Skip to content

Commit e9cdd06

Browse files
committed
feat(profile): bind named profile credentials
1 parent 3ea8dab commit e9cdd06

1 file changed

Lines changed: 42 additions & 4 deletions

File tree

‎src/main/java/io/github/easy4j/hermes/HermesClient.java‎

Lines changed: 42 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,9 @@
33
import io.github.easy4j.hermes.api.model.*;
44
import io.github.easy4j.hermes.cli.HermesCli;
55
import io.github.easy4j.hermes.cli.HermesCliExecutor;
6+
import io.github.easy4j.hermes.security.ProfileBinding;
7+
import io.github.easy4j.hermes.security.ProfileCredentialResolver;
8+
import io.github.easy4j.hermes.security.ProfileIdentity;
69
import io.github.easy4j.hermes.api.HermesHttpClient;
710
import io.github.easy4j.hermes.api.HermesChatClient;
811
import io.github.easy4j.hermes.api.HermesSseClient;
@@ -94,6 +97,7 @@ public class HermesClient implements AutoCloseable {
9497
public HermesClient(HermesClientConfig config) {
9598
this(Objects.requireNonNull(config, "config").getHttp(), config.getCli(), new ObjectMapper(),
9699
HermesOkHttpClientFactory.create(config.getHttp()), true);
100+
this.config.setProfileCredentialResolver(config.getProfileCredentialResolver());
97101
}
98102

99103
/**
@@ -125,6 +129,7 @@ public HermesClient(HermesClientConfig config, ObjectMapper objectMapper, OkHttp
125129
objectMapper,
126130
httpClient,
127131
false);
132+
this.config.setProfileCredentialResolver(config.getProfileCredentialResolver());
128133
}
129134

130135
/**
@@ -323,6 +328,8 @@ private static void copyHttpConfig(HermesHttpClientConfig src, HermesHttpClientC
323328
target.setEndpointPolicy(src.getEndpointPolicy());
324329
target.setBaseUrl(src.getBaseUrl());
325330
target.setApiKey(src.getApiKey());
331+
target.setCredentialProvider(src.getCredentialProvider());
332+
target.setProfileIdentity(src.getProfileIdentity());
326333
target.setConnectTimeoutMillis(src.getConnectTimeoutMillis());
327334
target.setReadTimeoutMillis(src.getReadTimeoutMillis());
328335
target.setWriteTimeoutMillis(src.getWriteTimeoutMillis());
@@ -1066,16 +1073,47 @@ public HermesClient forProfile(String profileId) {
10661073
throw new IllegalStateException("Hermes HTTP client is disabled");
10671074
}
10681075
String normalizedProfileId = normalizeProfileId(profileId);
1069-
// 并发访问同一 profile 时只发布一个托管视图。
1070-
return profileClients.computeIfAbsent(normalizedProfileId, this::createProfileClient);
1076+
ProfileCredentialResolver resolver = config.getProfileCredentialResolver();
1077+
if (resolver == null) {
1078+
throw new IllegalStateException("No credential is configured for Hermes profile "
1079+
+ normalizedProfileId + "; root credentials are never inherited by named profiles");
1080+
}
1081+
ProfileBinding binding = resolver.resolve(normalizedProfileId);
1082+
if (binding == null) {
1083+
throw new IllegalStateException("No credential is configured for Hermes profile " + normalizedProfileId);
1084+
}
1085+
if (!normalizedProfileId.equals(binding.getProfileId())) {
1086+
throw new IllegalStateException("Profile credential resolver returned a binding for "
1087+
+ binding.getProfileId() + " instead of " + normalizedProfileId);
1088+
}
1089+
return forProfile(binding);
1090+
}
1091+
1092+
public HermesClient forProfile(ProfileBinding binding) {
1093+
Objects.requireNonNull(binding, "binding");
1094+
if (managedProfileView) {
1095+
throw new IllegalStateException("Cannot create a profile client from another profile client");
1096+
}
1097+
if (closed.get()) {
1098+
throw new IllegalStateException("HermesClient is closed");
1099+
}
1100+
if (!isHttpEnabled()) {
1101+
throw new IllegalStateException("Hermes HTTP client is disabled");
1102+
}
1103+
String profileId = normalizeProfileId(binding.getProfileId());
1104+
String cacheKey = config.getHttp().getBaseUrl() + "|" + profileId + "|" + binding.getCredentialIdentity();
1105+
return profileClients.computeIfAbsent(cacheKey, ignored -> createProfileClient(binding, profileId));
10711106
}
10721107

1073-
private HermesClient createProfileClient(String profileId) {
1108+
private HermesClient createProfileClient(ProfileBinding binding, String profileId) {
10741109
HermesHttpClientConfig profileConfig = new HermesHttpClientConfig();
10751110
copyHttpConfig(config.getHttp(), profileConfig);
1076-
// profile 只改变 URL 前缀并禁用重复探测,传输和 JSON 配置继续复用根客户端。
10771111
profileConfig.setBaseUrl(profileServerUrl(config.getHttp().getBaseUrl(), profileId));
10781112
profileConfig.setStartupCheckEnabled(false);
1113+
profileConfig.setApiKey(null);
1114+
profileConfig.setProfileIdentity(new ProfileIdentity(
1115+
config.getHttp().getBaseUrl(), profileId, binding.getCredentialIdentity()));
1116+
profileConfig.setCredentialProvider(binding.getCredentialProvider());
10791117
HermesCliConfig disabledCli = new HermesCliConfig();
10801118
disabledCli.setEnabled(false);
10811119
return new HermesClient(profileConfig, disabledCli, objectMapper, sharedHttpClient, false, true);

0 commit comments

Comments
 (0)