refac
This commit is contained in:
@@ -229,6 +229,11 @@ class TerminalServerConnection(BaseModel):
|
||||
|
||||
config: Optional[dict] = None
|
||||
|
||||
# Orchestrator policy fields
|
||||
server_type: Optional[str] = None # "orchestrator", "terminal"
|
||||
policy_id: Optional[str] = None
|
||||
policy: Optional[dict] = None # cached policy data
|
||||
|
||||
model_config = ConfigDict(extra="allow")
|
||||
|
||||
|
||||
|
||||
@@ -75,6 +75,12 @@ async def proxy_terminal(
|
||||
)
|
||||
|
||||
target_url = f"{base_url}/{path}"
|
||||
|
||||
# Route through orchestrator policy endpoint if policy_id is set
|
||||
policy_id = connection.get("policy_id")
|
||||
if policy_id:
|
||||
target_url = f"{base_url}/p/{policy_id}/{path}"
|
||||
|
||||
if request.query_params:
|
||||
target_url += f"?{request.query_params}"
|
||||
|
||||
@@ -236,14 +242,18 @@ async def ws_terminal(
|
||||
# Build upstream WebSocket URL (no token in URL)
|
||||
ws_base = base_url.replace("https://", "wss://").replace("http://", "ws://")
|
||||
|
||||
auth_type = connection.get("auth_type", "bearer")
|
||||
# Route through orchestrator policy endpoint if policy_id is set
|
||||
policy_id = connection.get("policy_id")
|
||||
upstream_params = {}
|
||||
# For orchestrator-backed servers, pass user_id
|
||||
upstream_params["user_id"] = user.id
|
||||
|
||||
import urllib.parse
|
||||
|
||||
upstream_url = f"{ws_base}/api/terminals/{session_id}"
|
||||
if policy_id:
|
||||
upstream_url = f"{ws_base}/p/{policy_id}/api/terminals/{session_id}"
|
||||
else:
|
||||
upstream_url = f"{ws_base}/api/terminals/{session_id}"
|
||||
if upstream_params:
|
||||
upstream_url += f"?{urllib.parse.urlencode(upstream_params)}"
|
||||
|
||||
|
||||
@@ -914,9 +914,17 @@ async def set_terminal_servers(request: Request):
|
||||
|
||||
enabled = connection.get("enabled", True)
|
||||
|
||||
base_url = connection.get("url", "").rstrip("/")
|
||||
policy_id = connection.get("policy_id", "")
|
||||
|
||||
# Orchestrator connections route through /p/{policy_id}/ — the
|
||||
# OpenAPI spec lives on the proxied terminal, not the orchestrator.
|
||||
if connection.get("server_type") == "orchestrator" and policy_id:
|
||||
base_url = f"{base_url}/p/{policy_id}"
|
||||
|
||||
server_configs.append(
|
||||
{
|
||||
"url": connection.get("url", ""),
|
||||
"url": base_url,
|
||||
"key": connection.get("key", ""),
|
||||
"auth_type": connection.get("auth_type", "bearer"),
|
||||
"path": connection.get("path", "/openapi.json"),
|
||||
|
||||
Reference in New Issue
Block a user