mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-09 10:57:03 +08:00
fix: exempt admins from default user group limits
This commit is contained in:
@@ -364,6 +364,9 @@ impl RpmPlan {
|
||||
if auth.local_rejection.is_some() || auth.user_id.is_empty() || auth.api_key_id.is_empty() {
|
||||
return None;
|
||||
}
|
||||
if auth.admin_bypass_limits {
|
||||
return None;
|
||||
}
|
||||
|
||||
let now_ts = current_unix_secs();
|
||||
let bucket = config.current_bucket(now_ts);
|
||||
@@ -488,6 +491,7 @@ mod tests {
|
||||
user_rate_limit: Some(1),
|
||||
api_key_rate_limit: Some(10),
|
||||
api_key_is_standalone: false,
|
||||
admin_bypass_limits: false,
|
||||
local_rejection: None,
|
||||
allowed_models: None,
|
||||
});
|
||||
@@ -526,6 +530,7 @@ mod tests {
|
||||
user_rate_limit: None,
|
||||
api_key_rate_limit: Some(10),
|
||||
api_key_is_standalone: false,
|
||||
admin_bypass_limits: false,
|
||||
local_rejection: None,
|
||||
allowed_models: None,
|
||||
});
|
||||
@@ -550,6 +555,39 @@ mod tests {
|
||||
}
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn limiter_skips_admin_bypass_context() {
|
||||
let limiter = FrontdoorUserRpmLimiter::new(FrontdoorUserRpmConfig::new(60, 120, false))
|
||||
.with_system_default_limit_for_tests(1);
|
||||
let decision = sample_decision(GatewayControlAuthContext {
|
||||
user_id: "admin-1".to_string(),
|
||||
api_key_id: "key-1".to_string(),
|
||||
username: None,
|
||||
api_key_name: None,
|
||||
balance_remaining: Some(10.0),
|
||||
access_allowed: true,
|
||||
user_rate_limit: Some(1),
|
||||
api_key_rate_limit: Some(1),
|
||||
api_key_is_standalone: false,
|
||||
admin_bypass_limits: true,
|
||||
local_rejection: None,
|
||||
allowed_models: None,
|
||||
});
|
||||
let state = AppState::new().expect("state should build for tests");
|
||||
|
||||
let first = limiter
|
||||
.check_and_consume(&state, Some(&decision))
|
||||
.await
|
||||
.expect("check should succeed");
|
||||
let second = limiter
|
||||
.check_and_consume(&state, Some(&decision))
|
||||
.await
|
||||
.expect("check should succeed");
|
||||
|
||||
assert_eq!(first, FrontdoorUserRpmOutcome::NotApplicable);
|
||||
assert_eq!(second, FrontdoorUserRpmOutcome::NotApplicable);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn config_normalizes_non_positive_values() {
|
||||
let config = FrontdoorUserRpmConfig::new(0, 0, true);
|
||||
@@ -574,6 +612,7 @@ mod tests {
|
||||
user_rate_limit: Some(1),
|
||||
api_key_rate_limit: Some(10),
|
||||
api_key_is_standalone: false,
|
||||
admin_bypass_limits: false,
|
||||
local_rejection: None,
|
||||
allowed_models: None,
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user