Skip to content

feat: canned, unbilled responses for omni_sk_test_ keys - #29

Merged
man4ish merged 1 commit into
mainfrom
feature/m13-test-mode-canned-responses
Oct 4, 2026
Merged

man4ish merged 1 commit into
mainfrom
feature/m13-test-mode-canned-responses

Conversation

@man4ish

@man4ish man4ish commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

Paired with omnibioai-auth's live/test key prefix change -- closes the last remaining bullet of design audit gap #9 ("test keys and canned, unbilled responses are absent").

  • IAMClient.validate_api_key now propagates test_mode from the exchange response; AuthMiddleware copies it onto request.state.identity (only ever True for an API-key identity).
  • /v1/literature/answers and /v1/literature/search check identity.test_mode and, when true, return a deterministic canned response (build_test_answer/build_test_search in literature_contract.py) in the exact same shape a real call would produce -- empty citations/results rather than fabricated literature data, since a test key's job is exercising a caller's own integration code, not pretending to answer a real question.
  • Quota reservation, the real RAG forward, and usage emission are all skipped entirely for a test-mode call -- it never consumes real org quota and is never billed.
  • The concurrency cap is skipped too (a test key never touches real RAG capacity, so acquiring a slot would just be unearned contention against real callers sharing the same key/org budget).
  • Rate limiting still applies unconditionally -- it protects the gateway's own resources regardless of whether a call is "real".
  • Idempotency-Key replay works identically for test-mode calls, so a caller can validate their own retry/idempotency handling against a test key realistically.

Test plan

  • pytest tests/test_v1_literature.py -- 62 passed (56 existing + 6 new: canned answers/search responses, quota bypass, rate limiting still enforced, concurrency slot never touched, idempotency replay)
  • pytest tests/test_api_key_auth.py -- 20 passed (18 existing + 2 new: test_mode propagation through validate_api_key, defaults closed when absent)
  • Full repo suite -- 378 passed

🤖 Generated with Claude Code

An omni_sk_test_ key's exchange response now carries test_mode (paired
omnibioai-auth change), propagated onto request.state.identity. /v1/
literature/answers and /search read it and short-circuit to a
deterministic canned response (build_test_answer/build_test_search) --
never a real RAG call, never counted against quota, never billed. Rate
limiting still applies (abuse protection the gateway needs regardless
of whether a call is real); the concurrency cap and quota reservation
are skipped entirely, since a test key never touches the real resources
either protects. Closes the last remaining bullet of design audit gap #9.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@man4ish
man4ish merged commit b367e01 into main Oct 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant