Spaces:
Running
Running
deploy(hf): sync szl-holdings/a11oy@f5440d365471d656807a617e6b73b5b4dbe939ea derived COPY set
Browse filesReusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy f5440d365471d656807a617e6b73b5b4dbe939ea.
Files: 1187 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).
Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- routers/frontier_reads.py +150 -0
routers/frontier_reads.py
CHANGED
|
@@ -24,8 +24,156 @@ Signed-off-by: Stephen P. Lutar Jr. <stephenlutar2@gmail.com>
|
|
| 24 |
"""
|
| 25 |
from __future__ import annotations
|
| 26 |
|
|
|
|
|
|
|
|
|
|
|
|
|
| 27 |
from fastapi.responses import JSONResponse
|
| 28 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 29 |
# ---- Vertical-pack registry (GAP-5): 13 verticals, live/stub. "Cyber Resilience"
|
| 30 |
# label avoids the literal forbidden string. NO amaru/sentra/rosie. ----
|
| 31 |
_A11OY_VERTICALS = [
|
|
@@ -47,6 +195,8 @@ _A11OY_VERTICALS = [
|
|
| 47 |
|
| 48 |
def register(app) -> dict:
|
| 49 |
"""Attach frontier reads and the additive Series-A control plane."""
|
|
|
|
|
|
|
| 50 |
import serve # shared module-scope state lives at serve module scope
|
| 51 |
|
| 52 |
@app.get("/api/a11oy/v1/forecast-baseline")
|
|
|
|
| 24 |
"""
|
| 25 |
from __future__ import annotations
|
| 26 |
|
| 27 |
+
import json
|
| 28 |
+
from datetime import datetime, timezone
|
| 29 |
+
from typing import Any, AsyncIterator
|
| 30 |
+
|
| 31 |
from fastapi.responses import JSONResponse
|
| 32 |
|
| 33 |
+
PHASE_B_OBSERVATION_PATHS = frozenset(
|
| 34 |
+
{
|
| 35 |
+
"/api/a11oy/provenance",
|
| 36 |
+
"/api/a11oy/v1/energy/sci",
|
| 37 |
+
"/api/a11oy/v1/observability/summary",
|
| 38 |
+
"/api/a11oy/v1/observability/business",
|
| 39 |
+
"/api/a11oy/v1/mesh/state",
|
| 40 |
+
}
|
| 41 |
+
)
|
| 42 |
+
PHASE_B_OBSERVATION_ALIASES = frozenset({"/v1/observability/business"})
|
| 43 |
+
KEVGATE_PATHS = frozenset({"/api/a11oy/v1/sec/kev"})
|
| 44 |
+
_PHASE_B_MUTATED_PATHS = (
|
| 45 |
+
PHASE_B_OBSERVATION_PATHS
|
| 46 |
+
| PHASE_B_OBSERVATION_ALIASES
|
| 47 |
+
| KEVGATE_PATHS
|
| 48 |
+
)
|
| 49 |
+
|
| 50 |
+
|
| 51 |
+
def utc_observation_clock() -> str:
|
| 52 |
+
"""Return one genuine request-time UTC observation clock."""
|
| 53 |
+
return datetime.now(timezone.utc).isoformat().replace("+00:00", "Z")
|
| 54 |
+
|
| 55 |
+
|
| 56 |
+
def normalize_phase_b_payload(
|
| 57 |
+
path: str,
|
| 58 |
+
payload: Any,
|
| 59 |
+
*,
|
| 60 |
+
observed_at: str | None = None,
|
| 61 |
+
status_code: int = 200,
|
| 62 |
+
) -> Any:
|
| 63 |
+
"""Apply the closed Phase-B vocabulary to one decoded JSON value.
|
| 64 |
+
|
| 65 |
+
Supplying ``observed_at`` makes the function deterministic for regression
|
| 66 |
+
tests. Unknown paths and non-object values are returned without semantic
|
| 67 |
+
changes. Error responses are never rewritten into cached KEV evidence.
|
| 68 |
+
"""
|
| 69 |
+
if not isinstance(payload, dict):
|
| 70 |
+
return payload
|
| 71 |
+
|
| 72 |
+
normalized = dict(payload)
|
| 73 |
+
if (
|
| 74 |
+
path in PHASE_B_OBSERVATION_PATHS
|
| 75 |
+
or path in PHASE_B_OBSERVATION_ALIASES
|
| 76 |
+
):
|
| 77 |
+
normalized["observed_at"] = observed_at or utc_observation_clock()
|
| 78 |
+
|
| 79 |
+
if path in KEVGATE_PATHS and 200 <= int(status_code) < 300:
|
| 80 |
+
raw_kind = str(normalized.get("data_kind") or "").strip().casefold()
|
| 81 |
+
canonical_kind = "live" if raw_kind == "live" else "cached"
|
| 82 |
+
normalized["data_kind"] = canonical_kind
|
| 83 |
+
|
| 84 |
+
detail = normalized.get("detail")
|
| 85 |
+
if not isinstance(detail, str) or not detail.strip():
|
| 86 |
+
note = normalized.get("note")
|
| 87 |
+
if isinstance(note, str) and note.strip():
|
| 88 |
+
detail = note
|
| 89 |
+
elif canonical_kind == "live":
|
| 90 |
+
detail = (
|
| 91 |
+
"The KEV source identified this response as live during "
|
| 92 |
+
"the current request; reachability is not independent "
|
| 93 |
+
"validation."
|
| 94 |
+
)
|
| 95 |
+
else:
|
| 96 |
+
detail = (
|
| 97 |
+
"Bundled CISA KEV snapshot served from the current image; "
|
| 98 |
+
"this is cached source material, not a live catalog fetch."
|
| 99 |
+
)
|
| 100 |
+
normalized["detail"] = detail
|
| 101 |
+
|
| 102 |
+
return normalized
|
| 103 |
+
|
| 104 |
+
|
| 105 |
+
async def _phase_b_single_body(body: bytes) -> AsyncIterator[bytes]:
|
| 106 |
+
yield body
|
| 107 |
+
|
| 108 |
+
|
| 109 |
+
def install_phase_b_response_contract(app: Any) -> None:
|
| 110 |
+
"""Install the exact-path JSON normalizer once."""
|
| 111 |
+
state = getattr(app, "state", None)
|
| 112 |
+
marker = "_readiness_phase_b_response_contract_installed"
|
| 113 |
+
if state is not None and getattr(state, marker, False):
|
| 114 |
+
return
|
| 115 |
+
if state is not None:
|
| 116 |
+
setattr(state, marker, True)
|
| 117 |
+
|
| 118 |
+
@app.middleware("http")
|
| 119 |
+
async def _phase_b_response_contract(
|
| 120 |
+
request: Any,
|
| 121 |
+
call_next: Any,
|
| 122 |
+
) -> Any:
|
| 123 |
+
response = await call_next(request)
|
| 124 |
+
path = request.url.path
|
| 125 |
+
if path not in _PHASE_B_MUTATED_PATHS:
|
| 126 |
+
return response
|
| 127 |
+
|
| 128 |
+
content_type = response.headers.get("content-type", "").casefold()
|
| 129 |
+
if "json" not in content_type:
|
| 130 |
+
return response
|
| 131 |
+
content_encoding = response.headers.get(
|
| 132 |
+
"content-encoding",
|
| 133 |
+
"identity",
|
| 134 |
+
).casefold()
|
| 135 |
+
if content_encoding not in {"", "identity"}:
|
| 136 |
+
return response
|
| 137 |
+
|
| 138 |
+
iterator = getattr(response, "body_iterator", None)
|
| 139 |
+
if iterator is None:
|
| 140 |
+
return response
|
| 141 |
+
|
| 142 |
+
chunks: list[bytes] = []
|
| 143 |
+
async for chunk in iterator:
|
| 144 |
+
if isinstance(chunk, bytes):
|
| 145 |
+
chunks.append(chunk)
|
| 146 |
+
elif isinstance(chunk, str):
|
| 147 |
+
chunks.append(chunk.encode("utf-8"))
|
| 148 |
+
else:
|
| 149 |
+
chunks.append(bytes(chunk))
|
| 150 |
+
raw = b"".join(chunks)
|
| 151 |
+
|
| 152 |
+
try:
|
| 153 |
+
payload = json.loads(raw.decode("utf-8"))
|
| 154 |
+
except (UnicodeDecodeError, json.JSONDecodeError):
|
| 155 |
+
response.body_iterator = _phase_b_single_body(raw)
|
| 156 |
+
response.headers["content-length"] = str(len(raw))
|
| 157 |
+
return response
|
| 158 |
+
|
| 159 |
+
normalized = normalize_phase_b_payload(
|
| 160 |
+
path,
|
| 161 |
+
payload,
|
| 162 |
+
status_code=int(getattr(response, "status_code", 200)),
|
| 163 |
+
)
|
| 164 |
+
encoded = json.dumps(
|
| 165 |
+
normalized,
|
| 166 |
+
ensure_ascii=False,
|
| 167 |
+
separators=(",", ":"),
|
| 168 |
+
).encode("utf-8")
|
| 169 |
+
response.body_iterator = _phase_b_single_body(encoded)
|
| 170 |
+
response.headers["content-length"] = str(len(encoded))
|
| 171 |
+
for stale_validator in ("etag", "content-md5"):
|
| 172 |
+
if stale_validator in response.headers:
|
| 173 |
+
del response.headers[stale_validator]
|
| 174 |
+
return response
|
| 175 |
+
|
| 176 |
+
|
| 177 |
# ---- Vertical-pack registry (GAP-5): 13 verticals, live/stub. "Cyber Resilience"
|
| 178 |
# label avoids the literal forbidden string. NO amaru/sentra/rosie. ----
|
| 179 |
_A11OY_VERTICALS = [
|
|
|
|
| 195 |
|
| 196 |
def register(app) -> dict:
|
| 197 |
"""Attach frontier reads and the additive Series-A control plane."""
|
| 198 |
+
install_phase_b_response_contract(app)
|
| 199 |
+
|
| 200 |
import serve # shared module-scope state lives at serve module scope
|
| 201 |
|
| 202 |
@app.get("/api/a11oy/v1/forecast-baseline")
|