Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 22 additions & 17 deletions usage-service/internal/httpapi/server.go
Original file line number Diff line number Diff line change
Expand Up @@ -883,40 +883,45 @@ func (s *Server) handleUsage(w http.ResponseWriter, r *http.Request) {
if !s.authorizeIfConfigured(w, r) {
return
}
path := strings.TrimRight(r.URL.Path, "/")
if path == "" {
path = "/"
}
switch r.Method {
case http.MethodGet:
if strings.HasSuffix(r.URL.Path, "/export") {
switch path {
case "/v0/management/usage/export":
s.handleUsageExport(w, r)
return
}
if strings.HasSuffix(r.URL.Path, "/summary") {
case "/v0/management/usage/summary":
s.handleUsageSummary(w, r)
return
}
if strings.HasSuffix(r.URL.Path, "/accounts") {
case "/v0/management/usage/accounts":
s.handleUsageBreakdownPage(w, r, store.UsageBreakdownAccounts)
return
}
if strings.HasSuffix(r.URL.Path, "/api-keys") {
case "/v0/management/usage/api-keys":
s.handleUsageBreakdownPage(w, r, store.UsageBreakdownAPIKeys)
return
}
if strings.HasSuffix(r.URL.Path, "/realtime") {
case "/v0/management/usage/realtime":
s.handleUsageBreakdownPage(w, r, store.UsageBreakdownRealtime)
return
}
if strings.HasSuffix(r.URL.Path, "/models") {
case "/v0/management/usage/models":
s.handleUsageBreakdownPage(w, r, store.UsageBreakdownModels)
return
}
events, err := s.store.RecentEvents(r.Context(), s.cfg.QueryLimit)
if err != nil {
writeError(w, http.StatusInternalServerError, err)
case "/v0/management/usage":
events, err := s.store.RecentEvents(r.Context(), s.cfg.QueryLimit)
if err != nil {
writeError(w, http.StatusInternalServerError, err)
return
}
writeJSON(w, http.StatusOK, usage.BuildPayload(events))
return
default:
http.NotFound(w, r)
return
}
writeJSON(w, http.StatusOK, usage.BuildPayload(events))
case http.MethodPost:
if strings.HasSuffix(r.URL.Path, "/import") {
if path == "/v0/management/usage/import" {
s.handleUsageImport(w, r)
return
}
Expand Down
27 changes: 27 additions & 0 deletions usage-service/internal/httpapi/server_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -345,6 +345,33 @@ func TestUsageBreakdownPageEndpointsReturnPagination(t *testing.T) {
}
}

func TestUsageEndpointsUseExactPathsWithTrailingSlashNormalization(t *testing.T) {
handler := newTestHandler(t, "http://example.test", true)

req := httptest.NewRequest(http.MethodGet, "/v0/management/usage/summary/", nil)
req.Header.Set("Authorization", "Bearer management-key")
rr := httptest.NewRecorder()
handler.ServeHTTP(rr, req)
if rr.Code != http.StatusOK {
t.Fatalf("summary trailing slash status = %d, body = %s", rr.Code, rr.Body.String())
}

for _, path := range []string{
"/v0/management/usage/not-summary/summary",
"/v0/management/usage/accounts-extra",
} {
t.Run(path, func(t *testing.T) {
req := httptest.NewRequest(http.MethodGet, path, nil)
req.Header.Set("Authorization", "Bearer management-key")
rr := httptest.NewRecorder()
handler.ServeHTTP(rr, req)
if rr.Code != http.StatusNotFound {
t.Fatalf("status = %d, body = %s", rr.Code, rr.Body.String())
}
})
}
}

func TestUsageBreakdownPageRejectsUnsafePageFilters(t *testing.T) {
handler := newTestHandler(t, "http://example.test", true)
for _, path := range []string{
Expand Down
Loading
Loading