Files
writer-work-flow/apps/api/tests/fakes_providers.py
Yaojia Wang 345cc73965 fix(txn+security): 仓储改 flush + 启动校验/兜底 + job.error 脱敏 + SSE 异常硬化
P0-1 SqlCredentialStore/save_draft 由自提交改 flush,端点/服务统一 commit
  (新增 CredentialStore.commit() 统一提交点;token 刷新落库显式提交);
  补多凭据一请求中途失败整体回滚集成测试。
P0-2 启动校验 _fernet(enc_key) 快速失败 + catch-all Exception → ErrorEnvelope;
  credential_enc_key 改 SecretStr。
P0-3 run_job 异常分类:AppError 存 code+message,其余存通用文案不泄 str(exc)。
P0-4 评审/正文 SSE 失败先发 error 事件,尾部 commit 包 try/except。
P1-4 max_version 加 FOR UPDATE 行锁消除 TOCTOU。
P1-5 scan_overdue 谓词下推 + 批量 UPDATE RETURNING。
P1-10 移除 OAuth user_code 日志。
P2 provider_deps 改调网关 build_adapter;accept_service Committable Protocol;
  CORS 白名单收窄;request_id 安全字符集白名单;stdlib 日志接管;读端点 404 校验;
  httpx timeout;测试用合法 Fernet key;类型化响应模型(JobResponse/DimensionEntry/
  ReviewConflictView/selling_points)+路由 ErrorEnvelope responses(供 codegen)。
2026-06-21 19:32:24 +02:00

87 lines
3.3 KiB
Python
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

"""内存替身:凭据存储 + 提供商探测(端点测试用,无 DB/无网络)。
绝对导入 `from fakes import ...`(包目录无 __init__.py见 memory/gotchas
"""
from __future__ import annotations
import uuid
from ww_api.services.credentials import StoredCredential, StoredRouting
from ww_llm_gateway.adapters.base import Capabilities
class FakeCredentialStore:
"""实现 `CredentialStore` Protocol 的内存版。"""
def __init__(self) -> None:
# key: (owner_id, provider) → api_key 密文
self.creds: dict[tuple[uuid.UUID, str], bytes] = {}
# key: (owner_id, provider) → oauth 密文OAuth 凭据auth_type="oauth"
self.oauth: dict[tuple[uuid.UUID, str], bytes] = {}
self.routing: dict[str, StoredRouting] = {}
async def list_credentials(self, owner_id: uuid.UUID) -> list[StoredCredential]:
rows = [
StoredCredential(provider=p, api_key_enc=blob)
for (o, p), blob in self.creds.items()
if o == owner_id
]
rows += [
StoredCredential(provider=p, api_key_enc=None, auth_type="oauth", oauth_enc=blob)
for (o, p), blob in self.oauth.items()
if o == owner_id
]
return rows
async def list_routing(self) -> list[StoredRouting]:
return list(self.routing.values())
async def get_credential(self, owner_id: uuid.UUID, provider: str) -> StoredCredential | None:
oauth_blob = self.oauth.get((owner_id, provider))
if oauth_blob is not None:
return StoredCredential(
provider=provider, api_key_enc=None, auth_type="oauth", oauth_enc=oauth_blob
)
blob = self.creds.get((owner_id, provider))
if blob is None:
return None
return StoredCredential(provider=provider, api_key_enc=blob)
async def upsert_credential(
self, owner_id: uuid.UUID, provider: str, api_key_enc: bytes
) -> None:
self.creds[(owner_id, provider)] = api_key_enc
self.oauth.pop((owner_id, provider), None)
async def upsert_oauth_credential(
self, owner_id: uuid.UUID, provider: str, oauth_enc: bytes
) -> None:
self.oauth[(owner_id, provider)] = oauth_enc
self.creds.pop((owner_id, provider), None)
async def delete_credential(self, owner_id: uuid.UUID, provider: str) -> bool:
had = (owner_id, provider) in self.creds or (owner_id, provider) in self.oauth
self.creds.pop((owner_id, provider), None)
self.oauth.pop((owner_id, provider), None)
return had
async def upsert_routing(self, routing: StoredRouting) -> None:
self.routing[routing.tier] = routing
async def commit(self) -> None:
# 内存替身无事务commit 为 no-op写入在 upsert 时即生效)。
return None
class FakeProviderProbe:
"""实现 `ProviderProbe` Protocol返回固定能力矩阵绝不联网。"""
def __init__(self, caps: Capabilities | None = None) -> None:
self.caps = caps or Capabilities(structured_output=True, prefix_cache=True, thinking=False)
self.calls: list[tuple[uuid.UUID, str]] = []
async def probe(self, owner_id: uuid.UUID, provider: str) -> Capabilities:
self.calls.append((owner_id, provider))
return self.caps