ren worker folder adding orig, mv new one into root
This commit is contained in:
34
worker-toolkit-potion-polyglot/scripts/lib/call-origin.sh
Normal file
34
worker-toolkit-potion-polyglot/scripts/lib/call-origin.sh
Normal file
@@ -0,0 +1,34 @@
|
||||
# shellcheck shell=bash
|
||||
# call-origin.sh — build the X-Surge-Client-Metadata header value.
|
||||
#
|
||||
# Which surface a proxy call came from (a trial agent, the grader, Explore, a
|
||||
# dev box). Separate from llm-proxy-env.sh, which carries the project id and the
|
||||
# proxy routes: those are platform-internal, this is not, so this file is the
|
||||
# half that ships in the worker toolkit — worker runs go through the same proxy
|
||||
# and are attributed the same way.
|
||||
#
|
||||
# . scripts/lib/call-origin.sh
|
||||
# meta="$(LLM_CALL_ORIGIN=harbor-grading call_origin_metadata)"
|
||||
#
|
||||
# The proxy rejects the WHOLE CALL over a malformed metadata header (400
|
||||
# invalid_client_metadata), so an origin that is not a plain slug yields an
|
||||
# empty string and the caller sends no header at all: losing attribution beats
|
||||
# failing the call.
|
||||
|
||||
CALL_ORIGIN_HEADER="X-Surge-Client-Metadata"
|
||||
# An unlabelled call is still a real call, so it gets a bucket rather than no
|
||||
# header: a missing origin in the audit log then means an unplumbed surface.
|
||||
DEFAULT_CALL_ORIGIN="local"
|
||||
|
||||
# Compact JSON for the header, or empty when LLM_CALL_ORIGIN is unusable.
|
||||
# Only a slug matching this pattern is ever interpolated, so nothing needs
|
||||
# JSON-escaping and this stays dependency-free (it is sourced in worker
|
||||
# containers, which have no python).
|
||||
call_origin_metadata() {
|
||||
local origin="${LLM_CALL_ORIGIN:-$DEFAULT_CALL_ORIGIN}"
|
||||
case "$origin" in
|
||||
"" | *[!a-z0-9._-]* | [!a-z0-9]*) return 0 ;;
|
||||
esac
|
||||
[ "${#origin}" -le 64 ] || return 0
|
||||
printf '{"origin":"%s"}' "$origin"
|
||||
}
|
||||
Reference in New Issue
Block a user