feat: 扩展 Rust gateway 全功能模块,新增 billing/crypto/wallet crate 及完整数据层

- 新增 aether-billing、aether-crypto、aether-wallet 独立 crate
- aether-data 扩展 repository 层:announcements、auth_modules、billing、
  candidate_selection、gemini_file_mappings、global_models、management_tokens、
  oauth_providers、proxy_nodes、quota、users、wallet 等模块
- aether-gateway 新增 api/auth/billing/control/middleware/scheduler/usage/
  video_tasks/hooks/maintenance/model_fetch/provider_transport 等功能模块
- 重构 executor decision 和 gateway state 为模块目录结构
- 新增 gateway router、frontdoor 路由层及对应测试
- Python 侧 API 路由重构,新增 compat/support 模块
- 前端 Logo 组件更新及 Provider 管理页面调整
This commit is contained in:
fawney19
2026-03-31 19:19:04 +08:00
parent b5a0070023
commit ddf18fed9a
690 changed files with 235085 additions and 16299 deletions
@@ -0,0 +1,114 @@
use std::sync::RwLock;
use async_trait::async_trait;
use super::types::{
AuthModuleReadRepository, AuthModuleWriteRepository, StoredLdapModuleConfig,
StoredOAuthProviderModuleConfig,
};
use crate::DataLayerError;
#[derive(Debug, Default)]
pub struct InMemoryAuthModuleReadRepository {
oauth_providers: RwLock<Vec<StoredOAuthProviderModuleConfig>>,
ldap_config: RwLock<Option<StoredLdapModuleConfig>>,
}
impl InMemoryAuthModuleReadRepository {
pub fn seed<I>(oauth_providers: I, ldap_config: Option<StoredLdapModuleConfig>) -> Self
where
I: IntoIterator<Item = StoredOAuthProviderModuleConfig>,
{
Self {
oauth_providers: RwLock::new(oauth_providers.into_iter().collect()),
ldap_config: RwLock::new(ldap_config),
}
}
}
#[async_trait]
impl AuthModuleReadRepository for InMemoryAuthModuleReadRepository {
async fn list_enabled_oauth_providers(
&self,
) -> Result<Vec<StoredOAuthProviderModuleConfig>, DataLayerError> {
Ok(self
.oauth_providers
.read()
.expect("auth module oauth provider repository lock")
.clone())
}
async fn get_ldap_config(&self) -> Result<Option<StoredLdapModuleConfig>, DataLayerError> {
Ok(self
.ldap_config
.read()
.expect("auth module ldap repository lock")
.clone())
}
}
#[async_trait]
impl AuthModuleWriteRepository for InMemoryAuthModuleReadRepository {
async fn upsert_ldap_config(
&self,
config: &StoredLdapModuleConfig,
) -> Result<Option<StoredLdapModuleConfig>, DataLayerError> {
self.ldap_config
.write()
.expect("auth module ldap repository lock")
.replace(config.clone());
Ok(Some(config.clone()))
}
}
#[cfg(test)]
mod tests {
use super::InMemoryAuthModuleReadRepository;
use crate::repository::auth_modules::{
AuthModuleReadRepository, StoredLdapModuleConfig, StoredOAuthProviderModuleConfig,
};
#[tokio::test]
async fn reads_seeded_auth_module_configs() {
let repository = InMemoryAuthModuleReadRepository::seed(
vec![StoredOAuthProviderModuleConfig::new(
"linuxdo".to_string(),
"Linux DO".to_string(),
"client-id".to_string(),
Some("encrypted".to_string()),
"https://example.com/callback".to_string(),
)
.expect("oauth provider should build")],
Some(StoredLdapModuleConfig {
server_url: "ldaps://ldap.example.com".to_string(),
bind_dn: "cn=admin,dc=example,dc=com".to_string(),
bind_password_encrypted: Some("encrypted-password".to_string()),
base_dn: "dc=example,dc=com".to_string(),
user_search_filter: Some("(uid={username})".to_string()),
username_attr: Some("uid".to_string()),
email_attr: Some("mail".to_string()),
display_name_attr: Some("displayName".to_string()),
is_enabled: true,
is_exclusive: false,
use_starttls: true,
connect_timeout: Some(10),
}),
);
let oauth = repository
.list_enabled_oauth_providers()
.await
.expect("oauth providers should load");
let ldap = repository
.get_ldap_config()
.await
.expect("ldap config should load");
assert_eq!(oauth.len(), 1);
assert_eq!(oauth[0].provider_type, "linuxdo");
assert_eq!(
ldap.expect("ldap config should exist").server_url,
"ldaps://ldap.example.com"
);
}
}
@@ -0,0 +1,10 @@
mod memory;
mod sql;
mod types;
pub use memory::InMemoryAuthModuleReadRepository;
pub use sql::{SqlxAuthModuleReadRepository, SqlxAuthModuleRepository};
pub use types::{
AuthModuleReadRepository, AuthModuleWriteRepository, StoredLdapModuleConfig,
StoredOAuthProviderModuleConfig,
};
@@ -0,0 +1,297 @@
use async_trait::async_trait;
use sqlx::{postgres::PgRow, PgPool, Row};
use super::types::{
AuthModuleReadRepository, AuthModuleWriteRepository, StoredLdapModuleConfig,
StoredOAuthProviderModuleConfig,
};
use crate::DataLayerError;
const LIST_ENABLED_OAUTH_PROVIDERS_SQL: &str = r#"
SELECT
provider_type,
display_name,
client_id,
client_secret_encrypted,
redirect_uri
FROM oauth_providers
WHERE is_enabled = TRUE
ORDER BY provider_type ASC
"#;
const GET_LDAP_CONFIG_SQL: &str = r#"
SELECT
server_url,
bind_dn,
bind_password_encrypted,
base_dn,
user_search_filter,
username_attr,
email_attr,
display_name_attr,
is_enabled,
is_exclusive,
use_starttls,
connect_timeout
FROM ldap_configs
ORDER BY id ASC
LIMIT 1
"#;
const UPDATE_LDAP_CONFIG_SQL: &str = r#"
UPDATE ldap_configs
SET
server_url = $1,
bind_dn = $2,
bind_password_encrypted = $3,
base_dn = $4,
user_search_filter = $5,
username_attr = $6,
email_attr = $7,
display_name_attr = $8,
is_enabled = $9,
is_exclusive = $10,
use_starttls = $11,
connect_timeout = $12,
updated_at = NOW()
WHERE id = (
SELECT id
FROM ldap_configs
ORDER BY id ASC
LIMIT 1
)
RETURNING
server_url,
bind_dn,
bind_password_encrypted,
base_dn,
user_search_filter,
username_attr,
email_attr,
display_name_attr,
is_enabled,
is_exclusive,
use_starttls,
connect_timeout
"#;
const INSERT_LDAP_CONFIG_SQL: &str = r#"
INSERT INTO ldap_configs (
server_url,
bind_dn,
bind_password_encrypted,
base_dn,
user_search_filter,
username_attr,
email_attr,
display_name_attr,
is_enabled,
is_exclusive,
use_starttls,
connect_timeout,
created_at,
updated_at
)
VALUES (
$1,
$2,
$3,
$4,
$5,
$6,
$7,
$8,
$9,
$10,
$11,
$12,
NOW(),
NOW()
)
RETURNING
server_url,
bind_dn,
bind_password_encrypted,
base_dn,
user_search_filter,
username_attr,
email_attr,
display_name_attr,
is_enabled,
is_exclusive,
use_starttls,
connect_timeout
"#;
#[derive(Debug, Clone)]
pub struct SqlxAuthModuleReadRepository {
pool: PgPool,
}
impl SqlxAuthModuleReadRepository {
pub fn new(pool: PgPool) -> Self {
Self { pool }
}
}
#[derive(Debug, Clone)]
pub struct SqlxAuthModuleRepository {
pool: PgPool,
}
impl SqlxAuthModuleRepository {
pub fn new(pool: PgPool) -> Self {
Self { pool }
}
}
#[async_trait]
impl AuthModuleReadRepository for SqlxAuthModuleReadRepository {
async fn list_enabled_oauth_providers(
&self,
) -> Result<Vec<StoredOAuthProviderModuleConfig>, DataLayerError> {
let rows = sqlx::query(LIST_ENABLED_OAUTH_PROVIDERS_SQL)
.fetch_all(&self.pool)
.await?;
rows.iter().map(map_oauth_row).collect()
}
async fn get_ldap_config(&self) -> Result<Option<StoredLdapModuleConfig>, DataLayerError> {
let row = sqlx::query(GET_LDAP_CONFIG_SQL)
.fetch_optional(&self.pool)
.await?;
row.as_ref().map(map_ldap_row).transpose()
}
}
#[async_trait]
impl AuthModuleReadRepository for SqlxAuthModuleRepository {
async fn list_enabled_oauth_providers(
&self,
) -> Result<Vec<StoredOAuthProviderModuleConfig>, DataLayerError> {
let rows = sqlx::query(LIST_ENABLED_OAUTH_PROVIDERS_SQL)
.fetch_all(&self.pool)
.await?;
rows.iter().map(map_oauth_row).collect()
}
async fn get_ldap_config(&self) -> Result<Option<StoredLdapModuleConfig>, DataLayerError> {
let row = sqlx::query(GET_LDAP_CONFIG_SQL)
.fetch_optional(&self.pool)
.await?;
row.as_ref().map(map_ldap_row).transpose()
}
}
#[async_trait]
impl AuthModuleWriteRepository for SqlxAuthModuleRepository {
async fn upsert_ldap_config(
&self,
config: &StoredLdapModuleConfig,
) -> Result<Option<StoredLdapModuleConfig>, DataLayerError> {
let updated = sqlx::query(UPDATE_LDAP_CONFIG_SQL)
.bind(&config.server_url)
.bind(&config.bind_dn)
.bind(config.bind_password_encrypted.as_deref())
.bind(&config.base_dn)
.bind(config.user_search_filter.as_deref())
.bind(config.username_attr.as_deref())
.bind(config.email_attr.as_deref())
.bind(config.display_name_attr.as_deref())
.bind(config.is_enabled)
.bind(config.is_exclusive)
.bind(config.use_starttls)
.bind(config.connect_timeout)
.fetch_optional(&self.pool)
.await?;
if let Some(row) = updated.as_ref() {
return map_ldap_row(row).map(Some);
}
let inserted = sqlx::query(INSERT_LDAP_CONFIG_SQL)
.bind(&config.server_url)
.bind(&config.bind_dn)
.bind(config.bind_password_encrypted.as_deref())
.bind(&config.base_dn)
.bind(config.user_search_filter.as_deref())
.bind(config.username_attr.as_deref())
.bind(config.email_attr.as_deref())
.bind(config.display_name_attr.as_deref())
.bind(config.is_enabled)
.bind(config.is_exclusive)
.bind(config.use_starttls)
.bind(config.connect_timeout)
.fetch_optional(&self.pool)
.await?;
inserted.as_ref().map(map_ldap_row).transpose()
}
}
fn map_oauth_row(row: &PgRow) -> Result<StoredOAuthProviderModuleConfig, DataLayerError> {
StoredOAuthProviderModuleConfig::new(
row.try_get("provider_type")?,
row.try_get("display_name")?,
row.try_get("client_id")?,
row.try_get("client_secret_encrypted")?,
row.try_get("redirect_uri")?,
)
}
fn map_ldap_row(row: &PgRow) -> Result<StoredLdapModuleConfig, DataLayerError> {
Ok(StoredLdapModuleConfig {
server_url: row.try_get("server_url")?,
bind_dn: row.try_get("bind_dn")?,
bind_password_encrypted: row.try_get("bind_password_encrypted")?,
base_dn: row.try_get("base_dn")?,
user_search_filter: row.try_get("user_search_filter")?,
username_attr: row.try_get("username_attr")?,
email_attr: row.try_get("email_attr")?,
display_name_attr: row.try_get("display_name_attr")?,
is_enabled: row.try_get("is_enabled")?,
is_exclusive: row.try_get("is_exclusive")?,
use_starttls: row.try_get("use_starttls")?,
connect_timeout: row.try_get("connect_timeout")?,
})
}
#[cfg(test)]
mod tests {
use super::{SqlxAuthModuleReadRepository, SqlxAuthModuleRepository};
use crate::postgres::{PostgresPoolConfig, PostgresPoolFactory};
#[tokio::test]
async fn repository_constructs_from_lazy_pool() {
let factory = PostgresPoolFactory::new(PostgresPoolConfig {
database_url: "postgres://localhost/aether".to_string(),
min_connections: 1,
max_connections: 4,
acquire_timeout_ms: 1_000,
idle_timeout_ms: 5_000,
max_lifetime_ms: 30_000,
statement_cache_capacity: 64,
require_ssl: false,
})
.expect("factory should build");
let pool = factory.connect_lazy().expect("pool should build");
let _repository = SqlxAuthModuleReadRepository::new(pool);
}
#[tokio::test]
async fn writable_repository_constructs_from_lazy_pool() {
let factory = PostgresPoolFactory::new(PostgresPoolConfig {
database_url: "postgres://localhost/aether".to_string(),
min_connections: 1,
max_connections: 4,
acquire_timeout_ms: 1_000,
idle_timeout_ms: 5_000,
max_lifetime_ms: 30_000,
statement_cache_capacity: 64,
require_ssl: false,
})
.expect("factory should build");
let pool = factory.connect_lazy().expect("pool should build");
let _repository = SqlxAuthModuleRepository::new(pool);
}
}
@@ -0,0 +1,73 @@
use async_trait::async_trait;
#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct StoredOAuthProviderModuleConfig {
pub provider_type: String,
pub display_name: String,
pub client_id: String,
pub client_secret_encrypted: Option<String>,
pub redirect_uri: String,
}
impl StoredOAuthProviderModuleConfig {
pub fn new(
provider_type: String,
display_name: String,
client_id: String,
client_secret_encrypted: Option<String>,
redirect_uri: String,
) -> Result<Self, crate::DataLayerError> {
if provider_type.trim().is_empty() {
return Err(crate::DataLayerError::UnexpectedValue(
"oauth_providers.provider_type is empty".to_string(),
));
}
if display_name.trim().is_empty() {
return Err(crate::DataLayerError::UnexpectedValue(
"oauth_providers.display_name is empty".to_string(),
));
}
Ok(Self {
provider_type,
display_name,
client_id,
client_secret_encrypted,
redirect_uri,
})
}
}
#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct StoredLdapModuleConfig {
pub server_url: String,
pub bind_dn: String,
pub bind_password_encrypted: Option<String>,
pub base_dn: String,
pub user_search_filter: Option<String>,
pub username_attr: Option<String>,
pub email_attr: Option<String>,
pub display_name_attr: Option<String>,
pub is_enabled: bool,
pub is_exclusive: bool,
pub use_starttls: bool,
pub connect_timeout: Option<i32>,
}
#[async_trait]
pub trait AuthModuleReadRepository: Send + Sync {
async fn list_enabled_oauth_providers(
&self,
) -> Result<Vec<StoredOAuthProviderModuleConfig>, crate::DataLayerError>;
async fn get_ldap_config(
&self,
) -> Result<Option<StoredLdapModuleConfig>, crate::DataLayerError>;
}
#[async_trait]
pub trait AuthModuleWriteRepository: Send + Sync {
async fn upsert_ldap_config(
&self,
config: &StoredLdapModuleConfig,
) -> Result<Option<StoredLdapModuleConfig>, crate::DataLayerError>;
}