fix: fail-closed internal identity and preserve billing error semantics
Build / build (push) Has been cancelled
Docker / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
Build / build (push) Has been cancelled
Docker / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
- Gateway internal identity: when a service token is configured, reject wrong/missing tokens even from loopback (closes SSRF/local bypass). - Terminal metering: classified AgentControlError propagates without retry; exhausted retries raise BILLING_UNAVAILABLE instead of a generic RuntimeError, keeping error attribution accurate.
This commit is contained in:
@@ -37,10 +37,11 @@ class _FakeClient:
|
||||
async def __aexit__(self, *exc):
|
||||
return False
|
||||
|
||||
def stream(self, method, url, json=None):
|
||||
def stream(self, method, url, json=None, headers=None):
|
||||
assert method == "POST"
|
||||
assert url.endswith("/api/internal/recoverable-runs/model/stream")
|
||||
self.sent = json
|
||||
self.headers = headers
|
||||
return _FakeStream(self._lines)
|
||||
|
||||
|
||||
@@ -58,6 +59,7 @@ def test_runtime_error_repr_preserves_only_stable_code():
|
||||
|
||||
@pytest.mark.anyio
|
||||
async def test_astream_yields_chunks_from_sse(monkeypatch):
|
||||
monkeypatch.setenv("AI4SCI_EVO_RUNTIME_GRANT_SECRET", "runtime-service-secret")
|
||||
model = GatewayProxyChatModel(
|
||||
gateway_url="http://gw",
|
||||
run_id="run-1",
|
||||
@@ -75,6 +77,7 @@ async def test_astream_yields_chunks_from_sse(monkeypatch):
|
||||
chunks = [c async for c in model._astream([HumanMessage(content="hi")])]
|
||||
|
||||
assert fake.sent["stream"] is True
|
||||
assert fake.headers == {"X-Ai4Sci-Service-Token": "runtime-service-secret"}
|
||||
assert len(chunks) == 2
|
||||
assert chunks[0].message.content == "hello"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user