mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-09 10:57:03 +08:00
Expose the xAI Imagine image and video surfaces on top of the `xai` provider, and make the shared OpenAI video-task layer survive the production configuration they need. Native video requests live under /v1 (generations, edits, extensions, with /v1/videos as a creation alias that only selects xAI candidates); the OpenAI-compatible adapter stays under /openai/v1/videos and maps `seconds` / `size` onto numeric duration, aspect ratio and resolution. Clients receive an opaque Aether task ID scoped to the owning user; polling uses the upstream task ID and the original credential, and completed downloads fetch the returned media URL without forwarding provider authorization to the media host. Three fixes to the shared video layer are required for this to work outside tests: - OpenAI/xAI task persistence now supplies a stable 16-character short_id, which the PostgreSQL schema requires. Existing rows keep their original value across reconstruction, so no schema change or historical rewrite is needed. - Task retrieval and content downloads are admitted by the production GET execution gate, and reconstructed tasks resolve proxy nodes, system proxy defaults, tunnel affinity and transport profiles through the same deployment resolver used for creation. A configured proxy route no longer silently becomes a direct request after restart. - When the gateway also serves the frontend, /openai/v1/videos and its subpaths bypass the static SPA handler. Otherwise a video query returns HTTP 200 with text/html instead of the task JSON. Co-Authored-By: Claude Opus 5 <[email protected]>
213 lines
8.4 KiB
Rust
213 lines
8.4 KiB
Rust
use std::sync::{Arc, Mutex};
|
|
|
|
use axum::body::Body;
|
|
use axum::response::Response;
|
|
use axum::routing::any;
|
|
use axum::{extract::Request, Router};
|
|
use http::header::{HeaderName, HeaderValue};
|
|
use http::StatusCode;
|
|
|
|
use crate::constants::{
|
|
CONTROL_EXECUTED_HEADER, CONTROL_EXECUTE_FALLBACK_HEADER, EXECUTION_PATH_HEADER,
|
|
};
|
|
|
|
use super::{build_router, start_server};
|
|
|
|
#[tokio::test]
|
|
async fn gateway_hides_video_task_from_unauthenticated_caller_with_opt_in_headers() {
|
|
let execute_hits = Arc::new(Mutex::new(0usize));
|
|
let execute_hits_clone = Arc::clone(&execute_hits);
|
|
let public_hits = Arc::new(Mutex::new(0usize));
|
|
let public_hits_clone = Arc::clone(&public_hits);
|
|
|
|
let upstream = Router::new()
|
|
.route(
|
|
"/api/internal/gateway/execute-sync",
|
|
any(move |_request: Request| {
|
|
let execute_hits_inner = Arc::clone(&execute_hits_clone);
|
|
async move {
|
|
*execute_hits_inner.lock().expect("mutex should lock") += 1;
|
|
let mut response = Response::builder()
|
|
.status(StatusCode::OK)
|
|
.body(Body::from("{\"status\":\"queued\"}"))
|
|
.expect("response should build");
|
|
response.headers_mut().insert(
|
|
http::header::CONTENT_TYPE,
|
|
HeaderValue::from_static("application/json"),
|
|
);
|
|
response.headers_mut().insert(
|
|
HeaderName::from_static(CONTROL_EXECUTED_HEADER),
|
|
HeaderValue::from_static("true"),
|
|
);
|
|
response
|
|
}
|
|
}),
|
|
)
|
|
.route(
|
|
"/v1/videos/task-123",
|
|
any(move |_request: Request| {
|
|
let public_hits_inner = Arc::clone(&public_hits_clone);
|
|
async move {
|
|
*public_hits_inner.lock().expect("mutex should lock") += 1;
|
|
(StatusCode::IM_A_TEAPOT, Body::from("public-route-hit"))
|
|
}
|
|
}),
|
|
);
|
|
|
|
let (upstream_url, upstream_handle) = start_server(upstream).await;
|
|
let gateway = build_router().expect("gateway should build");
|
|
let (gateway_url, gateway_handle) = start_server(gateway).await;
|
|
|
|
let response = reqwest::Client::new()
|
|
.get(format!("{gateway_url}/v1/videos/task-123"))
|
|
.header(CONTROL_EXECUTE_FALLBACK_HEADER, "true")
|
|
.send()
|
|
.await
|
|
.expect("request should succeed");
|
|
|
|
assert_eq!(response.status(), StatusCode::NOT_FOUND);
|
|
let payload: serde_json::Value = response.json().await.expect("body should parse");
|
|
assert_eq!(payload, crate::video_tasks::not_found_body());
|
|
assert_eq!(*execute_hits.lock().expect("mutex should lock"), 0);
|
|
assert_eq!(*public_hits.lock().expect("mutex should lock"), 0);
|
|
|
|
gateway_handle.abort();
|
|
upstream_handle.abort();
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn gateway_hides_video_task_without_calling_public_or_control_upstream() {
|
|
let execute_hits = Arc::new(Mutex::new(0usize));
|
|
let execute_hits_clone = Arc::clone(&execute_hits);
|
|
let public_hits = Arc::new(Mutex::new(0usize));
|
|
let public_hits_clone = Arc::clone(&public_hits);
|
|
let public_execution_path = Arc::new(Mutex::new(None::<String>));
|
|
let public_execution_path_clone = Arc::clone(&public_execution_path);
|
|
|
|
let upstream = Router::new()
|
|
.route(
|
|
"/api/internal/gateway/execute-sync",
|
|
any(move |_request: Request| {
|
|
let execute_hits_inner = Arc::clone(&execute_hits_clone);
|
|
async move {
|
|
*execute_hits_inner.lock().expect("mutex should lock") += 1;
|
|
let mut response = Response::builder()
|
|
.status(StatusCode::OK)
|
|
.body(Body::from("{\"unexpected\":true}"))
|
|
.expect("response should build");
|
|
response.headers_mut().insert(
|
|
HeaderName::from_static(CONTROL_EXECUTED_HEADER),
|
|
HeaderValue::from_static("true"),
|
|
);
|
|
response
|
|
}
|
|
}),
|
|
)
|
|
.route(
|
|
"/v1/videos/task-123",
|
|
any(move |request: Request| {
|
|
let public_hits_inner = Arc::clone(&public_hits_clone);
|
|
let public_execution_path_inner = Arc::clone(&public_execution_path_clone);
|
|
async move {
|
|
*public_hits_inner.lock().expect("mutex should lock") += 1;
|
|
*public_execution_path_inner
|
|
.lock()
|
|
.expect("mutex should lock") = Some(
|
|
request
|
|
.headers()
|
|
.get(EXECUTION_PATH_HEADER)
|
|
.and_then(|value| value.to_str().ok())
|
|
.unwrap_or_default()
|
|
.to_string(),
|
|
);
|
|
(StatusCode::IM_A_TEAPOT, Body::from("public-route-hit"))
|
|
}
|
|
}),
|
|
);
|
|
|
|
let (upstream_url, upstream_handle) = start_server(upstream).await;
|
|
let gateway = build_router().expect("gateway should build");
|
|
let (gateway_url, gateway_handle) = start_server(gateway).await;
|
|
|
|
let response = reqwest::Client::new()
|
|
.get(format!("{gateway_url}/v1/videos/task-123"))
|
|
.header(CONTROL_EXECUTE_FALLBACK_HEADER, "true")
|
|
.send()
|
|
.await
|
|
.expect("request should succeed");
|
|
|
|
assert_eq!(response.status(), StatusCode::NOT_FOUND);
|
|
let payload: serde_json::Value = response.json().await.expect("body should parse");
|
|
assert_eq!(payload, crate::video_tasks::not_found_body());
|
|
assert_eq!(*execute_hits.lock().expect("mutex should lock"), 0);
|
|
assert_eq!(*public_hits.lock().expect("mutex should lock"), 0);
|
|
assert_eq!(
|
|
public_execution_path
|
|
.lock()
|
|
.expect("mutex should lock")
|
|
.clone()
|
|
.as_deref(),
|
|
None
|
|
);
|
|
|
|
gateway_handle.abort();
|
|
upstream_handle.abort();
|
|
}
|
|
|
|
#[tokio::test]
|
|
async fn gateway_hides_video_task_from_unauthenticated_caller_without_opt_in_headers() {
|
|
let execute_hits = Arc::new(Mutex::new(0usize));
|
|
let execute_hits_clone = Arc::clone(&execute_hits);
|
|
let public_hits = Arc::new(Mutex::new(0usize));
|
|
let public_hits_clone = Arc::clone(&public_hits);
|
|
|
|
let upstream = Router::new()
|
|
.route(
|
|
"/api/internal/gateway/execute-sync",
|
|
any(move |_request: Request| {
|
|
let execute_hits_inner = Arc::clone(&execute_hits_clone);
|
|
async move {
|
|
*execute_hits_inner.lock().expect("mutex should lock") += 1;
|
|
let mut response = Response::builder()
|
|
.status(StatusCode::OK)
|
|
.body(Body::from("{\"status\":\"queued\"}"))
|
|
.expect("response should build");
|
|
response.headers_mut().insert(
|
|
HeaderName::from_static(CONTROL_EXECUTED_HEADER),
|
|
HeaderValue::from_static("true"),
|
|
);
|
|
response
|
|
}
|
|
}),
|
|
)
|
|
.route(
|
|
"/v1/videos/task-123",
|
|
any(move |_request: Request| {
|
|
let public_hits_inner = Arc::clone(&public_hits_clone);
|
|
async move {
|
|
*public_hits_inner.lock().expect("mutex should lock") += 1;
|
|
(StatusCode::IM_A_TEAPOT, Body::from("public-route-hit"))
|
|
}
|
|
}),
|
|
);
|
|
|
|
let (upstream_url, upstream_handle) = start_server(upstream).await;
|
|
let gateway = build_router().expect("gateway should build");
|
|
let (gateway_url, gateway_handle) = start_server(gateway).await;
|
|
|
|
let response = reqwest::Client::new()
|
|
.get(format!("{gateway_url}/v1/videos/task-123"))
|
|
.send()
|
|
.await
|
|
.expect("request should succeed");
|
|
|
|
assert_eq!(response.status(), StatusCode::NOT_FOUND);
|
|
let payload: serde_json::Value = response.json().await.expect("body should parse");
|
|
assert_eq!(payload, crate::video_tasks::not_found_body());
|
|
assert_eq!(*execute_hits.lock().expect("mutex should lock"), 0);
|
|
assert_eq!(*public_hits.lock().expect("mutex should lock"), 0);
|
|
|
|
gateway_handle.abort();
|
|
upstream_handle.abort();
|
|
}
|