From fc3c5a1e0c72e9146d6180b8b445e65e81895bf2 Mon Sep 17 00:00:00 2001 From: li Date: Fri, 17 Jul 2026 15:15:54 +0800 Subject: [PATCH] =?UTF-8?q?fix:=20=E6=9D=83=E9=99=90=E6=A3=80=E6=9F=A5?= =?UTF-8?q?=E5=92=8C=E5=B9=B6=E5=8F=91=E6=A7=BD=E4=B9=9F=E4=BD=BF=E7=94=A8?= =?UTF-8?q?=E6=98=BE=E5=BC=8F=E6=A3=80=E6=9F=A5=EF=BC=8C=E4=BF=AE=E5=A4=8D?= =?UTF-8?q?=E8=A2=AB=E5=8A=A8=20namespace=20=E8=A7=A6=E5=8F=91=20403?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fixes #4447 --- backend/internal/handler/openai_gateway_handler.go | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/backend/internal/handler/openai_gateway_handler.go b/backend/internal/handler/openai_gateway_handler.go index a31011b8e..920a74596 100644 --- a/backend/internal/handler/openai_gateway_handler.go +++ b/backend/internal/handler/openai_gateway_handler.go @@ -276,7 +276,10 @@ func (h *OpenAIGatewayHandler) Responses(c *gin.Context) { return } - imageIntent := service.IsImageGenerationIntentForPlatform("/v1/responses", reqModel, body, openAICompatibleRequestPlatform(apiKey)) + // 使用 IsExplicitImageGenerationIntent 排除被动 image_gen namespace 声明。 + // Codex 在所有请求中被动声明 image_gen namespace,宽泛检测会导致禁了生图的 + // 分组中所有 Codex 请求被 403(#4447),并误占生图并发槽位。 + imageIntent := service.IsExplicitImageGenerationIntent("/v1/responses", reqModel, body) if imageIntent && !service.GroupAllowsImageGeneration(apiKey.Group) { h.errorResponse(c, http.StatusForbidden, "permission_error", service.ImageGenerationPermissionMessage()) return @@ -1481,7 +1484,7 @@ func (h *OpenAIGatewayHandler) ResponsesWebSocket(c *gin.Context) { return } - imageIntent := service.IsImageGenerationIntentForPlatform("/v1/responses", reqModel, firstMessage, openAICompatibleRequestPlatform(apiKey)) + imageIntent := service.IsExplicitImageGenerationIntent("/v1/responses", reqModel, firstMessage) if imageIntent && !service.GroupAllowsImageGeneration(apiKey.Group) { closeOpenAIClientWS(wsConn, coderws.StatusPolicyViolation, service.ImageGenerationPermissionMessage()) return