Wesley Liddick and GitHub
bfabfe60c8
Merge pull request #4593 from StarryKira/fix/image-storage-env-unreachable
...
fix: 异步生图开关配了却不生效(环境变量被静默丢弃 + 迁移到后台开关)
2026-07-20 09:20:15 +08:00
Jlypx and Sisyphus
dd0cbe91c9
fix: 避免复制客户端 IP 原子状态
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:22:45 +08:00
Jlypx and Sisyphus
ff5b0e6254
test: 更新客户端 IP 设置响应契约
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:09:47 +08:00
Jlypx and Sisyphus
fedeba2568
feat: 审计客户端 IP 请求头变更
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:09:37 +08:00
Jlypx and Sisyphus
3c86e249f4
feat: 接入客户端 IP 请求头管理接口
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:09:21 +08:00
Jlypx and Sisyphus
f72958d530
feat: 持久化客户端 IP 请求头设置
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:09:11 +08:00
Jlypx and Sisyphus
8b8b6b3132
feat: 定义客户端 IP 请求头系统设置
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:09:00 +08:00
Jlypx and Sisyphus
9bc7d10c08
fix: 快照自定义客户端 IP 请求头
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:08:48 +08:00
Jlypx and Sisyphus
496005d688
fix: 按自定义请求头解析客户端 IP
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:08:36 +08:00
Jlypx and Sisyphus
041db5d824
feat: 支持自定义客户端 IP 请求头配置
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:08:26 +08:00
Jlypx and Sisyphus
93717394b2
fix: 迁移客户端 IP 兼容开关
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-19 21:41:45 +08:00
Jlypx and Sisyphus
6aa6b3a968
fix: 将客户端 IP 模式注入请求上下文
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-19 21:41:12 +08:00
Jlypx and Sisyphus
39107ca457
fix: 安全初始化 Gin 可信代理
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-19 21:40:32 +08:00
Jlypx and Sisyphus
6e2ba0e4cd
fix: 统一请求级客户端 IP 模式
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-19 21:39:49 +08:00
Jlypx and Sisyphus
8a147fcc51
fix: 解析显式可信代理配置
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-19 21:39:24 +08:00
Jlypx
732aeef880
fix: 兼容反代和 Docker 客户端 IP 解析
2026-07-19 19:41:01 +08:00
haruka and Claude Opus 4.8
6102d64274
fix(wire): 补上 PromptAdminService 的绑定,恢复 wire 代码生成
...
ProviderSet 提供了 NewPromptAdminHandler,也绑定了 PromptEngine,却没有为
PromptAdminService 绑定实现,导致 go generate ./cmd/server 直接失败:
no provider found for securityaudit.PromptAdminService
needed by *securityaudit.PromptAdminHandler
*PromptService 本就实现了该接口的全部方法,wire_gen.go 也一直是手工维护到位的
(补上绑定后重新生成的结果与现有文件逐字节一致),只是生成这条路被堵死了,
后续任何依赖改动都无法再靠 go generate 同步。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01VHreE5pzCkSYz7J45fmd2Y
2026-07-19 01:03:41 -07:00
haruka and Claude Opus 4.8
b08cab91a9
feat(image-storage): 异步生图对象存储改为后台配置,保存即生效
...
此前开启异步生图必须改服务器上的 config.yaml 并重启容器(#4542),且若想
复用已配置的备份 S3,还得把同一套凭证再填一遍(#4458)。
- 新增 ImageStorageSettingService:配置存 settings 表,SecretAccessKey 经
SecretEncryptor 加密落库、读回脱敏、留空表示沿用旧值,与备份 S3 配置同一套做法。
- reuse_backup_s3(默认开)直接借用 backup_s3_config 的端点与密钥,只用自己的
bucket/prefix 区分对象,因此备份走 backups/、图片走 images/,且密钥不会在库里存两份。
- ImageTaskService 的启用状态改由 ImageStorageResolver 在运行时解析并缓存,
保存设置后 Invalidate 使下次请求重建客户端——不再需要重启。
- repository 侧由提供实例改为提供工厂,客户端才可能在运行期重建。
- 轮询接口的门控从 enabled() 放宽为 Pollable():关掉开关只拒绝新提交,
已受理的任务仍可取回结果,不再被中途吞掉。
- config.yaml 的 image_storage 保留为回落,后台从未保存过时沿用,
升级前已用配置文件开启的部署不受影响。
- 管理端 GET/PUT/POST /admin/backups/image-storage,PUT 与备份 S3 配置一样要求
step-up 2FA:改写存储目标同样能把生成内容导向外部账号。
注:go generate ./cmd/server 在当前 upstream 基线上即失败(securityaudit.
PromptAdminService 缺 provider),故 wire_gen.go 为手工同步。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01VHreE5pzCkSYz7J45fmd2Y
2026-07-19 00:56:21 -07:00
github-actions[bot]
d4b9797ff7
chore: sync VERSION to 0.1.161 [skip ci]
2026-07-18 14:18:28 +00:00
Wesley Liddick and GitHub
19149ca196
Merge pull request #4558 from fengshao1227/fix/antigravity-plan-type-preserve
...
fix(antigravity): 保留付费 tier 的 PlanType,IneligibleTiers 仅标记异常状态
2026-07-18 21:48:44 +08:00
Wesley Liddick and GitHub
831812b39d
Merge pull request #4556 from superman2003/fix/grok-free-probe-encrypted-recovery
...
fix(grok): stabilize Free probes and encrypted reasoning recovery
2026-07-18 21:48:31 +08:00
li
72b29a7d4e
fix(antigravity): 保留付费 tier 的 PlanType,IneligibleTiers 仅标记异常状态
...
Fixes #4519
2026-07-18 21:43:54 +08:00
shaw
14608dc6d4
Merge origin/main into codex/secure-protected-video-content-4498
...
Reconcile with #4539 (grok media account model mapping), now on main:
- handler/grok_media.go non-failover error path keeps both changes —
#4539 's grokMediaScheduleModel(account, routingModel, nil) schedule
attribution and this branch's IsResponseCommitted guard
- auto-merged sections verified: routing/classify use #4539 's routingModel,
video lookup owner-binding and no-failover semantics intact, ForwardGrokMedia
keeps mapping block (skipped for lookup endpoints via RequiresRequestBody),
empty-image failover, and video-status URL rewrite in order
2026-07-18 21:38:17 +08:00
shaw
8a95a46a69
Merge origin/main into codex/secure-protected-video-content-4498
...
Resolve conflicts with main:
- service/grok_media.go: keep both post-response blocks — #4497 's empty
image-output failover (main) runs first for image endpoints, then this
branch's video-status content-URL rewrite; the endpoint conditions are
mutually exclusive
- handler/openai_gateway_credential_failover_loop_test.go: mark the stub
OAuth accounts media-eligible via the grok_media_eligible extra override,
because this branch moved grok media failover coverage to the generation
endpoint, which is now gated by #4540 's paid-eligibility probe on main
2026-07-18 21:31:28 +08:00
shaw
9d498c2474
Merge origin/main into codex/fix-grok-media-model-mapping-4503
...
Resolve conflicts with main:
- handler/grok_media_test.go: keep both new tests (schedule model test from
this branch, eligibility gating tests from #4540 )
- service/openai_gateway_grok_test.go: keep both new tests; update the image
cases of the mapping table test to return a non-empty image payload because
#4497 (already on main) now converts empty image responses into an upstream
failover error
2026-07-18 21:25:43 +08:00
Wesley Liddick and GitHub
a2f802d409
Merge pull request #4541 from wucm667/fix/issue-4532-renew-expired-subscription
...
fix(subscription): renew expired admin assignments
2026-07-18 21:14:23 +08:00
Wesley Liddick and GitHub
b01196a7a8
Merge pull request #4553 from wp-a/fix/openai-ws-turn-lifecycle
...
[codex] enforce websocket passthrough turn lifecycle
2026-07-18 21:10:48 +08:00
superman2003
e14fb2b6ff
fix(grok): recover invalid encrypted content once
2026-07-18 21:05:50 +08:00
superman2003
dd7a2b22f0
fix(grok): align Free probes with health checks
2026-07-18 21:05:50 +08:00
shaw
4e8ea7d568
fix(test): 池模式临时规则测试适配 #4547 模型级隔离语义
...
#4496 与 #4547 文本无冲突但语义相撞:#4496 的测试断言规则命中后账号级
跨模型封锁,#4547(issue 4527 第4点)将已知模型的临时不可调度改为按
模型隔离(SetModelRateLimit,不再触发账号级 runtime block)。
按 #4547 的语义更新断言:命中模型 gpt-5.4 记模型级封锁、gpt-5.5 不受
影响、不再调用账号级 SetTempUnschedulable;池模式规则仍生效(停止同
账号重试),issue 4470 的诉求不受影响。未知模型的账号级兜底已由
TestOpenAITempUnschedulable_UnknownModelKeepsAccountRuntimeBlock 覆盖。
2026-07-18 21:02:23 +08:00
Wesley Liddick and GitHub
a3f2b8fd87
Merge pull request #4540 from heathermhuang/codex/investigate-grok-oauth-test-4525
...
fix(grok): retry CLI chat permission denial
2026-07-18 20:50:07 +08:00
Wesley Liddick and GitHub
23cdd20606
Merge pull request #4537 from heathermhuang/codex/refresh-anthropic-monitor-1953
...
fix(monitor): refresh Anthropic text-block extraction
2026-07-18 20:49:40 +08:00
Wesley Liddick and GitHub
a62b821b5f
Merge pull request #4478 from yardbirds0/codex/fix-upstream-billing-probe-refresh
...
fix: 完善上游 Sub2API 倍率探测刷新、展示与账号配置
2026-07-18 20:49:14 +08:00
Wesley Liddick and GitHub
774ff5d8c8
Merge pull request #4515 from BenjaminAaron196/feat/filter-noise-rejected-requests
...
(fix) 过滤入口拒绝日志并强化鉴权安全边界
2026-07-18 20:46:50 +08:00
Wesley Liddick and GitHub
e002fbb349
Merge pull request #4508 from wucm667/fix/model-not-found-transient-misclassification
...
fix: 临时账号耗尽时保留 503 错误分类
2026-07-18 20:41:35 +08:00
Wesley Liddick and GitHub
005bc5c8d4
Merge pull request #4497 from heathermhuang/agent/fix-grok-media-fallback-4471
...
fix(grok): fail closed for ineligible OAuth media
2026-07-18 20:41:24 +08:00
Wesley Liddick and GitHub
bc4bd118d8
Merge pull request #4547 from heathermhuang/codex/fix-model-scoped-temp-cooldown-4527
...
fix(routing): isolate temporary cooldowns by model
2026-07-18 20:41:12 +08:00
Wesley Liddick and GitHub
f3925db11b
Merge pull request #4496 from StarryKira/agent/fix-4470-pool-temp-unschedulable
...
fix: honor temp unschedulable rules in pool mode
2026-07-18 20:40:12 +08:00
Wesley Liddick and GitHub
f9a467a4c0
Merge pull request #4520 from StarryKira/codex/fix-4487
...
fix: report Chat Completions stream transport failures
2026-07-18 20:39:49 +08:00
Wesley Liddick and GitHub
8ce9288a6a
Merge pull request #4489 from fengshao1227/fix/grok-free-cache-tool-injection
...
fix(grok): 纯客户端函数工具不再注入原生搜索工具
2026-07-18 20:39:37 +08:00
Wesley Liddick and GitHub
c1e702be5e
Merge pull request #4505 from cyhhao/fix/claude-1m-model-suffix
...
fix(gateway): normalize Claude Code 1m model suffix
2026-07-18 20:39:27 +08:00
Wesley Liddick and GitHub
bc6b69289c
Merge pull request #4468 from docooler/fix/responses-stream-content-part
...
fix(apicompat): emit content_part events and full output in Responses stream
2026-07-18 20:39:15 +08:00
Wesley Liddick and GitHub
5a0492bf88
Merge pull request #4517 from weiness/fix/custom-branding-flash
...
fix: prevent custom branding flash on initial load
2026-07-18 20:39:00 +08:00
haruka and Claude Opus 4.8
37db8d031b
fix(config): 让环境变量能真正配置 image_storage 等凭证
...
viper.Unmarshal 只解码 AllKeys() 返回的键,而 AllKeys() 只汇总 SetDefault、
配置文件和显式 BindEnv 三个来源。AutomaticEnv 仅能覆盖已在其中的键,无法引入
新键;能兜底的 viper_bind_struct 又被 build tag 排除(我们只用 -tags embed)。
因此任何「没有注册默认值、且不在 config.yaml 里」的配置项,其环境变量会被静默
丢弃。image_storage 的 endpoint/bucket/access_key_id/secret_access_key/
public_base_url 正属此列,于是纯环境变量部署落到最坏组合:IMAGE_STORAGE_ENABLED
生效使 Enabled=true,四个凭证却为空 → Active()=false → 异步生图接口整体 404,
运维看到的却是"凭证不完整"。deploy/docker-compose.yml 默认就是纯环境变量驱动,
且自动生成的 config.yaml 从不写 image_storage 段,必然踩中(见 #4458、#4542)。
同类缺口不止于此:github_oauth、google_oauth、dingtalk_connect 三组第三方登录
配置(含 client_secret)同样完全无法用环境变量设置。
- 为这些键注册零值默认,使其进入 AllKeys() 而可被环境变量覆盖。零值与"键缺失"
时的解码结果一致,故行为不变。
- sticky_escape_enabled 例外:它的实际默认是 true(靠 IsSet 守卫在解码后补上),
注册 false 会让 IsSet 恒真而永久关闭该特性,故直接注册 true。
- 启动告警补上 missing_keys 字段,指明到底哪个凭证为空。
- 新增反射守卫测试:Config 结构体上每个可由环境变量表达的字段都必须已注册默认值。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01VHreE5pzCkSYz7J45fmd2Y
2026-07-18 05:24:32 -07:00
王鹏
f0e0b7e6d8
fix(openai-ws): enforce passthrough turn lifecycle
2026-07-18 19:17:53 +08:00
Heatherm Huang
4c845ca697
test(grok): sanitize security fixtures
2026-07-18 17:50:53 +08:00
Heatherm Huang
95d27f2dce
fix(grok): fetch validated signed video content
2026-07-18 17:49:09 +08:00
Heatherm Huang
f2e7a55703
fix(grok): proxy signed video status URLs
2026-07-18 17:21:53 +08:00
Heatherm Huang
1ed9f59599
test(grok): keep media failover coverage on generation
2026-07-18 15:54:43 +08:00
Heatherm Huang
b4ad7fd363
test(grok): configure multipart media mapping
2026-07-18 15:49:21 +08:00