro_auth_type_supported(transport.key.auth_type.as_str()) {
return None;
}
@@ -90,12 +85,7 @@ pub fn resolve_local_kiro_request_auth(
{
return None;
}
if !transport
.key
.auth_type
.trim()
.eq_ignore_ascii_case("bearer")
{
if !kiro_auth_type_supported(transport.key.auth_type.as_str()) {
return None;
}
@@ -137,15 +127,18 @@ pub fn supports_local_kiro_request_auth_resolution(
.provider_type
.trim()
.eq_ignore_ascii_case(PROVIDER_TYPE)
&& transport
.key
.auth_type
.trim()
.eq_ignore_ascii_case("bearer")
&& kiro_auth_type_supported(transport.key.auth_type.as_str())
&& auth_config.can_refresh_access_token()
})
}
fn kiro_auth_type_supported(auth_type: &str) -> bool {
matches!(
auth_type.trim().to_ascii_lowercase().as_str(),
"bearer" | "oauth"
)
}
#[cfg(test)]
mod tests {
use super::super::super::snapshot::{
@@ -235,6 +228,27 @@ mod tests {
assert!(resolve_local_kiro_bearer_auth(&transport).is_none());
}
#[test]
fn resolves_request_auth_when_legacy_oauth_auth_type_is_used() {
let mut transport = sample_transport();
transport.key.auth_type = "oauth".to_string();
transport.key.decrypted_api_key = "__placeholder__".to_string();
transport.key.decrypted_auth_config = Some(
r#"{
"access_token":"cached-token",
"refresh_token":"rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr",
"machine_id":"123e4567-e89b-12d3-a456-426614174000",
"api_region":"us-west-2"
}"#
.to_string(),
);
let auth = resolve_local_kiro_request_auth(&transport)
.expect("request auth should resolve from legacy oauth auth_type");
assert_eq!(auth.value, "Bearer cached-token");
assert!(supports_local_kiro_request_auth_resolution(&transport));
}
#[test]
fn resolves_request_auth_from_cached_access_token() {
let mut transport = sample_transport();