shaw
539bfc8bad
feat(security): 敏感操作 step-up 2FA 开关化,安全开关默认关闭
...
新增系统设置 step_up_enabled(默认关闭),把敏感操作 2FA 门控做成可开关;
同时将会话 IP/UA 绑定默认值从开启改为关闭,避免用户因 IP 变动登录后掉线。
## 新增功能
- 敏感操作 step-up 2FA 总开关 step_up_enabled(默认关闭):关闭时账号/代理导出、
备份创建/下载、S3 配置修改、提升管理员等操作恢复门控引入前的直接放行行为;
开启后要求当前会话在 15 分钟内完成过 TOTP step-up 验证。
## 优化改进
- 会话 IP/UA 绑定默认改为关闭(功能保留,可在设置页按需开启)。
- 开启 step-up 开关需操作者本人已启用 TOTP(防自锁);关闭开关本身作为敏感操作,
需通过 step-up 验证(防止攻击者拿到会话后先关闸再导出/备份)。
- 两个安全开关请求字段改为可空指针(省略=保持现值),避免旧客户端全量保存时
静默重置安全开关。
- 备份恢复(整库覆盖可回滚安全设置)纳入 step-up 门控。
- 审计摘要 diffSettings 补记 step_up_enabled / session_binding_enabled 变更。
## Bug 修复
- 修复 BackupView 恢复操作 409(恢复进行中)判断未适配 apiClient 扁平化错误对象。
2026-07-18 10:46:42 +08:00
Wesley Liddick and GitHub
8bfbc5ca99
Merge pull request #4485 from Sub2API-Devs/dev
...
feat(security-audit): 新增 OpenAI 兼容提示词审计能力与安全审计控制台
2026-07-17 16:15:26 +08:00
Wesley Liddick and GitHub
cb40288fb8
Merge pull request #4479 from fengshao1227/fix/backup-s3-stepup-totp
...
fix(frontend): saveS3Config 接入 step-up TOTP 门控
2026-07-17 16:14:49 +08:00
Wesley Liddick and GitHub
33766c299f
Merge pull request #4481 from fengshao1227/fix/passive-image-namespace-capability
...
fix(gateway): 被动 image_gen namespace 不再强制要求 Responses capability
2026-07-17 16:14:35 +08:00
Wesley Liddick and GitHub
13468b3fa5
Merge pull request #4484 from heathermhuang/codex/fix-grok-scheduler-media-cache
...
fix(grok): preserve media eligibility in scheduler cache
2026-07-17 16:13:31 +08:00
shaw
bc50c9d013
chore: update sponsors
2026-07-17 14:05:59 +08:00
Wesley Liddick and GitHub
dda20ae9a6
Merge pull request #4474 from heathermhuang/codex/fix-grok-media-image-url-4420
...
v0.1.159 fix(grok): normalize media payloads and quarantine ineligible accounts
2026-07-17 13:49:09 +08:00
Wesley Liddick and GitHub
2a75d7d238
Merge pull request #4462 from Wei-Shaw/fix/unify-security-client-ip
...
fix(security): unify audit log & session binding client IP with API key ACL trust toggle
2026-07-17 09:42:43 +08:00
Wesley Liddick and GitHub
1c3f2810af
Merge pull request #4461 from yardbirds0/feat/account-homepage-link
...
feat: 支持从 API Key 账号名称跳转上游站点主页
2026-07-17 09:34:50 +08:00
shaw and Claude
7c48f9a85f
fix(security): unify audit log & session binding client IP with API key ACL trust toggle
...
Behind a reverse proxy (e.g. nginx with X-Real-IP), admin audit logs and
session IP/UA binding always recorded 127.0.0.1 because they hardcoded
the gin trusted_proxies chain, while API key IP restriction already
honored the "trust forwarded client IP" system setting.
- add ip.GetSecurityClientIP(c, trustForwarded) as the single source of
truth for security-sensitive client IP selection; API key auth
middlewares (main + google) refactored onto it with zero behavior change
- SessionBindingContext(cfg) now resolves the client IP via the same
toggle and injects it into the request context; token issuance,
binding enforcement and its mismatch audit record all read the
injected value, so issue/verify can never diverge
- audit log middleware and audit-log clear trace record the same
security client IP (middleware.SecurityClientIP), falling back to the
trusted proxy chain when the injection is absent
- settings UI hint (zh/en) documents the broadened toggle scope and the
one-time re-login after toggling while session binding is enabled
With the toggle off (default) behavior is byte-for-byte unchanged.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-07-17 09:33:18 +08:00
shaw and Claude
980a46ffb0
fix(i18n): add missing OpenAI account entry labels
...
- admin.accounts.oauth.openai.mobileRefreshTokenAuth was referenced by
OAuthAuthorizationFlow.vue since 9f8cffe88 (Mobile RT entry) but never
added to zh/en locales, rendering the raw key in the add-account wizard
- admin.accounts.oauth.openai.accessTokenAuth has the same latent issue
since 26060e702 (Sora AT import); currently hidden but fixed alongside
Co-Authored-By: Claude <noreply@anthropic.com >
2026-07-17 09:32:48 +08:00
Wesley Liddick and GitHub
9b3c96dc68
Merge pull request #4451 from rurucxk/fix/grok-free-responses-function-tool-cache
...
fix(grok): enable free prompt cache for Responses function tools
2026-07-17 09:04:47 +08:00
Wesley Liddick and GitHub
52f2bc69fb
Merge pull request #4450 from wucm667/fix/issue-4442-lazy-stripe-loader
...
fix(frontend): lazy-load Stripe payment dependency
2026-07-17 09:04:33 +08:00
Wesley Liddick and GitHub
067cf8b46e
Merge pull request #4459 from Wei-Shaw/fix/openai-alpha-search-apikey-scheduling
...
fix(openai): restore APIKey account scheduling for alpha/search
2026-07-17 09:04:17 +08:00
shaw
d2b080e88b
fix(openai): restore APIKey account scheduling for alpha/search
...
PR #4394 (776f3f0de ) 在新增 alpha_search 调度能力时加入了 OAuth-only
门控,把 APIKey 账号从 /alpha/search 候选池整体剔除;但转发层自
52071d391 起就支持 APIKey 走 {base_url}/v1/alpha/search,门控注释中
「API key 会被发往 chatgpt.com 导致 401」与实际路由不符。结果是纯
APIKey 分组自 v0.1.157 起独立搜索在选号阶段即失败(无可用账号)。
修复:
- SupportsOpenAIEndpointCapability 的 alpha_search 门控放行
AccountTypeAPIKey(OAuth/APIKey 均可,Grok 等仍拒绝);显式能力集
语义不变,chat_completions 继续隐含放行 alpha_search。
- ForwardAlphaSearch 对 APIKey 账号的 404/405 按端点级 failover 处理
(换号、不写账号错误状态),避免混合分组里请求死在不支持该端点的
APIKey 上游;OAuth 账号 404 透传行为保持不变。
- 更新固化旧门控行为的用例,并在调度层新增 APIKey 放行回归锁。
2026-07-17 08:44:23 +08:00
Wesley Liddick and GitHub
26abd19a28
Merge pull request #4433 from heathermhuang/codex/fix-grok-regressions-4412-4421
...
fix(grok): repair OAuth media and compatibility regressions
2026-07-16 20:16:46 +08:00
shaw
c29b50394f
Merge main (fix batch-limits test typecheck breaking CI)
2026-07-16 20:05:48 +08:00
shaw
3d23cc399f
fix(admin): align batch-limits test with expanded NewUserHandler signature
...
PR #4425 was authored before #4429 widened NewUserHandler with the
step-up TOTP and user services, and merged without a rebase, breaking
typecheck on main.
2026-07-16 20:05:31 +08:00
shaw
c1fd1cb44e
Merge origin/main into codex/fix-grok-regressions-4412-4421
...
Reconcile the OAuth media route with the manual endpoint-switch redesign
(7f5d067af ): media leaves for api.x.ai only when text traffic resolves to
the CLI gateway host; manually selected official/regional/custom endpoints
keep serving media as-is.
2026-07-16 19:57:48 +08:00
Wesley Liddick and GitHub
7e13b6d039
Merge pull request #4425 from AdrianZhaoDev/agent/admin-users-batch-limits
...
feat(admin): batch update user concurrency and RPM
2026-07-16 19:33:32 +08:00
Wesley Liddick and GitHub
c993490a82
Merge pull request #4434 from yan9651688/feat/group-one-click-copy
...
feat(group): add safe one-click duplication
2026-07-16 19:33:18 +08:00
Wesley Liddick and GitHub
4d91f39474
Merge pull request #4431 from linyqh/codex/fix-codex-image-handoff
...
fix(openai): 修复 Codex 生图网关侧交接问题
2026-07-16 19:32:33 +08:00
Wesley Liddick and GitHub
af6bd44d2a
Merge pull request #4435 from superman2003/fix/grok-codex-wsv2-template
...
fix(grok): enable Codex Responses WebSocket v2 in setup template
2026-07-16 19:32:14 +08:00
Wesley Liddick and GitHub
541ca3bc27
Merge pull request #4430 from feitianbubu/fix/proxy-fallback-label
...
fix(i18n): 代理"失败回退"改名"到期回退",与实际行为一致
2026-07-16 19:32:04 +08:00
shaw
7f5d067af2
feat(grok): 支持上游端点手动切换与快捷端点,修复 SSO 建号自定义地址被覆盖
...
官方端点(api.x.ai / cli-chat-proxy.grok.com)偶发不可用,运营方需要在
端点间手动切换。旧语义把 OAuth 账号存储的官方 host 一律视同"未定制"并
回落默认 CLI 网关:填了官方地址保存成功却不生效、重新编辑开关回到关闭、
再次保存直接删值,形成"修改不生效"的静默循环。
后端:
- GetGrokBaseURL OAuth 分支改为"存了什么用什么":官方 API / 区域 API /
第三方转发地址一律按填写值转发与探测,仅空值或无法解析的脏数据回落
默认 CLI 网关;删除官方变体运行时迁移逻辑
- *.api.x.ai 区域端点(us-east-1/us-west-2/eu-west-1 等)纳入可信 host,
OAuth 使用时不受运营方 URL 白名单限制,官方 host 仍强制 /v1 path
- 修复 SSO 批量建号 MergeCredentials 方向缺陷:BuildAccountCredentials
恒写官方 base_url,会覆盖导入请求指定的自定义转发地址;抽出
grokSSOImportCredentials 显式保留请求值(与 RefreshAccountToken 对齐)
前端:
- isCustomGrokBaseUrl 仅默认 CLI 网关 host 视同未定制:api.x.ai 与区域
端点保存后正常回显(开关开启 + 显示地址),不再被静默吞掉
- 新增 GrokBaseUrlPresets 快捷端点组件(Grok Build CLI / 官方 API /
us-east-1 / us-west-2 / eu-west-1),接入编辑(OAuth 自定义区 + apikey
Base URL)、新增(同前)与批量编辑(所选平台全为 grok 时显示,点击
自动勾选 base_url);仅快速填充,输入框仍可自由填写任意第三方地址
2026-07-16 19:10:21 +08:00
shaw
b960ec1980
chore: update sponsors
2026-07-16 17:45:13 +08:00
Wesley Liddick and GitHub
a2779cd5f3
Merge pull request #4428 from alfadb/fix/anthropic-haiku-full-mimicry
...
fix(gateway): 修复 Haiku OAuth 请求被归入额外用量
2026-07-16 16:55:11 +08:00
Wesley Liddick and GitHub
dbef64bb45
Merge pull request #4427 from yan9651688/feat/channel-monitor-one-click-copy
...
feat(channel-monitor): add safe one-click duplication
2026-07-16 16:54:22 +08:00
Wesley Liddick and GitHub
3ecfcc48ae
Merge pull request #4429 from Wei-Shaw/feat/role-stepup-admin-2fa-password
...
feat(security): 角色提升纳入 step-up 2FA + 管理员 2FA 密码验证 + 审计日志页优化
2026-07-16 16:53:51 +08:00
shaw
35748d8c51
feat(security): gate admin role promotion behind step-up 2FA and harden admin TOTP verification
...
- 提升用户为管理员 / 创建管理员账号纳入敏感操作:handler 级 EnforceStepUp 门控
(admin API key 拒绝、未启用 TOTP 拒绝、无 grant 返回 STEP_UP_REQUIRED),
目标已是管理员的日常编辑不触发
- 管理员启用/停用 2FA 一律使用密码验证(默认通知邮箱常收不到验证码),
verification-method 按用户角色返回;普通用户行为不变
- 用户编辑/创建弹窗接入 useStepUp:命中 STEP_UP_REQUIRED 弹 TOTP 验证并自动重试
- 审计日志清理入口与其他敏感操作对齐:未启用 2FA 时直接提示先启用 TOTP,
不再弹出无法完成的验证码输入框(后端强制现场 TOTP 语义不变)
- 审计日志页重构:DataTable 布局、详情弹窗分区展示、时间范围改为 ops 同款
下拉(预设窗口 + 自定义起止支持时分)
2026-07-16 16:49:08 +08:00
Wesley Liddick and GitHub
393a8fe56a
Merge pull request #4424 from StarryKira/fix/4417-responses-image-account-capability
...
fix(gateway): route image-intent /v1/responses only to Responses-capable accounts (#4417 )
2026-07-16 15:35:45 +08:00
Wesley Liddick and GitHub
09729ba54c
Merge pull request #4406 from StarryKira/agent/fix-4326-async-image-object-storage
...
feat: 异步生图任务与结果轮询(重新引入 #4381)+ 结果落对象存储
2026-07-16 15:35:04 +08:00
shaw
590efe29a5
Merge remote-tracking branch 'origin/main' into agent/fix-4326-async-image-object-storage
...
# Conflicts:
# backend/cmd/server/wire_gen.go
2026-07-16 15:32:38 +08:00
Wesley Liddick and GitHub
813920607e
Merge pull request #4418 from Wei-Shaw/feat/audit-log-and-credential-hardening
...
feat(security): 操作审计日志 + 会话IP/UA绑定 + 敏感操作 step-up 2FA
2026-07-16 15:27:13 +08:00
shaw
2d97207d41
fix(settings): 审计日志保留天数清空时回退默认值避免保存 400
...
audit_log_retention_days 用 v-model.number 绑定数字框,管理员清空输入框时
得到空串,后端 int 字段 ShouldBindJSON 解析空串失败返回 400,导致整次系统
设置保存被拒。payload 构建时对空/非法值回退默认 180(与后端
parseAuditLogRetentionDays("") 语义一致;显式 0 仍表示永久保留)。
2026-07-16 15:19:19 +08:00
shaw
d67a2cad2b
fix(lint): 检查 audit 键归一化中 WriteRune 返回值 (errcheck)
...
golangci-lint errcheck 报 audit_log.go:115 未检查 (*strings.Builder).WriteRune
返回值。Builder.WriteRune 永不返回错误,按仓库惯例以 _, _ = 显式丢弃。
2026-07-16 15:05:19 +08:00
shaw
2de6ccb071
fix(security): 补齐审计日志脱敏缺口 + step-up 下载/取消体验修复
...
审计发现修复:
高危——审计日志请求体脱敏不全(audit_logs 沦为明文凭证聚合点):
- 键名归一化比对(小写+去分隔符),覆盖 privateKey/apiv3key 等无分隔符与 camelCase 写法
- 程序化并入 SensitiveCredentialKeys 与 providerSensitiveConfigFields 两份权威敏感表,防清单漂移
- 补齐 proxy_key(内嵌代理密码)、custom_key(自设 API Key 明文)精确键
- Codex session 导入路由 body 整体由粘贴的 auth JSON 构成,键级脱敏无法覆盖,整体不入库
- 新增守卫测试:两份权威表的每个键必须被审计脱敏命中;provider_key 等渠道标识保留以便追责
中危——step-up 前端体验:
- 备份下载改同页 anchor 导航(预签名 URL 后端强制 attachment disposition),
避免 step-up 弹窗 await 耗尽瞬态激活后 window.open 被浏览器拦截
- useStepUp.run 用户取消时抛 StepUpCancelledError sentinel,
三个调用点静默处理,不再把取消误报为红色错误 toast
低危:
- 修正审计中间件挂载位置的陈旧注释(实际挂在认证之后)
- 审计 body 捕获改 LimitReader 按 256KB 上限截断读取,超出部分拼接回填,
避免大体积导入请求被完整复制进内存两次
- TOTP step-up 弹窗验证成功后即时清空验证码输入
2026-07-16 14:38:16 +08:00
shaw
a1af031969
fix(test): gofmt 审计日志测试 + 补齐 settings 契约 golden 两新字段
...
- audit_log_test.go: gofmt map 对齐
- api_contract_test.go: GET /admin/settings 两处 golden 补 session_binding_enabled/audit_log_retention_days
2026-07-16 13:58:50 +08:00
shaw
0ddd58aaf9
feat(security): 操作审计日志 + 会话IP/UA绑定 + 敏感操作 step-up 2FA
...
应对管理员访问凭证失守导致的数据外泄风险,新增三层防护:
审计日志(admin-only 可见,用户不可见)
- 新增 append-only audit_logs 表(migration 180)+ 异步批量写入 + 保留期清理
- 审计中间件挂在 admin/user/auth/admin-payment 组认证之后:记录所有变更类
请求 + 白名单敏感读取(账号/代理导出、备份下载、admin/user API key 读取)
- 请求头凭证首尾掩码;请求体 JSON 递归脱敏(api_key/password 等擦除,base_url
保留以便追责);非 JSON body 不入库
- 无单条删除;全量清空需现场 TOTP 校验、拒绝 admin API key、未启用 2FA 不允许,
清空后同步写入留痕记录
会话 IP/UA 绑定(默认开启,可在系统设置关闭)
- JWT 携带 session id + IP/UA 指纹哈希;IP 或 UA 任一变化即撤销会话家族并要求
重新登录;旧 token 无指纹时放行以平滑升级
敏感操作 step-up 2FA(sudo 窗口 15 分钟)
- 账号/代理导出、DB 备份创建/下载、S3 目标修改要求近期 TOTP 二次验证;admin API
key 一律拒绝;前端 useStepUp 组合式 + TotpStepUpDialog 弹码后自动重试
- API key 查看按需求暂不加强管控
前端:新增 /admin/audit-logs 操作日志页面(筛选/详情/2FA 清空)、侧边栏入口、
step-up 弹窗接入导出与备份流程、安全设置项(绑定开关 + 日志保留天数)、zh/en i18n
2026-07-16 13:47:50 +08:00
Wesley Liddick and GitHub
09c6c6d740
Merge pull request #4387 from yardbirds0/feat/upstream-rate-scheduling
...
feat: 按上游计费倍率调度 OpenAI 账号
2026-07-16 10:46:29 +08:00
shaw
0408bdb34f
Merge remote-tracking branch 'origin/main' into feat/upstream-rate-scheduling
...
# Conflicts:
# backend/internal/handler/openai_gateway_handler.go
2026-07-16 10:31:21 +08:00
Wesley Liddick and GitHub
ab978e615e
Merge pull request #4385 from yardbirds0/feat/upstream-billing-probe
...
feat: 增加上游 Sub2API 计费倍率探测与账号展示
2026-07-16 10:27:45 +08:00
Wesley Liddick and GitHub
8d36ce3d20
Merge pull request #4108 from yardbirds0/feat/key-billing-info
...
feat: 增加 API Key 计费倍率自省接口
2026-07-16 10:27:35 +08:00
shaw
e2bb90a80d
fix(test): tls.peet.ws 站点故障时跳过 TLS 指纹集成测试
...
skipIfExternalServiceUnavailable 的不可用特征清单漏掉 EOF/connection
reset/broken pipe,站点半死返回空响应断开时测试走 Fatalf 导致 CI 必红。
补齐特征清单,并把读体失败、非 200 状态码、响应体非法 JSON 一并归为
外部服务不可用跳过;站点健康时指纹校验行为不变。
2026-07-16 09:51:41 +08:00
Wesley Liddick and GitHub
08828293b7
Merge pull request #4404 from Wei-Shaw/revert-4381-agent/fix-4326-async-image-tasks
...
Revert "feat: 支持异步生图任务与结果轮询"
2026-07-16 09:48:09 +08:00
Wesley Liddick and GitHub
a3a227c858
Merge pull request #4381 from StarryKira/agent/fix-4326-async-image-tasks
...
feat: 支持异步生图任务与结果轮询
2026-07-16 09:44:26 +08:00
Wesley Liddick and GitHub
51f2b0e3ee
Merge pull request #4382 from wp-a/fix/openai-responses-rejected-field-retries
...
[codex] retry explicitly rejected Responses fields
2026-07-16 09:37:36 +08:00
Wesley Liddick and GitHub
531ae04a0b
Merge pull request #4395 from wp-a/fix/openai-body-limit-failover
...
[codex] fail over account-specific OpenAI body limits
2026-07-16 09:33:48 +08:00
Wesley Liddick and GitHub
e4329a04e8
Merge pull request #4393 from superman2003/fix/grok-codex-compatibility
...
fix(grok): improve Codex compatibility and key setup
2026-07-16 09:33:20 +08:00
Wesley Liddick and GitHub
f3138ceb43
Merge pull request #4384 from wp-a/fix/openai-model-scoped-transient-cooldown
...
[codex] scope OpenAI transient cooldowns by model
2026-07-16 09:33:09 +08:00
Wesley Liddick and GitHub
1c5c42c183
Merge pull request #4394 from siyuan-123/codex/pr-gpt56-pat-alpha-search
...
fix(openai): route PAT alpha search via responses web_search
2026-07-16 09:32:59 +08:00
Wesley Liddick and GitHub
3fc0336e1d
Merge pull request #4377 from wp-a/fix/openai-ws-ingress-lifecycle
...
[codex] close OpenAI WS ingress reads cleanly
2026-07-16 09:32:50 +08:00
Wesley Liddick and GitHub
807850769f
Merge pull request #4396 from StarryKira/fix/4386-image-input-pricing
...
fix(billing): 图像输入 token 按独立单价计费(gpt-image-2 图片编辑)
2026-07-16 09:32:29 +08:00
Wesley Liddick and GitHub
8852194670
Merge pull request #4402 from wucm667/fix/issue-4399-oauth-image-usage
...
fix(openai): 修复 OAuth 生图工具用量计费
2026-07-16 09:32:18 +08:00
Wesley Liddick and GitHub
4226ff8e3a
Merge pull request #4392 from jianjianai/new/perf-bulk-account-platform-scope
...
perf(scheduler): 按平台收窄批量账户事件重建
2026-07-16 09:31:59 +08:00
Wesley Liddick and GitHub
ff08694d79
Merge pull request #4400 from jianjianai/new/perf-scheduler-payload-reuse
...
perf: 复用同批次调度快照账号载荷写入
2026-07-16 09:31:51 +08:00
Wesley Liddick and GitHub
7e43ebc792
Merge pull request #4369 from wp-a/fix/openai-wsv2-malformed-json
...
[codex] reject malformed OpenAI WS v2 events
2026-07-16 09:31:39 +08:00
Wesley Liddick and GitHub
4a50d05393
Merge pull request #4380 from wucm667/fix/issue-4357-responses-lite-context
...
fix(openai): normalize Responses Lite reasoning context
2026-07-16 09:31:29 +08:00
Wesley Liddick and GitHub
ba01199812
Merge pull request #4376 from drgnchan/hotfix/find-n6-table-scroll
...
fix(frontend): preserve horizontal table scrolling on tablets
2026-07-16 09:31:16 +08:00
Wesley Liddick and GitHub
25d7797d83
Merge pull request #4379 from wucm667/fix/issue-4348-reject-image-chat-models
...
fix(openai): reject image models on chat completions
2026-07-16 09:31:05 +08:00
shaw
eb2b8632de
fix(frontend): 修复 Grok OAuth 建号缺上游配置入口与 JSON 导入渲染崩溃
...
- CreateAccountModal 为 Grok OAuth 新增自定义上游地址与请求头覆写区块,
经统一校验注入授权码兑换/RT 批量/SSO 批量三条创建路径(授权码路径
在兑换前校验,避免烧掉一次性 code)
- JSON 导入示例文案内嵌花括号被 vue-i18n 消息编译器当占位符解析,
渲染时抛 Invalid token in placeholder 炸掉面板:示例移出 i18n 硬编码;
同类修复 settings 的死键 claudeOAuthSystemPromptBlocksPlaceholder(删)
与 Hint 中被吞掉的 {billing_header}(字面量转义)
- 新增 localesMessageCompile 守卫测试:预编译中英全部文案,拦截非法占位符
- 面板打开后 scrollIntoView + 聚焦,避免在弹窗滚动容器视野外展开
- 删除「填入模板」按钮及三平台模板常量(产品决策:无意义)
- 抽取 HeaderOverrideEditor 共享组件,消除 Create/Edit/BulkEdit 三处重复
2026-07-15 22:05:59 +08:00
Wesley Liddick and GitHub
be6cd1250c
Merge pull request #4367 from Wei-Shaw/feat/grok-custom-base-url-and-headers
...
feat(grok): 支持账号级自定义上游地址与请求头覆写
2026-07-15 20:55:16 +08:00
Wesley Liddick and GitHub
34015a1791
Merge pull request #4359 from catoncat/agent/fix-agent-identity-import-expiry
...
fix(openai): make Agent Identity usable end to end
2026-07-15 20:55:05 +08:00
Wesley Liddick and GitHub
a733e66330
Merge pull request #4358 from DanisJiang/feat/admin-recharge-affiliate-rebate
...
feat(affiliate): support rebates for admin balance deposits
2026-07-15 20:54:48 +08:00
Wesley Liddick and GitHub
960d1886f3
Merge pull request #4323 from turingcat/feat/plan-currency-label
...
feat(payment): 订阅套餐支持币种标注,区分 $ 符号对应币种
2026-07-15 20:54:34 +08:00
shaw
221581400b
feat(grok): 支持账号级自定义上游地址与请求头覆写
...
将账号级请求头覆写从 anthropic/openai 的 api_key 账号扩展到 Grok 的
api_key 与 oauth 账号,并放开 Grok OAuth 账号的自定义上游地址(仅作用于
转发端点,授权与 token 刷新链路不变)。
后端:
- IsHeaderOverrideEligible 扩展到 Grok(api_key+oauth),禁止名单新增
x-grok-conv-id(逐请求会话路由头)。
- 所有 Grok 上游请求路径接线 ApplyHeaderOverrides(Responses/Chat 桥/
媒体/配额探测/billing 探测/连通性测试),统一置于内置默认头之后。
- GetGrokBaseURL/GetGrokMediaBaseURL 放开 OAuth 自定义地址:官方地址
视同未定制回落官方网关,仅显式第三方 host 改发转发流量。
- 非官方 host 允许任意 path 前缀,官方 host 仍强制 /v1。
- OAuth base_url 校验按 host 判定官方/自定义,自定义 host 恒受运营方
URL 策略约束,不受 XAI_ALLOW_UNSAFE_URL_OVERRIDES 调试开关放宽。
- 给 GrokQuotaService 注入 config,使配额/billing 探测与转发共用同一
URL 策略。
前端:
- Edit 模态为 Grok OAuth 账号新增「自定义上游地址」开关。
- 请求头表单新增 JSON 快速导入与按 JSON 一键复制(复用 useClipboard,
兼容非安全上下文 HTTP 页面)。
- 门控改为平台×类型判定,Bulk 批量 base_url 增加格式校验,zh/en 文案同步。
2026-07-15 20:30:23 +08:00
shaw
4e4ce440b3
fix(test): align duplicate account test with new NewAccountHandler signature
2026-07-15 16:13:22 +08:00
shaw
bdb5be1c42
Merge remote-tracking branch 'origin/main' into pr4241-fix
2026-07-15 16:11:28 +08:00
Wesley Liddick and GitHub
0de768e8be
Merge pull request #4221 from heathermhuang/codex/fix-grok-oauth-pool-health
...
fix(grok): refresh OAuth pools proactively
2026-07-15 16:07:09 +08:00
Wesley Liddick and GitHub
d348193179
Merge pull request #4262 from wucm667/fix/issue-4245-root-models-alias
...
fix(codex): add root models compatibility alias
2026-07-15 16:06:59 +08:00
Wesley Liddick and GitHub
bac925624f
Merge pull request #4289 from Tiantianr/fix/openai-ws-first-message-timeout
...
fix(openai-ws): make first-message timeout configurable
2026-07-15 15:45:24 +08:00
Wesley Liddick and GitHub
651bb019d5
Merge pull request #4346 from xiaohei210509/agent/handle-codex-image-function-tool
...
fix(openai): preserve Codex image function tools during bridge injection
2026-07-15 15:35:07 +08:00
Wesley Liddick and GitHub
4de53b61b8
Merge pull request #4339 from wp-a/codex/read-tool-stream-finalization
...
fix(apicompat): sanitize complete Read tool argument streams
2026-07-15 15:16:24 +08:00
Wesley Liddick and GitHub
dba6cefb6b
Merge pull request #4340 from wp-a/codex/anthropic-incomplete-finalization
...
fix(apicompat): preserve incomplete stream finalization
2026-07-15 15:16:12 +08:00
Wesley Liddick and GitHub
80560e48d2
Merge pull request #4341 from wp-a/codex/additional-tools-discriminator
...
fix(apicompat): scope additional tools parsing
2026-07-15 15:15:58 +08:00
Wesley Liddick and GitHub
44452d4a9d
Merge pull request #4334 from lenzhang/fix/grok-vision-image-bridge
...
fix(grok): bridge image_url content parts through Responses API for vision models
2026-07-15 14:43:44 +08:00
Wesley Liddick and GitHub
8e84071f21
Merge pull request #4307 from wp-a/fix/openai-first-output-timeout
...
fix(openai): bound native responses first output wait
2026-07-15 14:41:11 +08:00
Wesley Liddick and GitHub
788b1cebf1
Merge pull request #4333 from superman2003/fix/grok-free-messages-function-cache
...
fix(grok): cache Free Messages function tools
2026-07-15 14:40:14 +08:00
shaw
986310d0bd
fix(lint): apply De Morgan's law to grok vision bridge gate (QF1001)
2026-07-15 14:30:47 +08:00
Wesley Liddick and GitHub
2d218fbe61
Merge pull request #4317 from yan9651688/feat/account-one-click-copy
...
feat(accounts): add safe one-click account duplication
2026-07-15 14:23:35 +08:00
Wesley Liddick and GitHub
9d1b44e6a0
Merge pull request #4324 from superman2003/fix/responses-lite-tool-compat
...
fix(openai): normalize Responses Lite tool declarations
2026-07-15 14:22:15 +08:00
Wesley Liddick and GitHub
601a1d1662
Merge pull request #4305 from wp-a/fix/outbox-degraded-rebuild-latch
...
fix(scheduler): latch degraded outbox rebuilds
2026-07-15 14:22:03 +08:00
Wesley Liddick and GitHub
83ef20bf8b
Merge pull request #4299 from wp-a/fix/xai-oauth-unsafe-base-url-components
...
fix(xai): reject empty base URL queries
2026-07-15 14:21:42 +08:00
Wesley Liddick and GitHub
e4a0e69424
Merge pull request #4280 from bestony/feat/keys-id-column
...
feat(keys): add optional ID column on /keys page
2026-07-15 13:50:37 +08:00
Wesley Liddick and GitHub
156cabd260
Merge pull request #4316 from fengshao1227/fix/grok-image-model-responses-reject
...
fix(grok): 拦截图片模型发往 Responses 端点,返回明确错误
2026-07-15 13:49:25 +08:00
Wesley Liddick and GitHub
febc5cbdd8
Merge pull request #4319 from feeeei/main
...
统一gork使用模板中的名称风格
2026-07-15 13:49:07 +08:00
Wesley Liddick and GitHub
3e30862ddd
Merge pull request #4295 from caigee-cmd/perf/direct-anthropic-chatcompletions-bridge
...
perf(apicompat): force-chat 路径直转 Anthropic↔ChatCompletions,跳过 Responses 中间层
2026-07-15 13:46:56 +08:00
shaw
7b51271a84
fix(apicompat): default stop_reason for empty-choices responses
...
Adversarial re-verification found one more divergence from the
double-conversion chain: an upstream 200 with empty choices (or a nil
response) left stop_reason as an empty string, while the old chain
reports end_turn. Derive the fallback from the content blocks — the
guard never fires when choices exist, since every finish_reason maps to
a non-empty stop_reason.
Also strengthen the equivalence tests: compare tool_use Content[].Input
and tool_call Function.Arguments across bridges, and add an
empty-choices stop_reason parity case.
2026-07-15 11:44:47 +08:00
shaw
430fd8f20a
fix(apicompat): align direct bridge edge semantics with double conversion
...
Adversarial review of the direct bridge found divergences from the
double-conversion chain it replaces; all are now aligned and covered by
tests that fail against the previous implementation:
- flush argument fragments buffered before a deferred tool announcement,
and announce name-less tools at finalize, so no tool arguments are lost
when upstreams stream arguments before the name
- fold text-only user array content into a single string; parts form only
when an image requires it (strict chat upstreams reject array content)
- drop tool_choice pointing at undeclared tools and unknown choice types
- treat cache_write_tokens/cache_creation_tokens as alternate spellings
(prefer write), not additive
- generate a response id when the upstream omits one
- derive stop_reason from blocks for content_filter/unknown finish reasons
- emit input_json_delta "{}" when a tool block closes without argument
deltas
2026-07-15 11:29:22 +08:00
Wesley Liddick and GitHub
3f605c3543
Merge pull request #4303 from wp-a/fix/web-fingerprinted-asset-caching
...
fix(web): limit immutable caching to fingerprinted assets
2026-07-15 11:12:50 +08:00
Wesley Liddick and GitHub
23796a1b34
Merge pull request #4291 from bestony/agent/user-server-timing/bes-26
...
feat: extend Server-Timing to authenticated user web APIs
2026-07-15 11:12:37 +08:00
Wesley Liddick and GitHub
5b5e41450c
Merge pull request #4310 from jianjianai/codex/perf-scheduler-final
...
perf(scheduler): 完善缓存桶生命周期并复用重建批次查询
2026-07-15 11:09:47 +08:00
Wesley Liddick and GitHub
10798abe4f
Merge pull request #4300 from wp-a/fix/frontend-datatable-row-cache
...
fix(frontend): clear stale DataTable row caches
2026-07-15 11:08:58 +08:00
Wesley Liddick and GitHub
4344f6afb0
Merge pull request #4298 from wp-a/fix/openai-images-json-completion-boundary
...
fix(images): preserve JSON completion boundaries
2026-07-15 11:08:47 +08:00
Wesley Liddick and GitHub
ab369c363f
Merge pull request #4290 from wucm667/fix/issue-4287-preserve-antigravity-rt
...
fix(antigravity): 保留手动输入的 refresh token
2026-07-15 11:08:37 +08:00
Wesley Liddick and GitHub
6460b9895c
Merge pull request #4297 from wp-a/fix/openai-reset-credit-malformed-details
...
fix(openai): preserve reset count on malformed details
2026-07-15 11:08:25 +08:00
shaw
cf6aa1a5c3
fix(openai): 和解 #4304 与 #4306 的透传错误语义冲突
...
两个 PR 分别合并后在 main 上语义相撞(文本无冲突,CI 才暴露):
- #4306 把所有非 failover 透传错误重建为通用净化信封;
- #4304 要求确定性 context-window 错误不切号且文案对客户端可见
(如触发客户端自动压缩),其测试断言原文可达。
和解方案(保留双方意图):
- 净化器拆出 writeOpenAIPassthroughErrorEnvelope;context-window 错误
仍走本地 JSON 信封 + 净化头策略,但 message 使用脱敏后的上游消息,
不再抹成通用文案;其余错误净化行为不变。
- RebuildsUpstreamErrors 的两个 5xx 用例改用非瞬时状态码(530/501):
瞬时 5xx 对 API-key 账号已按 #4304 契约走 failover(由
APIKeyPassthrough_Transient5xxTriggersFailover 覆盖),净化重建
路径的 5xx 覆盖由非瞬时状态码继续承担。
2026-07-15 10:40:14 +08:00
Wesley Liddick and GitHub
40a59c9e86
Merge pull request #4275 from jianjianai/codex/perf-u17-response-sse-flush
...
优化 Responses 流式事件边界刷新
2026-07-15 10:30:31 +08:00
Wesley Liddick and GitHub
65d744d0e1
Merge pull request #4294 from caigee-cmd/fix/parallel-tool-use-ghost-delta
...
fix(apicompat): 并行 tool_use 幽灵 content_block_delta(index 错误)
2026-07-15 10:26:02 +08:00
Wesley Liddick and GitHub
2381b6c104
Merge pull request #4304 from wp-a/fix/openai-passthrough-5xx-failover
...
fix(openai): fail over API-key passthrough 5xx
2026-07-15 10:20:44 +08:00