Files
EvoScientist-Multi/EvoScientist/internal_service.py
T
m4 561e161123
Build / build (push) Has been cancelled
Docker / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
fix: fail-closed internal identity and preserve billing error semantics
- Gateway internal identity: when a service token is configured, reject
  wrong/missing tokens even from loopback (closes SSRF/local bypass).
- Terminal metering: classified AgentControlError propagates without
  retry; exhausted retries raise BILLING_UNAVAILABLE instead of a
  generic RuntimeError, keeping error attribution accurate.
2026-09-03 18:45:31 +08:00

18 lines
472 B
Python

"""Authentication headers for LangGraph-to-Gateway internal calls."""
from __future__ import annotations
import os
def internal_service_token() -> str:
return (
os.environ.get("EVOSCIENTIST_BACKEND_SERVICE_TOKEN", "").strip()
or os.environ.get("AI4SCI_EVO_RUNTIME_GRANT_SECRET", "").strip()
)
def internal_service_headers() -> dict[str, str]:
token = internal_service_token()
return {"X-Ai4Sci-Service-Token": token} if token else {}