mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-17 20:52:15 +03:00
* feat(sse): add Vertex AI DeepSeek OCR transformation to the registry Adds VERTEX_DEEPSEEK_TRANSFORMATION (request/response mapping for the Vertex AI DeepSeek OCR MaaS endpoint) and registers the "vertex-deepseek-ocr" provider in OCR_PROVIDERS, modeled on litellm's VertexAIDeepSeekOCRConfig. buildRequest treats the resolved baseUrl as the complete Vertex endpoint URL (project/location resolved upstream), matching the existing Mistral passthrough pattern. * feat(sse): resolve Vertex AI DeepSeek OCR auth and endpoint URL Adds resolveVertexOcrAccessToken (mints a Vertex OAuth access token from a Service Account JSON apiKey, reusing open-sse/executors/vertex.ts's existing JWT-bearer exchange — no new OAuth flow) and resolveVertexOcrBaseUrl (derives the project/location "openapi/chat/ completions" endpoint from providerSpecificData or the Service Account JSON's project_id). Both live in open-sse/handlers/ocr.ts, not the src/app/api/v1/ocr route, since routes may not import executor implementations directly (EXECUTOR_IMPORT_RESTRICTION in eslint.config.mjs) — the route re-exports/consumes them across that boundary. handleOcr now prefers credentials.accessToken over apiKey so the minted token (not the raw Service Account JSON) is sent upstream. * docs(api): document the vertex-deepseek-ocr /v1/ocr provider Adds the vertex-deepseek-ocr row to the /v1/ocr provider table and a short section on its Vertex AI auth/endpoint resolution, and lists the new provider/model id in openapi.yaml alongside mistral and azure-document-intelligence. * docs(skills): regenerate omni-inference skill for the Vertex OCR provider --------- Co-authored-by: Xiangzhe <bakryun0718@proton.me>
143 lines
6.1 KiB
TypeScript
143 lines
6.1 KiB
TypeScript
import { test } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import { generateKeyPairSync } from "node:crypto";
|
|
import {
|
|
resolveOcrCredentials,
|
|
resolveVertexOcrAccessToken,
|
|
} from "../../src/app/api/v1/ocr/route.ts";
|
|
|
|
// ── resolveOcrCredentials — vertex-deepseek-ocr project/location resolution ─
|
|
// Mirrors the Azure DI pattern (providerSpecificData.baseUrl → top-level
|
|
// baseUrl) but synthesizes the full Vertex "openapi/chat/completions"
|
|
// endpoint URL from providerSpecificData.project/region, or (when project is
|
|
// not explicitly configured) from the Service Account JSON's project_id —
|
|
// the same source VertexExecutor.buildUrl uses (open-sse/executors/vertex.ts).
|
|
|
|
test("resolveOcrCredentials builds the Vertex endpoint URL from explicit providerSpecificData.project/region", () => {
|
|
const credentials = {
|
|
apiKey: "ya29.raw-access-token",
|
|
providerSpecificData: { project: "proj-explicit", region: "europe-west4" },
|
|
};
|
|
const resolved = resolveOcrCredentials(credentials, "vertex-deepseek-ocr");
|
|
assert.equal(
|
|
resolved.baseUrl,
|
|
"https://aiplatform.googleapis.com/v1/projects/proj-explicit/locations/europe-west4/endpoints/openapi/chat/completions"
|
|
);
|
|
});
|
|
|
|
test("resolveOcrCredentials defaults the Vertex region to us-central1 when unset", () => {
|
|
const credentials = { apiKey: "ya29.tok", providerSpecificData: { project: "proj-1" } };
|
|
const resolved = resolveOcrCredentials(credentials, "vertex-deepseek-ocr");
|
|
assert.equal(
|
|
resolved.baseUrl,
|
|
"https://aiplatform.googleapis.com/v1/projects/proj-1/locations/us-central1/endpoints/openapi/chat/completions"
|
|
);
|
|
});
|
|
|
|
test("resolveOcrCredentials derives the Vertex project from a Service Account JSON apiKey when providerSpecificData.project is absent", () => {
|
|
const credentials = {
|
|
apiKey: JSON.stringify({
|
|
project_id: "proj-from-sa",
|
|
client_email: "svc@x.iam",
|
|
private_key: "x",
|
|
}),
|
|
};
|
|
const resolved = resolveOcrCredentials(credentials, "vertex-deepseek-ocr");
|
|
assert.equal(
|
|
resolved.baseUrl,
|
|
"https://aiplatform.googleapis.com/v1/projects/proj-from-sa/locations/us-central1/endpoints/openapi/chat/completions"
|
|
);
|
|
});
|
|
|
|
test("resolveOcrCredentials leaves baseUrl unset when the Vertex project cannot be resolved (raw token, no providerSpecificData.project)", () => {
|
|
const credentials = { apiKey: "ya29.raw-token-no-project" };
|
|
const resolved = resolveOcrCredentials(credentials, "vertex-deepseek-ocr");
|
|
assert.equal(resolved.baseUrl, undefined);
|
|
});
|
|
|
|
test("resolveOcrCredentials keeps an explicit top-level baseUrl untouched for vertex-deepseek-ocr", () => {
|
|
const credentials = {
|
|
apiKey: "ya29.tok",
|
|
baseUrl: "https://explicit.example.com",
|
|
providerSpecificData: { project: "ignored" },
|
|
};
|
|
const resolved = resolveOcrCredentials(credentials, "vertex-deepseek-ocr");
|
|
assert.equal(resolved.baseUrl, "https://explicit.example.com");
|
|
});
|
|
|
|
test("resolveOcrCredentials is unaffected for non-vertex providers (mistral, azure-document-intelligence unchanged)", () => {
|
|
const mistral = { apiKey: "sk-mistral" };
|
|
assert.deepEqual(resolveOcrCredentials(mistral, "mistral"), mistral);
|
|
const azure = {
|
|
apiKey: "azkey",
|
|
providerSpecificData: { baseUrl: "https://r.cognitiveservices.azure.com" },
|
|
};
|
|
assert.equal(
|
|
resolveOcrCredentials(azure, "azure-document-intelligence").baseUrl,
|
|
"https://r.cognitiveservices.azure.com"
|
|
);
|
|
});
|
|
|
|
// ── resolveVertexOcrAccessToken — mints a Vertex OAuth access token from a ─
|
|
// Service Account JSON credential, reusing the exact same JWT-bearer flow
|
|
// the chat executor uses (open-sse/executors/vertex.ts::getAccessToken) —
|
|
// no new OAuth flow is implemented here.
|
|
|
|
test("resolveVertexOcrAccessToken is a no-op for non-vertex providers", async () => {
|
|
const credentials = { apiKey: JSON.stringify({ client_email: "x", private_key: "y" }) };
|
|
const resolved = await resolveVertexOcrAccessToken("mistral", credentials);
|
|
assert.equal(resolved, credentials);
|
|
});
|
|
|
|
test("resolveVertexOcrAccessToken is a no-op when an accessToken is already present", async () => {
|
|
const credentials = { apiKey: "sa-json-ignored", accessToken: "ya29.already-here" };
|
|
const resolved = await resolveVertexOcrAccessToken("vertex-deepseek-ocr", credentials);
|
|
assert.equal(resolved, credentials);
|
|
});
|
|
|
|
test("resolveVertexOcrAccessToken is a no-op for a raw (non-JSON) access token apiKey — used as-is", async () => {
|
|
const credentials = { apiKey: "ya29.raw-preminted-token" };
|
|
const resolved = await resolveVertexOcrAccessToken("vertex-deepseek-ocr", credentials);
|
|
assert.equal(resolved, credentials);
|
|
});
|
|
|
|
test("resolveVertexOcrAccessToken exchanges a Service Account JSON apiKey for a minted accessToken via the shared JWT-bearer flow", async () => {
|
|
const { privateKey } = generateKeyPairSync("rsa", {
|
|
modulusLength: 2048,
|
|
privateKeyEncoding: { type: "pkcs8", format: "pem" },
|
|
publicKeyEncoding: { type: "spki", format: "pem" },
|
|
});
|
|
const saJson = JSON.stringify({
|
|
project_id: "proj-ocr",
|
|
private_key_id: "kid-ocr-1",
|
|
client_email: "svc-ocr-route-test@example.iam.gserviceaccount.com",
|
|
private_key: privateKey,
|
|
});
|
|
|
|
const originalFetch = globalThis.fetch;
|
|
const calls: Array<{ url: string }> = [];
|
|
globalThis.fetch = async (url: string | URL | Request, options?: RequestInit) => {
|
|
calls.push({ url: String(url) });
|
|
assert.match(String(url), /oauth2\.googleapis\.com\/token$/);
|
|
assert.match(
|
|
String(options?.body ?? ""),
|
|
/grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer/
|
|
);
|
|
return new Response(JSON.stringify({ access_token: "ya29.minted-for-ocr", expires_in: 3600 }), {
|
|
status: 200,
|
|
headers: { "Content-Type": "application/json" },
|
|
});
|
|
};
|
|
|
|
try {
|
|
const credentials = { apiKey: saJson };
|
|
const resolved = await resolveVertexOcrAccessToken("vertex-deepseek-ocr", credentials);
|
|
assert.equal(resolved.accessToken, "ya29.minted-for-ocr");
|
|
// apiKey is preserved (resolveOcrCredentials may still need it to derive the project).
|
|
assert.equal(resolved.apiKey, saJson);
|
|
assert.equal(calls.length, 1);
|
|
} finally {
|
|
globalThis.fetch = originalFetch;
|
|
}
|
|
});
|