d364473620
vertex, bedrock and copilot-acp each overrode ProviderProfile.fetch_models with an identical `return None`, and the overrides could not simply be deleted because the base implementation derives a URL from base_url and would GET e.g. bedrock-runtime.../models or acp://copilot/models. ProviderProfile now carries `supports_model_listing` (default True); the base fetch_models returns None before touching the network when it is False, and the three SDK/subprocess-backed profiles set it in their constructors instead of overriding. Separately, two catalog GETs still went through bare urllib.request.urlopen: commandcode's fetch_models and hermes_cli.models._fetch_ai_gateway_models (which sends the AI Gateway bearer). Both now use the redirect-safe open_credentialed_url path (_urlopen_model_catalog_request in models.py, also applied to the unauthenticated fetch_ai_gateway_models for consistency). This is a security behavior change: a cross-origin redirect from either endpoint no longer forwards the Authorization/attribution headers to the redirect target. The AI Gateway tests that patched the global urlopen are repointed at hermes_cli.models._urlopen_model_catalog_request (the seam tests/hermes_cli/test_models.py already uses), the commandcode test patches open_credentialed_url on the plugin module, and two invariant tests pin the no-network guard and the bearer routing.
19 lines
626 B
Python
19 lines
626 B
Python
"""AWS Bedrock provider profile."""
|
|
|
|
from providers import register_provider
|
|
from providers.base import ProviderProfile
|
|
|
|
|
|
class BedrockProfile(ProviderProfile):
|
|
"""AWS Bedrock — no REST /v1/models endpoint; uses AWS SDK."""
|
|
|
|
|
|
bedrock = BedrockProfile(
|
|
name="bedrock", aliases=("aws", "aws-bedrock", "amazon-bedrock", "amazon"), api_mode="bedrock_converse",
|
|
env_vars=(), # AWS SDK credentials — not env vars
|
|
base_url="https://bedrock-runtime.us-east-1.amazonaws.com", auth_type="aws_sdk",
|
|
supports_model_listing=False, # listing goes through the AWS SDK, not a REST call
|
|
)
|
|
|
|
register_provider(bedrock)
|