Skip to content

chore(deps-rust)(deps): bump axum-test from 15.7.4 to 20.1.0 - #78

Merged
yacosta738 merged 1 commit into
mainfrom
dependabot/cargo/axum-test-20.1.0
Jun 2, 2026
Merged

yacosta738 merged 1 commit into
mainfrom
dependabot/cargo/axum-test-20.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 1, 2026

Copy link
Copy Markdown
Contributor

Bumps axum-test from 15.7.4 to 20.1.0.

Release notes

Sourced from axum-test's releases.

19.1.0

  • Remove TestServer::scheme, as it never actually worked with http requests only mocked requests.
  • Remove TestRequest::scheme, as it never actually worked with http requests only mocked requests.
  • Mocked transport no longer provides the scheme and authority to the service, which matches the behaviour with Tokio / Hyper based services.
  • Mocked now provides the HOST header, which matches the behaviour with Hyper based HTTP services.

19.0.0

  • Simplified constructors for TestServer, TestServerBuilder, and TestServerConfig.
    • new() constructor no longer returns a Result, and instead panics on failure.
    • Added try_new() to allow people to continue to catch the Result if needed.
  • TestResponse assertion functions now return &self, allowing calls to be chained!
  • Requests using Reqwest will now share cookies with regular Axum Test requests.
    • Cookies saved by one are saved to the other, and both adhere to TestServer::save_cookies() and TestServer::do_not_save_cookies() commands.
  • Improved error messages across the API.
    • JSON and Yaml assertions now output the body of the request when they fail.
  • Removed deprecated feature old-json-diff.
Commits

@dependabot @github

dependabot Bot commented on behalf of github Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Jun 1, 2026

Copy link
Copy Markdown

Thank you for contributing to this project with this PR, welcome to the community and the amazing world of open source!

yacosta738
yacosta738 previously approved these changes Jun 2, 2026
@yacosta738

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Bumps [axum-test](https://github.com/JosephLenton/axum-test) from 15.7.4 to 20.1.0.
- [Release notes](https://github.com/JosephLenton/axum-test/releases)
- [Commits](https://github.com/JosephLenton/axum-test/commits)

---
updated-dependencies:
- dependency-name: axum-test
  dependency-version: 20.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/axum-test-20.1.0 branch from b8e3da8 to 693ce7b Compare June 2, 2026 07:00
@yacosta738
yacosta738 merged commit 76bbb96 into main Jun 2, 2026
6 checks passed
@yacosta738
yacosta738 deleted the dependabot/cargo/axum-test-20.1.0 branch June 2, 2026 07:03

Copilot AI commented Jun 2, 2026

Copy link
Copy Markdown

@copilot resolve the merge conflicts in this pull request

I checked this branch against main at 693ce7b, and there are currently no merge conflicts to resolve. The PR head is already up to date with the base commit.

Copilot stopped work on behalf of yacosta738 due to an error June 2, 2026 07:03
Copilot AI requested a review from yacosta738 June 2, 2026 07:03
yacosta738 added a commit that referenced this pull request Jun 2, 2026
…uting (#85, #86) (#90)

* chore(deps-rust)(deps): bump axum-test from 15.7.4 to 20.1.0 (#78)

Bumps [axum-test](https://github.com/JosephLenton/axum-test) from 15.7.4 to 20.1.0.
- [Release notes](https://github.com/JosephLenton/axum-test/releases)
- [Commits](https://github.com/JosephLenton/axum-test/commits)

---
updated-dependencies:
- dependency-name: axum-test
  dependency-version: 20.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(api-key): add allowed_models and allowed_providers restriction fields (#85)

* feat(routing): enforce allowed_models and allowed_providers restrictions (#86)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
yacosta738 added a commit that referenced this pull request Jun 2, 2026
…nt (#89)

* feat(api-key): typed ApiKeyScope with canonical scope values (#83)

Add KnownScope enum with five canonical values: chat:read, chat:write,
providers:read, providers:write, admin.

ApiKeyScope::parse now rejects unknown values with UnknownScope error.
ApiKeyScope::parse_lenient is introduced for DB reads — accepts any
non-empty value and emits a tracing::warn for unrecognised scopes.

ManageApiKeys::create and update validate all scopes before touching
the repository.

Fixes pre-existing sha2 0.11 compilation breakage in login.rs,
validate_session.rs, and auth.rs.

* feat(authz): scope enforcement per route class in client API policy (#84)

Add required_scope(method, path) mapping routes under /v1/* to their
canonical scope requirement. Add check_scope helper that allows requests
when the subject holds the required scope or the admin superset scope,
and rejects with HTTP 403 INSUFFICIENT_SCOPE otherwise.

Thread method and path through evaluate_policy and client_api_policy.
Update env-fallback credentials to use canonical scope names.
Update all affected tests to use canonical scope values.

* fix: apply CodeRabbit auto-fixes

Fixed 8 file(s) based on 3 unresolved review comments.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>

* feat(api-key): add allowed_models/allowed_providers and enforce in routing (#85, #86) (#90)

* chore(deps-rust)(deps): bump axum-test from 15.7.4 to 20.1.0 (#78)

Bumps [axum-test](https://github.com/JosephLenton/axum-test) from 15.7.4 to 20.1.0.
- [Release notes](https://github.com/JosephLenton/axum-test/releases)
- [Commits](https://github.com/JosephLenton/axum-test/commits)

---
updated-dependencies:
- dependency-name: axum-test
  dependency-version: 20.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(api-key): add allowed_models and allowed_providers restriction fields (#85)

* feat(routing): enforce allowed_models and allowed_providers restrictions (#86)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(deps): add hex crate version 0.4.3 to Cargo.lock

* fix(dashboard): update API key scope options to canonical chat:read/chat:write

The dashboard was still emitting pre-#83 scope values ('read', 'write') in
the create/edit modals, which the backend now rejects with 400
'unknown API key scope'.

This was surfaced by 'just ci-local' failing the Playwright e2e suite
after #83/#84 landed. Without this fix, every dashboard user creating
an API key via the UI would have hit the same 400 error.

- ApiKeysView.vue: dropdown values updated to canonical scopes
- api-keys.spec.ts: helper defaults + 2 call sites updated; UI selector
  tightened to '^chat read$' to avoid accidental matches

* fix(authz): address code review findings (#1-#4)

Four pre-existing issues caught by inline review of the PR-A stack.
Finding 5 (SESSION_NOT_FOUND redirect) was verified invalid and skipped —
the dashboard redirect is driven by currentUser, not by rejection codes.

## Finding 1: stream paths bypassed forbidden/rate-limit HTTP mapping

chat_completions_stream and anthropic_messages_stream were returning
SSE 200 with a generic internal_error event when the upstream
execute_stream_with_format returned a forbidden or rate_limited error.
This means a model-restricted key streaming chat completions got
200 + a confusing SSE error event instead of a clean HTTP 403.

Added Err-arms for is_forbidden() and is_rate_limited() in both stream
handlers so streaming and non-streaming requests share identical
auth/rate-limit behavior. New helpers map_forbidden_openai and
map_rate_limited return typed HttpError for the IntoResponse path.

## Finding 2: restrictions_from_headers failed open on missing headers

The function used unwrap_or_default() on header lookups, so a missing
x-authz-allowed-models or x-authz-allowed-providers header was silently
treated as 'unrestricted'. The authz middleware must always stamp these
headers, so a missing header indicates either a routing bug or a
middleware bypass — both should be loud, not silent.

Restructured into a parse_csv_header helper that returns
Result<Vec<String>, HttpError> and propagates AUTHZ_HEADER_MISSING
or AUTHZ_HEADER_INVALID 500 responses. Empty header value (public
subject) still maps to empty Vec, which the domain treats as
unrestricted.

## Finding 3: scopes_from_json rejected pre-#83 legacy scope strings

auth-sqlite used ApiKeyScope::parse (strict) in scopes_from_json, which
rejects any unknown scope string. Existing API keys created before
#83 with legacy values ('read', 'write') would fail to load.

Switched to ApiKeyScope::parse_lenient, which is the documented
method for reading from the database (accepts unknowns, logs warning).
Added regression test read_key_with_legacy_scope_string_is_preserved.

## Finding 4: required_scope fallback allowed POST with read-only key

required_scope returned Some("chat:read") for ANY /v1/* path that
wasn't /v1/providers/* or /v1/chat/* — regardless of HTTP method. This
meant a key with only the chat:read scope could hit POST /v1/messages
(Anthropic) and pass the authz check, then rely on downstream luck.

Updated the fallback to inspect the method: GET → chat:read, all
others → chat:write. The special-cases for /v1/providers* and
/v1/chat/* are preserved.

Added regression test
client_api_with_chat_read_scope_rejected_on_post_to_messages.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants