IanShaw
1429e8f714
修复 PR 5888 剩余审计问题
2026-08-20 22:01:20 -07:00
IanShaw
b2b2adcf8d
修复 PR 5888 审查发现的兼容性与竞态问题
2026-08-20 21:06:48 -07:00
IanShaw
48615d5d1f
Merge remote-tracking branch 'upstream/main' into fix/openai-responses-compatibility
...
# Conflicts:
# backend/internal/handler/ops_error_logger.go
2026-08-20 00:31:12 -07:00
IanShaw
c374ff2951
完善 OpenAI 网关切换与运维错误语义
2026-08-19 23:13:40 -07:00
wucm667
6b0ec50f24
fix(ops): exclude model configuration errors from SLA
...
404 model_not_found remains unchanged while ops attribution becomes routing/business-limited.
2026-08-20 10:52:29 +08:00
IanShaw
cf3577a3c5
fix(openai): harden Responses compatibility
2026-08-19 09:03:37 -07:00
Wesley Liddick and GitHub
774ff5d8c8
Merge pull request #4515 from BenjaminAaron196/feat/filter-noise-rejected-requests
...
(fix) 过滤入口拒绝日志并强化鉴权安全边界
2026-07-18 20:46:50 +08:00
haruka
bd0f2d6405
fix: report chat stream transport failures
2026-07-18 03:24:04 +08:00
benjamin
b92bbf0299
fix: 过滤入口拒绝日志并强化鉴权边界
2026-07-18 00:11:18 +08:00
Eyre921
5aba53d542
fix(ops): 记录固化 200 SSE 流上的就地错误,修复流内限流不进错误看板
...
流式请求一旦 flush 了 keepalive ping,HTTP 状态码即固化为 200;此后
出现的错误(等待并发槽位超时后回退的限流、Wait 后二次计费校验失败、
流开始后才无可用账号等)只能就地以 SSE error 帧回传。而 ops_error_logger
以 status>=400 为采集触发条件,这类挂在 200 流上的失败此前会在错误看板里
完全隐形——客户端能收到 rate_limit_error,但网关侧没有任何错误记录可供排障。
- service: 新增 OpsStreamError 上下文 + MarkOpsStreamError/GetOpsStreamError,
采用「首个标记生效」保留根因错误,避免被后续通用兜底帧覆盖。
- handler: handleStreamingAwareError 在 streamStarted 分支标记流内错误。
- handler: OpsErrorLoggerMiddleware 在 status<400 且无上游错误上下文时,
据标记补记一条错误日志;分级用 IntendedStatus(如并发限流 429),
StatusCode 仍记 wire 的 200。上游透传错误已由 upstream-context 分支落库,
故此路径不重复记录。
- 补充单测覆盖补记、no-op、skip_monitoring 跳过与首个标记生效。
2026-07-08 02:51:51 +00:00
ddf063352a
feat(ops): 错误日志 key 归因与早退字段补全
...
让 /admin/ops 错误详情正确归因 API key 并补全早退场景字段,合并三项改动:
- 鉴权早退补全用户/分组/平台字段:引入 ops fallback key(ContextKeyOpsFallbackAPIKey),
apiKey 一加载成功即写入,覆盖分组停用/删除、Key 停用/过期/额度、用户停用、IP 限制等早退
路径;ops 错误日志改用 getOpsAPIKey(正式 key 优先、回退键兜底),不改「已鉴权」语义。
- 已删除 key 归因(迁移 145):删除 key 时同一事务写 deleted_api_key_audits 映射,认证失败
时用明文反查命中原所有者,错误详情展示「已删除 Key 所有者」「尝试的 Key 前缀」。
- 有效 key 报错快照前缀(迁移 147):对绑定有效 key 的错误,落库时快照明文前 8 位到
api_key_prefix(与 attempted_key_prefix 互斥),key 之后被删仍保留报错当时真实前缀。
均仅对上线后新产生的错误/删除生效。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-05 14:00:57 +08:00
benjamin and Sisyphus
c782c2d9c3
fix(ops): classify local policy denials outside SLA
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-26 17:19:09 +08:00
benjamin and Sisyphus
69305a6091
fix(ops): 排除本地客户端限制错误的 SLA 计数
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-20 22:01:33 +08:00
name
2eb622f2f6
Remove ops retry replay storage
2026-05-19 19:37:41 +08:00
wucm667
271aba1abe
fix(ops): exclude IP-denied access from SLA
2026-05-19 15:41:54 +08:00
benjamin and Sisyphus
ae6ee23e2e
fix: 调整 Ops 错误分类的 SLA 排除逻辑
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-18 16:52:06 +08:00
Ethan0x0000
f10e56be7e
refactor(test): improve type assertions in ops endpoint context tests
2026-03-24 09:52:56 +08:00
Ethan0x0000
7cd3824863
test(ops): add tests for setOpsEndpointContext and safeUpstreamURL
2026-03-21 23:49:50 +08:00
alfadb
093d7ba858
fix(ops): use normalized error type for all classification functions
...
- Compute normalizedType once and pass to classifyOpsPhase,
classifyOpsSeverity, classifyOpsIsBusinessLimited, classifyOpsIsRetryable
instead of raw parsed.ErrorType
- Add test case verifying known type takes precedence over conflicting code
Addresses Copilot review feedback on PR #680 .
2026-02-28 19:28:08 +08:00
alfadb and Claude Opus 4.6
ce006a7a91
fix(ops): validate error_type against known whitelist before classification
...
Upstream proxies (account 4, 112) return `"<nil>"` as the error.type in
their JSON responses — a Go fmt.Sprintf("%v", nil) artifact. Since
`normalizeOpsErrorType` only checked for empty string, the literal
"<nil>" passed through and poisoned the entire classification chain:
error_phase was misclassified as "internal" (instead of "request"),
severity was inflated to P2, and the stored error_type was meaningless.
Add `isKnownOpsErrorType` whitelist so any unrecognised type falls
through to the code-based or default "api_error" classification.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-28 19:28:08 +08:00
yangjianbo
bb664d9bbf
feat(sync): full code sync from release
2026-02-28 15:01:20 +08:00
yangjianbo
a89477ddf5
perf(gateway): 优化热点路径并补齐高覆盖测试
2026-02-22 13:31:30 +08:00