mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-08 10:27:46 +08:00
fix(ci): stabilize cross-platform workflow checks
This commit is contained in:
@@ -2828,12 +2828,14 @@ async fn gateway_handles_admin_keys_grouped_by_format_locally_with_trusted_admin
|
||||
.expect("Agent Identity auth config should encrypt"),
|
||||
);
|
||||
|
||||
let mut codex_provider = sample_provider("provider-codex", "codex", 30);
|
||||
codex_provider.provider_type = "codex".to_string();
|
||||
let provider_catalog_repository = Arc::new(SummaryNullingProviderCatalogReadRepository::seed(
|
||||
vec![
|
||||
sample_provider("provider-openai", "openai", 10),
|
||||
sample_provider("provider-claude", "claude", 20)
|
||||
.with_transport_fields(false, false, true, None, None, None, None, None, None),
|
||||
sample_provider("provider-codex", "codex", 30),
|
||||
codex_provider,
|
||||
],
|
||||
vec![
|
||||
sample_endpoint(
|
||||
|
||||
@@ -474,12 +474,19 @@ async fn gateway_auto_removes_codex_key_when_quota_proves_oauth_invalid() {
|
||||
"stale-access-token",
|
||||
);
|
||||
key.auth_type = "oauth".to_string();
|
||||
key.expires_at_unix_secs = Some(1);
|
||||
key.expires_at_unix_secs = Some(4_102_444_800);
|
||||
key.oauth_invalid_at_unix_secs = Some(1);
|
||||
key.oauth_invalid_reason = Some(
|
||||
"[REFRESH_FAILED] Token 续期失败 (401): refresh_token 无效、已过期或已撤销,请重新登录授权"
|
||||
.to_string(),
|
||||
);
|
||||
key.encrypted_auth_config = Some(
|
||||
encrypt_python_fernet_plaintext(
|
||||
DEVELOPMENT_ENCRYPTION_KEY,
|
||||
r#"{"provider_type":"codex","refresh_token":"invalid-refresh-token","expires_at":4102444800}"#,
|
||||
)
|
||||
.expect("auth config should encrypt"),
|
||||
);
|
||||
|
||||
let provider_catalog_repository = Arc::new(InMemoryProviderCatalogReadRepository::seed(
|
||||
vec![provider],
|
||||
@@ -521,7 +528,7 @@ async fn gateway_auto_removes_codex_key_when_quota_proves_oauth_invalid() {
|
||||
let payload: serde_json::Value = response.json().await.expect("json body should parse");
|
||||
assert_eq!(payload["success"], 0);
|
||||
assert_eq!(payload["failed"], 1);
|
||||
assert_eq!(payload["auto_removed"], 1);
|
||||
assert_eq!(payload["auto_removed"], 1, "payload={payload}");
|
||||
assert_eq!(payload["results"][0]["status"], "auth_invalid");
|
||||
assert_eq!(payload["results"][0]["auto_removed"], true);
|
||||
|
||||
|
||||
@@ -152,25 +152,33 @@ fn sample_kiro_device_access_token_without_email() -> String {
|
||||
}
|
||||
|
||||
fn sample_codex_access_token_with_profile_email(email: &str, account_id: &str) -> String {
|
||||
sample_codex_access_token_with_profile_email_and_expiry(email, account_id, Some(2_000_000_000))
|
||||
}
|
||||
|
||||
fn sample_codex_access_token_with_profile_email_and_expiry(
|
||||
email: &str,
|
||||
account_id: &str,
|
||||
expires_at: Option<u64>,
|
||||
) -> String {
|
||||
use base64::Engine as _;
|
||||
|
||||
let header =
|
||||
base64::engine::general_purpose::URL_SAFE_NO_PAD.encode(r#"{"alg":"none","typ":"JWT"}"#);
|
||||
let payload = base64::engine::general_purpose::URL_SAFE_NO_PAD.encode(
|
||||
json!({
|
||||
"iss": "https://auth.openai.com",
|
||||
"aud": ["https://api.openai.com/v1"],
|
||||
"exp": 2_000_000_000u64,
|
||||
"https://api.openai.com/profile": {
|
||||
"email": email,
|
||||
"email_verified": true,
|
||||
},
|
||||
"https://api.openai.com/auth": {
|
||||
"chatgpt_account_id": account_id,
|
||||
},
|
||||
})
|
||||
.to_string(),
|
||||
);
|
||||
let mut claims = json!({
|
||||
"iss": "https://auth.openai.com",
|
||||
"aud": ["https://api.openai.com/v1"],
|
||||
"https://api.openai.com/profile": {
|
||||
"email": email,
|
||||
"email_verified": true,
|
||||
},
|
||||
"https://api.openai.com/auth": {
|
||||
"chatgpt_account_id": account_id,
|
||||
},
|
||||
});
|
||||
if let Some(expires_at) = expires_at {
|
||||
claims["exp"] = json!(expires_at);
|
||||
}
|
||||
let payload = base64::engine::general_purpose::URL_SAFE_NO_PAD.encode(claims.to_string());
|
||||
format!("{header}.{payload}.sig")
|
||||
}
|
||||
|
||||
@@ -4352,6 +4360,11 @@ fn gateway_imports_codex_access_token_with_payload_expires_at_when_token_has_no_
|
||||
}
|
||||
|
||||
async fn gateway_imports_codex_access_token_with_payload_expires_at_when_token_has_no_exp_impl() {
|
||||
let access_token = sample_codex_access_token_with_profile_email_and_expiry(
|
||||
"[email protected]",
|
||||
"acct-opaque-123",
|
||||
None,
|
||||
);
|
||||
let mut provider = sample_provider("provider-codex", "codex", 10);
|
||||
provider.provider_type = "codex".to_string();
|
||||
let endpoint = sample_endpoint(
|
||||
@@ -4387,7 +4400,7 @@ async fn gateway_imports_codex_access_token_with_payload_expires_at_when_token_h
|
||||
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
|
||||
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
|
||||
.json(&json!({
|
||||
"access_token": "opaque-codex-access-token",
|
||||
"access_token": access_token,
|
||||
"expiresAt": 2_100_000_000u64,
|
||||
"name": "temporary-codex-opaque-access-token",
|
||||
}))
|
||||
@@ -7763,14 +7776,14 @@ async fn gateway_consecutive_manual_oauth_refresh_uses_rotated_refresh_token_imp
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn gateway_concurrent_manual_oauth_refresh_uses_rotated_refresh_token_after_lock_wait() {
|
||||
fn gateway_concurrent_manual_oauth_refresh_reuses_winner_after_lock_wait() {
|
||||
run_admin_oauth_test(
|
||||
"gateway_concurrent_manual_oauth_refresh_uses_rotated_refresh_token_after_lock_wait",
|
||||
gateway_concurrent_manual_oauth_refresh_uses_rotated_refresh_token_after_lock_wait_impl,
|
||||
"gateway_concurrent_manual_oauth_refresh_reuses_winner_after_lock_wait",
|
||||
gateway_concurrent_manual_oauth_refresh_reuses_winner_after_lock_wait_impl,
|
||||
);
|
||||
}
|
||||
|
||||
async fn gateway_concurrent_manual_oauth_refresh_uses_rotated_refresh_token_after_lock_wait_impl() {
|
||||
async fn gateway_concurrent_manual_oauth_refresh_reuses_winner_after_lock_wait_impl() {
|
||||
let refresh_request_bodies = Arc::new(Mutex::new(Vec::<String>::new()));
|
||||
let refresh_request_bodies_clone = Arc::clone(&refresh_request_bodies);
|
||||
let execution_runtime = Router::new().route(
|
||||
@@ -7963,17 +7976,12 @@ async fn gateway_concurrent_manual_oauth_refresh_uses_rotated_refresh_token_afte
|
||||
.lock()
|
||||
.expect("mutex should lock")
|
||||
.clone();
|
||||
assert_eq!(bodies.len(), 2);
|
||||
assert_eq!(bodies.len(), 1);
|
||||
assert!(
|
||||
bodies[0].contains("refresh_token=old-codex-refresh-token"),
|
||||
"unexpected first refresh body: {}",
|
||||
bodies[0]
|
||||
);
|
||||
assert!(
|
||||
bodies[1].contains("refresh_token=rotated-codex-refresh-token"),
|
||||
"unexpected second refresh body: {}",
|
||||
bodies[1]
|
||||
);
|
||||
|
||||
let stored_key = provider_catalog_repository
|
||||
.list_keys_by_ids(&["key-codex-oauth-concurrent-refresh".to_string()])
|
||||
@@ -7992,10 +8000,7 @@ async fn gateway_concurrent_manual_oauth_refresh_uses_rotated_refresh_token_afte
|
||||
.expect("auth config should decrypt");
|
||||
let auth_config: serde_json::Value =
|
||||
serde_json::from_str(&decrypted_auth_config).expect("auth config should parse");
|
||||
assert_eq!(
|
||||
auth_config["refresh_token"],
|
||||
"rotated-codex-refresh-token-2"
|
||||
);
|
||||
assert_eq!(auth_config["refresh_token"], "rotated-codex-refresh-token");
|
||||
|
||||
gateway_handle.abort();
|
||||
execution_runtime_handle.abort();
|
||||
|
||||
Reference in New Issue
Block a user