fix(sources): 源编辑不再清零 proxy_url / api_key_env / timeout

bf0657b 修好了 api_key,但 upsert 仍会重写整个源,于是请求无法表达的字段
一律被重置为零值。这四个字段的后果都不是"少个配置项":

  - api_key_env 丢失 ⇒ 盘上无明文密钥的源变成无凭据源,写操作返回 200,
    下一次调用上游才 401。而 README 恰恰把这个特性当作卖点在宣传。
  - proxy_url 丢失 ⇒ 一个走代理的上游变成直连(或反之),且完全无声。
  - timeout / queue_timeout 丢失 ⇒ 退回默认 120s / 60s。

触发路径不是只有脚本:WebUI 的 saveSource() 发的 payload 只含表单上的
11 个字段,而 editSource() 表单里根本没有这 4 项 ⇒ 运维在界面上改个并发数
就会静默清掉它们。

修法用「存在性」语义而不是「空即继承」:

  - 不传   → 保留已存值(部分更新的客户端要的就是这个)
  - 传了   → 覆盖,包括传空串表示清空

api_key 刻意保留它原有的「空即继承」规则,不跟着改成指针:该规则已随
v1.7.6 发布,脚本依赖它;而凭据丢失比代理丢失严重得多。两个字段的失败
模式相反,所以规则相反——这一条写进了两处注释。

另一处是差一点的:config.Source 把 Timeout/QueueTimeout 标成 json:"-",
所以 reveal 接口的结构体序列化**根本不返回它们**。表单读不到 → 输入框
恒空 → 而输入框每次都回传 → 每存一次就把 timeout 清零。等于把刚修好的
丢字段换个方向又造了一个。因此 reveal 分支现在显式返回 duration 字符串。

判据:
  - TestWebUIEditPayloadPreservesRoutingFields 用的是 WebUI 真实 payload
    的逐字节副本,并同时断言"确实改动的字段生效",否则"什么都不写"也能过
  - TestSourceEditPreservesAPIKeyEnv 单独盯 api_key_env(唯一造成凭据丢失的)
  - CanBeSet / CanBeCleared 分别盯两个方向:只有"空即继承"的实现过不了
    CanBeCleared(清空代理框会永远保留旧代理)
  - 持久化判据**重新加载 config.yaml 并按语义比对**:300s 会被重新序列化成
    5m0s,按字符串匹配是假红(我自己先踩了一次)
  - TestSourcePayloadCoversEveryEditableField 用反射卡住"这一类":新增
    Source 字段而没接到 API 上时立刻变红。反射查结构体而非 marshal 结果,
    因为指针 + omitempty 会合法地从序列化输出里消失,那正是"未提及"信号
  - 三个 UI 契约判据把 JS 侧也钉住(表单必须回传、必须从 reveal 读)

变异验证(每次都先确认 build 通过,再数红格):
  1. 去掉覆盖逻辑        → 7 个判据红
  2. 改成"空即继承"      → CanBeCleared + ClearIsScoped 红
  3. reveal 不返回 duration → TestSourceRevealExposesDurations 红
  4. 表单不回传 api_key_env → TestUIEditFormRoundTrips... 红

顺带修正 /api/v1 索引:DELETE /api/keys 的路径段写的是 {name},实际是 key
本身;PUT /api/keys/{key} 实现了却没列。

全量 + vet + race 全绿;WebUI 内联脚本过 node --check。
This commit is contained in:
JianFeeeee
2026-10-01 20:36:48 +08:00
parent 980f4a0e40
commit 18e422a943
5 changed files with 785 additions and 5 deletions

View File

@ -59,6 +59,82 @@ func lineOf(src string, idx int) int {
return strings.Count(src[:idx], "\n") + 1
}
// TestUIEditFormRoundTripsEveryOptionalSourceField pins the JS half of the
// source-edit contract.
//
// The server distinguishes "absent" from "explicitly empty" for proxy_url,
// api_key_env and timeout (they are pointers). That only helps if the form
// SENTS them — a form that omits them falls back to "inherit", so clearing the
// proxy box would silently keep the old proxy, which is the exact bug in the
// other direction.
//
// It must also send the api_key_env value it was given, since that is the one
// field whose loss is invisible until the next upstream call.
func TestUIEditFormRoundTripsEveryOptionalSourceField(t *testing.T) {
src := uiSource(t)
body, ok := jsFunctionBody(src, "saveSource")
if !ok {
t.Fatal("saveSource() not found in the WebUI")
}
for _, field := range []string{"proxy_url", "api_key_env", "timeout"} {
if !strings.Contains(body, field+":") {
t.Errorf("saveSource() does not send %q; the server treats an absent "+
"field as \"keep the stored value\", so the form could never clear it", field)
}
}
// The form's inputs must be filled from the values the server sends, or a
// save would post an empty box and clear a configured field.
for _, read := range []string{`$("#s-proxy")`, `$("#s-keyenv")`, `$("#s-timeout")`} {
if !strings.Contains(src, read+".value") {
t.Errorf("the source form never reads %s — it would post an empty value", read)
}
}
}
// TestUIEditFormReadsDurationsFromTheRevealView: config.Source tags
// Timeout/QueueTimeout `json:"-"`, so the durations only reach the form if the
// reveal endpoint adds them explicitly. The form MUST read them (see above),
// which makes this API response load-bearing rather than informational.
func TestUIEditFormReadsDurationsFromTheRevealView(t *testing.T) {
src := uiSource(t)
for _, id := range []string{"s-proxy", "s-keyenv", "s-timeout"} {
if !strings.Contains(src, `id="`+id+`"`) {
t.Errorf("source form input #%s is missing", id)
}
}
// The timeout box must render through the duration helper. Reading a raw
// time.Duration number would show nanoseconds in a box that expects "300s".
if !strings.Contains(src, "timeoutText(") {
t.Error("the timeout input does not go through timeoutText(); a raw " +
"time.Duration JSON number is nanoseconds and would be uneditable")
}
}
// TestUIEditFormSendsEverySourceField is the mirror of
// TestSourcePayloadCoversEveryEditableField on the JavaScript side: each field
// the server accepts must be submitted by the form, or the server's upsert has
// nothing to store for it.
func TestUIEditFormSendsEverySourceField(t *testing.T) {
src := uiSource(t)
body, ok := jsFunctionBody(src, "saveSource")
if !ok {
t.Fatal("saveSource() not found")
}
// Fields the edit dialog owns. proxy_url / api_key_env / timeout are
// covered by the round-trip test above; this one catches the rest.
// models and meta are local variables submitted by Go shorthand
// (payload = { models, meta }), so they are matched as bare identifiers.
for _, field := range []string{
"name:", "base_url:", "api_key:", "adapter:", "endpoint:",
"image_endpoint:", "max_concurrent:", "rpm:", "temperature:",
"models,", "meta,",
} {
if !strings.Contains(body, field) {
t.Errorf("saveSource() does not send %s", field)
}
}
}
// TestUIAPICallsDeclareMethod asserts that every api() call passing an options
// object also declares an HTTP method (or is a GET that only passes an
// AbortSignal). Without this, fetch defaults to GET and mutating endpoints are