mirror of
https://gitcode.com/JianFeeeee/ModelRouter.git
synced 2026-10-05 15:07:51 +00:00
fix(gateway): AUTO 被密钥模型范围拦下时报错误导 + 编辑器给出提示
一个密钥的模型范围不含 AUTO 时,它用不了 AUTO —— 范围过滤发生在链之前。 但这两条路径都不说真话: 1. 请求侧:AUTO 走的是通用分支,返回 model_not_found "model \"AUTO\" is not configured",读起来像 AUTO 没配置。非 AUTO 模型早就有 model_not_allowed 的专门提示,AUTO 漏了。补上,并说明修法(把 AUTO 加进该密钥的 models, 或去掉范围限制)。 2. 编辑器侧:per-key AUTO 链编辑器可以正常配链、保存也成功,看起来一切正常, 但该密钥的每个请求都会 403。管理员无从得知。现在弹窗顶部在检测到冲突时 显示警告,并列出当前范围。 刻意不做的事:不自动把 AUTO 加进该密钥的模型范围。那等于悄悄授予运营 没要求的访问权,比一个显眼的警告更糟。 判据 1 条,除确认提示出现外还断言该函数体内没有 PUT/POST/fetch/api —— 它只报告,不得写回。变异(去掉 AUTO 判断)判红。 CDP 实测四种场景:范围含 AUTO → 无提示;范围不含 → 警告并列出范围; 空范围(不受限)→ 无提示;范围含 AUTO → 无提示。 Co-Authored-By: ModelRouter <noreply@modelrouter.dev>
This commit is contained in:
@ -329,3 +329,36 @@ func TestUIKeyAutoNoticeDistinguishesSavedFromCopied(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// A key whose model scope excludes AUTO cannot use AUTO at all — the scope
|
||||
// filter runs before the chain — yet the editor happily lets an admin
|
||||
// configure a per-key chain. That combination is easy to create by accident
|
||||
// and produces a 403 with no visible cause, so the dialog must say so.
|
||||
//
|
||||
// We deliberately do NOT widen the scope automatically: silently granting a
|
||||
// model the operator did not ask for is worse than a loud warning.
|
||||
func TestUIKeyAutoWarnsOnScopeConflict(t *testing.T) {
|
||||
src := uiSource(t)
|
||||
if !strings.Contains(src, "function keyAutoScopeWarning(") {
|
||||
t.Fatal("no scope-conflict check in the per-key editor")
|
||||
}
|
||||
body := readFuncBody(t, src, "keyAutoScopeWarning")
|
||||
if !strings.Contains(body, "AUTO") {
|
||||
t.Fatal("keyAutoScopeWarning must test whether the scope lists AUTO")
|
||||
}
|
||||
// It must not write anything back to the key: reporting only.
|
||||
for _, forbidden := range []string{"PUT", "POST", "fetch(", "api("} {
|
||||
if strings.Contains(body, forbidden) {
|
||||
t.Fatalf("keyAutoScopeWarning calls %s — it must only report the "+
|
||||
"conflict, never widen the scope itself", forbidden)
|
||||
}
|
||||
}
|
||||
// Empty scope means unrestricted, so no warning is correct there.
|
||||
if !strings.Contains(body, "if (!models.length)") {
|
||||
t.Fatal("an unrestricted key (no models) must not be warned")
|
||||
}
|
||||
// Both languages.
|
||||
if n := strings.Count(src, "kAutoChainScopeWarn"); n < 2 {
|
||||
t.Fatalf("i18n key kAutoChainScopeWarn appears %d time(s), want zh+en", n)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user