Wesley Liddick and GitHub
651b24571c
Merge pull request #3000 from Pluviobyte/codex/sub2api-stream-field-validation
...
fix: validate stream field type across OpenAI-compatible handlers
2026-06-06 15:02:06 +08:00
wsxfs
aea2950b18
fix(auth): 修复 Linux DO 登录误进入邮箱验证
2026-06-06 13:05:07 +08:00
Wesley Liddick and GitHub
1f423ae02a
Merge pull request #2961 from CheriWen/fix/cwe-204-info-disclosure-key-oracle
...
[Security] fix: return 404 instead of 403 to prevent key ID enumeration
2026-06-06 11:10:03 +08:00
Wesley Liddick and GitHub
eb24485fc6
Merge pull request #3036 from whatIsNextToTheMoon/fix/openai-response-failed-passthrough
...
fix(openai): preserve upstream response.failed errors
2026-06-06 09:53:08 +08:00
Wesley Liddick and GitHub
427d591212
Merge pull request #2930 from touwaeriol/feat/image-token-billing
...
fix(billing): channel pricing override for image generation + display image_output_tokens
2026-06-06 09:28:46 +08:00
Wesley Liddick and GitHub
8775047f84
Merge pull request #3051 from wucm667/fix/openai-messages-missing-terminal-event-failover
...
fix(openai): /v1/messages 流式缺终止事件时纳入 failover 与 ops 错误归因
2026-06-05 21:34:14 +08:00
wucm667
36721d35a8
feat(openai): cool down image rate limits by capability
2026-06-05 18:12:33 +08:00
wucm667
8e27ff20af
fix(openai): handle missing messages stream terminal
2026-06-05 18:11:23 +08:00
fe8952733a
fix(usage): 管理端错误请求页过滤与分列完善
...
- 错误请求标签补传 model/account_id/group_id 过滤(此前 loadAdminErrors 丢弃),admin handler
读取 model 查询参数走精确匹配
- 错误表格拆成 用户/API Key/账号 三独立列(上游行也显示用户),补 api_key_name/api_key_deleted,
已删除 key 显示红色「已删除」标记;i18n keyDeletedBadge 补入 errorLog 命名空间
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-05 14:00:57 +08:00
cfb195c7b2
feat(usage): 记录并展示失败请求(用户端+管理端)
...
- 记录失败请求并在用户端/管理端展示;分类下拉改用统一 Select 组件
- 模型过滤改后端 ILIKE 模糊匹配;新增「Key 名称」列(含已删除标记)与按 Key 过滤;时间列移至末列
- 用户可见「已删除 key 失败请求」:OpsErrorLogFilter 加 MatchDeletedKeyOwner,用户侧归属
放宽为 (user_id OR deleted_key_owner_user_id),让 key 原所有者能看到删除 key 后继续请求
导致的认证失败记录(他人仍 NotFound,不泄露存在性)
- 迁移 148:ops_error_logs 用户+时间索引
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-05 14:00:57 +08:00
ddf063352a
feat(ops): 错误日志 key 归因与早退字段补全
...
让 /admin/ops 错误详情正确归因 API key 并补全早退场景字段,合并三项改动:
- 鉴权早退补全用户/分组/平台字段:引入 ops fallback key(ContextKeyOpsFallbackAPIKey),
apiKey 一加载成功即写入,覆盖分组停用/删除、Key 停用/过期/额度、用户停用、IP 限制等早退
路径;ops 错误日志改用 getOpsAPIKey(正式 key 优先、回退键兜底),不改「已鉴权」语义。
- 已删除 key 归因(迁移 145):删除 key 时同一事务写 deleted_api_key_audits 映射,认证失败
时用明文反查命中原所有者,错误详情展示「已删除 Key 所有者」「尝试的 Key 前缀」。
- 有效 key 报错快照前缀(迁移 147):对绑定有效 key 的错误,落库时快照明文前 8 位到
api_key_prefix(与 attempted_key_prefix 互斥),key 之后被删仍保留报错当时真实前缀。
均仅对上线后新产生的错误/删除生效。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-05 14:00:57 +08:00
ghostg00
bc7ce18574
fix(group): 管理员清空分组描述时正确持久化
...
UpdateGroup 之前用 `if input.Description != ""` 判空,
把"未提供"和"显式置空"混为一谈,导致管理员在分组编辑表单
里清空备注后保存无效。
将 UpdateGroupRequest / UpdateGroupInput 的 Description 改为
*string:nil 表示未提供(保持原值),"" 表示显式清空。
2026-06-04 19:48:03 +08:00
whatIsNextToTheMoon
5bd3d90434
fix(openai): preserve upstream response.failed errors
2026-06-04 11:17:22 +00:00
Pluviobyte
3571b082fb
fix: validate stream field type
2026-06-03 14:18:12 +08:00
Cheri Wen
11b6017171
fix: return 404 instead of 403 for unauthorized key access to prevent ID oracle (CWE-204)
...
GET /api/v1/keys/:id previously returned distinct HTTP status
codes for 'key not found' (404) vs 'key exists but belongs to
another user' (403). This oracle allowed attackers to enumerate
valid API key IDs by observing response differences.
Now returns 404 in both cases so the response is identical
regardless of whether a key exists.
Fixes: CWE-204 (Information Disclosure via ID Oracle)
2026-06-02 00:46:50 +08:00
Wesley Liddick and GitHub
5f63fe1945
Merge pull request #2927 from moonagic/main
...
fix antigravity gemini rate limit and account scheduling
2026-06-01 14:50:36 +08:00
Wesley Liddick and GitHub
a0057f44f2
Merge pull request #2932 from fatelei/issue-2917
...
fix: change balance to pointer type
2026-06-01 11:37:33 +08:00
xlx0852
08e19bb15c
fix(openai): bridge oversized websocket requests
2026-06-01 10:42:55 +08:00
Wesley Liddick and GitHub
910ff3cd58
Merge pull request #2892 from Arron196/feat/sync-upstream-models-on-create
...
feat: 添加账号时支持同步上游支持的模型
2026-06-01 09:58:33 +08:00
Wesley Liddick and GitHub
0f70f84182
Merge pull request #2925 from is7Qin/feat/openai-oom
...
refactor(gateway): 降低大请求体内存保留
2026-06-01 09:40:31 +08:00
fatelei
0560340bd4
fix: change balance to pointer type
2026-06-01 08:41:35 +08:00
erio
ef5ad0fb10
fix(frontend): display image_output_tokens breakdown in usage pages
...
When image generation models are billed by token (channel pricing mode=token),
the usage pages previously showed only image count format instead of detailed
token breakdown. This fixes the display to properly show image output tokens
separately from text output tokens.
2026-05-31 22:53:22 +08:00
moonagic
a01686c637
fix antigravity gemini rate limit and account scheduling
...
Squash of 4 commits:
- Fix Gemini rate limit scheduling
- fix antigravity gemini rate limit scheduling
- fix antigravity gemini limited account scheduling
- fix antigravity test stubs for default lint
2026-05-31 22:00:03 +08:00
name
5a3e193b53
refactor(gateway): shorten OpenAI request body retention
2026-05-30 20:01:39 +08:00
name
2caee9d884
refactor(gateway): snapshot usage worker inputs
2026-05-30 20:01:39 +08:00
name
619e5ae619
refactor(gateway): isolate anthropic body rewrites
...
Keep Anthropic request body rewrites attempt-local and synchronize the accepted wire body only after upstream success so failover and retry paths do not reuse stale parsed state.
2026-05-30 20:01:39 +08:00
name
b1c4be4ac8
refactor(gateway): remove parsed request object graphs
...
Keep large gateway payloads as raw body ranges and bind OpenAI parsed-body caches to the body bytes so failover and mapping do not reuse stale mutable state.
2026-05-30 20:01:38 +08:00
name
d8cbf9ab5c
refactor(gateway): introduce request body refs
2026-05-30 20:01:38 +08:00
bf24b61139
perf(usage): 优化 /admin/usage 打开速度与刷新响应
...
根因:页面 mount 并发 6 个请求,其中 5 个在原始 usage_logs 上 live 聚合,
且有 1 个重复 getModelStats。优化(不引入预聚合):
前端
- UsageView 经 :model-options 下传 model 列表,移除 UsageFilters 重复的
getModelStats(mount 请求 6→5,少一次 usage_logs 全表 GROUP BY model)
- 刷新/换筛选保留旧模型数据(invalidateModelStatsCache 只失效标记不清空数据),
图表不再闪空,刷新期间页面保持可交互
后端
- GetStatsWithFilters 4 条聚合 errgroup 并行(仅 *sql.DB 连接池路径,ent.Tx
顺序回退以保事务内不并发),endpoint 明细 best-effort;抑制取消级联噪声日志
- /admin/usage/stats 复用 dashboard 的 newSnapshotCache 30s 处理器层缓存,按
filters+窗口为 key;前端手动刷新带 nocache=1 强制回源(刷新=最新)
注:自合并提交 4c8396c 迁移而来,仅取"列表打开速度与刷新响应"部分;原提交的
"审计查看弹窗大 body 渲染"改动(AuditLogModal / audit-log-format / 审计 i18n)
依赖尚未迁移的审计功能(d8389ade),本次已排除。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-05-30 18:56:08 +08:00
DaydreamCoding and Claude Opus 4.7
b60d8bb4cc
feat(usage): 在 /admin/usage 支持查看已删除用户的历史使用情况
...
用户软删除后使用记录仍在,但身份(邮箱)被 ent 软删除拦截器隐藏。本次在
三条管理员只读路径定点穿透软删除过滤,并把删除状态传播到前端标记,零新表/
迁移/回填:
- 后端穿透:富化 usage 日志(loadUsers)、用户搜索(ListWithFilters +
UserListFilters.IncludeDeleted)、点击详情(GetByIDIncludeDeleted /
GetUserIncludeDeleted + getById ?include_deleted 分支)
- 状态传播:service.User / dto.User 新增 DeletedAt;SearchUsers 标记 deleted
- 前端:表格与余额弹窗展示"已删除"徽标、筛选下拉标注并排序、点击走
include_deleted;新增 i18n admin.usage.userDeletedBadge
- 安全:普通用户 usage 仅查本人(无 PII 泄漏);主用户列表与默认 getById
行为不变(已删用户仍 404);仅 admin 搜索设 IncludeDeleted
后端 build / 三态 vet / unit 全量 / 仓储集成全绿;前端 typecheck / vitest /
改动文件 eslint 全清。
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-30 17:52:18 +08:00
benjamin
57d9e15e04
feat: 添加账号时支持同步上游模型
...
新增 POST /admin/accounts/models/sync-upstream-preview 端点,
允许在创建账号流程中直接使用凭证同步上游支持的模型,
无需先保存账号获取 ID。
- 后端: 新增 SyncUpstreamModelsPreview handler
- 前端: 新增 syncUpstreamModelsPreview API 函数
- 前端: ModelWhitelistSelector 支持 syncCredentials prop
- 前端: CreateAccountModal 传递凭证给 ModelWhitelistSelector
2026-05-30 12:19:38 +08:00
DaydreamCoding and Claude Opus 4.8
f7f5e33830
feat(quota): user×platform 配额 DB 写聚合 flusher
...
Redis 同步权威 + DB 镜像,不在进程内维护 delta:
- 写入点 HasUserPlatformQuotaLimit 守卫:无 limit 跳过 Redis 写与持久化
- 累加 usage 的 Lua 在 flusher_enabled 时 SADD 脏集 billing:upq:dirty
- UserPlatformQuotaUsageFlusher 定时 SPOP 脏集 → 批量 HGETALL 读当前窗口 usage 快照
→ BatchSnapshotUsage 绝对值 UPSERT 覆盖 DB(去 SELECT FOR UPDATE 行锁)
→ 失败 SADD 回 / FK(23503)整批丢弃
- flusher 单批 clamp 到 ≤6000,保证一次 flush 只生成一条 UPSERT(单事务原子)
- flusher_enabled 默认 false(降级=旧异步直写 DB)
效果:DB 写连接从 O(QPS) 收敛到 O(副本)。
循环依赖:service 层独立 Snapshot/FK 类型,repository adapter 转换 + %w 映射 FK error。
admin reset/upsert 后失效 cache(脏残留被 flusher 当 MISS 跳过)。
健壮性与可观测性:
- flusher_enabled=false 时 Start 不注册定时器;flush_interval_ms 非法回退 2s
- Readd 回填失败单独计 dirty_lost(不再误记 dirty_readd)并 ALERT;脏集 Readd 补兜底 TTL
- 单 tick 达 max batches 上限仍有积压时记 log
- admin 失效 cache 失败升级为 ALERT(提示 enforcement 可能延迟至 sentinel TTL)
- BatchGet 单条命令失败 / usage 字段损坏均记 log,避免静默以 0 覆写 DB
三态 go vet + 单测/集成测全绿。
已知取舍(默认 flusher_enabled=false 不触发):
- FK 整批丢弃牵连同批正常 key(活跃 key 靠下次 SADD+绝对值快照自愈;Redis 仍权威)
- admin reset/upsert 直写 DB 与 flusher 异步刷存在覆盖竞态:flusher 持旧快照在途时可能覆盖
admin 刚写值(limit 列不受影响;usage 有 preflight windowExpired 兜底;低频)。彻底消除需 version OCC。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-05-29 17:19:15 +08:00
Wesley Liddick and GitHub
69e7c4db30
Merge pull request #2865 from wey-gu/feat/usage-request-context
...
fix(gateway): preserve usage request context
2026-05-29 16:21:59 +08:00
Wesley Liddick and GitHub
21cd382f39
Merge pull request #2855 from gaoren002/fix/concurrency-error-classification
...
fix: classify concurrency acquire failures
2026-05-29 10:33:40 +08:00
Wesley Liddick and GitHub
433f8dcd13
Merge pull request #2834 from DaydreamCoding/pr/openai-codex-cli-allow-claude-code
...
feat(openai): codex_cli_only 新增放行 Claude Code Codex 插件的机制
2026-05-29 10:30:33 +08:00
Wesley Liddick and GitHub
6bc1983506
Merge pull request #2853 from wucm667/fix/system-update-already-up-to-date-response
...
fix(admin): system/update 在无更新时返回 200 + already_up_to_date 而非 500
2026-05-29 10:29:49 +08:00
shaw
6010c3cca9
test: 修复内容审计日志异步断言
2026-05-29 09:57:02 +08:00
shaw
ed1b57c597
fix(openai): gate routing by endpoint capability
2026-05-29 08:58:10 +08:00
Wey Gu
2bd3125d0f
Preserve usage request context
2026-05-28 22:44:25 +08:00
Wesley Liddick and GitHub
8c1a07852c
Merge pull request #2858 from wey-gu/feat/openai-embeddings-gateway
...
feat(gateway): Add OpenAI embeddings gateway
2026-05-28 22:15:19 +08:00
lyen1688
1b2d8873b0
feat: 完善前置拦截审核运行态
2026-05-28 20:05:24 +08:00
Wey Gu
ccace69d4e
Add OpenAI embeddings gateway
2026-05-28 19:39:52 +08:00
gaoren002
56e96fdd8c
fix: classify concurrency acquire failures
2026-05-28 10:03:41 +00:00
wucm667
b15375dfb4
fix(admin): handle already up-to-date updates
2026-05-28 17:27:01 +08:00
56908d3c4c
feat(openai): codex_cli_only 新增放行 Claude Code Codex 插件的机制
...
适用场景:在 Claude Code 中使用 https://github.com/openai/codex-plugin-cc
插件时,插件经官方 codex app-server 以 clientInfo.name="Claude Code" 完成
initialize 握手,请求头被设为 originator=Claude Code、User-Agent 含
"Claude Code/",不在官方客户端白名单内,原本会被 codex_cli_only 拦截 403。
在官方客户端白名单未命中时评估两层独立放行(OR 语义):
- 按账号:account.Extra.codex_cli_only_allowed_clients 引用命名预设
(目前仅 claude_code),detector reason=allowed_client_matched
- 全局开关:/admin/settings 网关服务 OpenAI 区块新增
openai_allow_claude_code_codex_plugin(默认 false),开启后对所有
codex_cli_only 账号统一放行,detector reason=global_allowed_client_matched
签名仍要求 originator=Claude Code 精确等值 + UA 含 "Claude Code/"。
上游转发保持透传不变。
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-27 23:55:34 +08:00
Wesley Liddick and GitHub
cc077862b3
Merge pull request #2797 from wucm667/feat/account-list-created-at-column
...
feat(admin): 账号管理列表新增创建时间列
2026-05-27 22:10:21 +08:00
lyen1688 and lyen1688
f597c1581b
feat(group): 支持自定义 /v1/models 模型列表
2026-05-27 18:00:45 +08:00
Wesley Liddick and GitHub
2387cf9934
Merge pull request #2799 from siyuan-123/fix/ws-rate-limit-failover
...
修复 OpenAI WS 限额时不自动切换账号
2026-05-27 15:14:28 +08:00
Wesley Liddick and GitHub
4b9b63443f
Merge pull request #2790 from Arron196/from-arron-main
...
修复 Ops SLA 本地限制错误统计
2026-05-26 20:21:11 +08:00
siyuan
08061717b8
fix: enable account failover for OpenAI WS rate limits
2026-05-26 20:07:00 +08:00