上游对单次请求下发 error.code=cyber_policy 硬阻断时,网关在所有端点 (/v1/responses、/v1/chat/completions、/v1/messages、WebSocket)及流式/ 非流式路径下,将该结果原样透传给客户端,绝不 failover、换号或同步拦截; 命中后异步完成审计与计费: - 风控中心记录 cyber_policy 留痕并发送通知邮件,落库先于发信,SMTP 阻塞 不影响留痕 - ops 错误请求记录,状态码对齐客户端实际接收(流式 200 / 非流式 400) - 用量明细标记 request_type=cyber,按上游真实 token 计费,HTTP 与 WebSocket 计费口径统一,零 token 命中不误扣 - 会话级自动屏蔽(管理员开关,默认关):命中的会话在可配 TTL 内本地拦截 不再发往上游,仅屏蔽该会话不影响同 Key 其他会话 - 封号计数排除开关:可选让 cyber 命中不计入自动封号,命中当次不判定且 历史行在违规计数中一并排除 WebSocket 多轮连接下 cyber 标记按 turn 生命周期管理,逐轮独立检测与记录; 透传的错误响应不被兜底逻辑追加内容污染。 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
74 lines
2.7 KiB
Go
74 lines
2.7 KiB
Go
package repository
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"time"
|
|
|
|
"github.com/Wei-Shaw/sub2api/internal/service"
|
|
"github.com/redis/go-redis/v9"
|
|
)
|
|
|
|
const stickySessionPrefix = "sticky_session:"
|
|
|
|
type gatewayCache struct {
|
|
rdb *redis.Client
|
|
}
|
|
|
|
func NewGatewayCache(rdb *redis.Client) service.GatewayCache {
|
|
return &gatewayCache{rdb: rdb}
|
|
}
|
|
|
|
// buildSessionKey 构建 session key,包含 groupID 实现分组隔离
|
|
// 格式: sticky_session:{groupID}:{sessionHash}
|
|
func buildSessionKey(groupID int64, sessionHash string) string {
|
|
return fmt.Sprintf("%s%d:%s", stickySessionPrefix, groupID, sessionHash)
|
|
}
|
|
|
|
func (c *gatewayCache) GetSessionAccountID(ctx context.Context, groupID int64, sessionHash string) (int64, error) {
|
|
key := buildSessionKey(groupID, sessionHash)
|
|
return c.rdb.Get(ctx, key).Int64()
|
|
}
|
|
|
|
func (c *gatewayCache) SetSessionAccountID(ctx context.Context, groupID int64, sessionHash string, accountID int64, ttl time.Duration) error {
|
|
key := buildSessionKey(groupID, sessionHash)
|
|
return c.rdb.Set(ctx, key, accountID, ttl).Err()
|
|
}
|
|
|
|
func (c *gatewayCache) RefreshSessionTTL(ctx context.Context, groupID int64, sessionHash string, ttl time.Duration) error {
|
|
key := buildSessionKey(groupID, sessionHash)
|
|
return c.rdb.Expire(ctx, key, ttl).Err()
|
|
}
|
|
|
|
// DeleteSessionAccountID 删除粘性会话与账号的绑定关系。
|
|
// 当检测到绑定的账号不可用(如状态错误、禁用、不可调度等)时调用,
|
|
// 以便下次请求能够重新选择可用账号。
|
|
//
|
|
// DeleteSessionAccountID removes the sticky session binding for the given session.
|
|
// Called when the bound account becomes unavailable (e.g., error status, disabled,
|
|
// or unschedulable), allowing subsequent requests to select a new available account.
|
|
func (c *gatewayCache) DeleteSessionAccountID(ctx context.Context, groupID int64, sessionHash string) error {
|
|
key := buildSessionKey(groupID, sessionHash)
|
|
return c.rdb.Del(ctx, key).Err()
|
|
}
|
|
|
|
// Compile-time assertion: gatewayCache must implement CyberSessionBlockStore.
|
|
var _ service.CyberSessionBlockStore = (*gatewayCache)(nil)
|
|
|
|
const cyberSessionBlockPrefix = "cyber_session_block:"
|
|
|
|
// SetCyberSessionBlocked 把被 cyber_policy 命中的会话写入屏蔽表(TTL 自动过期)。
|
|
// 存储值 "1" 作为存在标记(IsCyberSessionBlocked 只检查 key 是否存在,不读值)。
|
|
func (c *gatewayCache) SetCyberSessionBlocked(ctx context.Context, key string, ttl time.Duration) error {
|
|
return c.rdb.Set(ctx, cyberSessionBlockPrefix+key, "1", ttl).Err()
|
|
}
|
|
|
|
// IsCyberSessionBlocked 查询会话是否在屏蔽表中。
|
|
func (c *gatewayCache) IsCyberSessionBlocked(ctx context.Context, key string) (bool, error) {
|
|
n, err := c.rdb.Exists(ctx, cyberSessionBlockPrefix+key).Result()
|
|
if err != nil {
|
|
return false, err
|
|
}
|
|
return n > 0, nil
|
|
}
|