Wesley Liddick and GitHub
005bc5c8d4
Merge pull request #4497 from heathermhuang/agent/fix-grok-media-fallback-4471
...
fix(grok): fail closed for ineligible OAuth media
2026-07-18 20:41:24 +08:00
haruka
bd0f2d6405
fix: report chat stream transport failures
2026-07-18 03:24:04 +08:00
Heatherm Huang
e86063155f
fix(grok): gate OAuth media on paid eligibility
2026-07-17 19:15:16 +08:00
Wesley Liddick and GitHub
8bfbc5ca99
Merge pull request #4485 from Sub2API-Devs/dev
...
feat(security-audit): 新增 OpenAI 兼容提示词审计能力与安全审计控制台
2026-07-17 16:15:26 +08:00
li
fc3c5a1e0c
fix: 权限检查和并发槽也使用显式检查,修复被动 namespace 触发 403
...
Fixes #4447
2026-07-17 15:15:54 +08:00
li
e375623abf
fix(gateway): 被动 image_gen namespace 不再强制要求 Responses capability
...
Fixes #4476
2026-07-17 15:07:41 +08:00
mt21625457
d11bdb13f5
feat(security-audit): add OpenAI-compatible prompt auditing
2026-07-17 00:39:39 +08:00
haruka and Claude Opus 4.8
605b026cc4
fix(gateway): route image-intent /v1/responses only to Responses-capable accounts ( #4417 )
...
For OpenAI-compatible API-key accounts, /v1/responses requests with
image-generation intent could be scheduled to accounts whose upstream
does not support the Responses API (extra.openai_responses_supported=false).
The flag was only consulted at forward time, where such accounts are
silently downgraded to a Chat-Completions path that cannot produce images,
causing upstream 4xx/5xx or canceled requests.
Fix:
- Add endpoint capability OpenAIEndpointCapabilityResponses. Its check in
SupportsOpenAIEndpointCapability excludes only OpenAI API-key accounts
probed as unsupported (mirroring the forward-time downgrade condition);
OAuth/Grok/unprobed accounts keep existing behavior, and a responses-
capable upstream must still pass the chat_completions gate. Reusing the
existing requiredCapability plumbing makes every scheduler filter path
enforce it with no scheduler signature changes.
- Request the responses capability at the HTTP Responses and
ResponsesWebSocket call sites only when imageIntent && platform==openai,
so non-image requests keep the downgrade path and Grok's own image path
is untouched.
- Normalize max_tokens -> max_output_tokens on the native responses
forward path (PlatformOpenAI), and strip prompt_cache_options alongside
prompt_cache_retention/safety_identifier.
/v1/images/generations continues to use native image capability (unchanged).
Tests: capability truth table, scheduler exclusion of unsupported accounts,
and forward-path transform behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KXpzKKvsb5jW2GvgBQqnnZ
2026-07-16 00:23:40 -07:00
shaw
0408bdb34f
Merge remote-tracking branch 'origin/main' into feat/upstream-rate-scheduling
...
# Conflicts:
# backend/internal/handler/openai_gateway_handler.go
2026-07-16 10:31:21 +08:00
Wesley Liddick and GitHub
531ae04a0b
Merge pull request #4395 from wp-a/fix/openai-body-limit-failover
...
[codex] fail over account-specific OpenAI body limits
2026-07-16 09:33:48 +08:00
Wesley Liddick and GitHub
e4329a04e8
Merge pull request #4393 from superman2003/fix/grok-codex-compatibility
...
fix(grok): improve Codex compatibility and key setup
2026-07-16 09:33:20 +08:00
Wesley Liddick and GitHub
f3138ceb43
Merge pull request #4384 from wp-a/fix/openai-model-scoped-transient-cooldown
...
[codex] scope OpenAI transient cooldowns by model
2026-07-16 09:33:09 +08:00
Tian Lee
90ee85f3ef
feat: 按上游计费倍率调度 OpenAI 账号
2026-07-16 00:40:46 +08:00
王鹏
3db00d3fee
fix(openai): fail over account-specific body limits
2026-07-16 00:19:20 +08:00
superman2003
410ea8490c
fix(grok): allow passive Codex image tool declarations
2026-07-16 00:16:21 +08:00
王鹏
40b8f04a6a
fix(openai): scope transient cooldowns by model
2026-07-15 22:52:35 +08:00
王鹏
4f641208a0
fix(openai-ws): close ingress reads cleanly
2026-07-15 22:15:44 +08:00
Wesley Liddick and GitHub
bac925624f
Merge pull request #4289 from Tiantianr/fix/openai-ws-first-message-timeout
...
fix(openai-ws): make first-message timeout configurable
2026-07-15 15:45:24 +08:00
王鹏
fc4089f292
fix(openai): bound native responses first output wait
...
Add an opt-in first semantic output budget for native HTTP Responses, including response-header wait. Keep preamble and keepalive bytes non-semantic so a stalled account can fail over once without replaying its response IDs. Defaults remain disabled.
Related to #4201 , #4185 , and #4248 . Complements the HTTP/2 dead-connection fix in #4207 .
2026-07-15 13:01:16 +08:00
Wesley Liddick and GitHub
4344f6afb0
Merge pull request #4298 from wp-a/fix/openai-images-json-completion-boundary
...
fix(images): preserve JSON completion boundaries
2026-07-15 11:08:47 +08:00
Wesley Liddick and GitHub
2ceaa4783c
Merge pull request #4311 from jianjianai/codex/perf-openai-forwarding-final
...
perf(openai): 优化 Responses 图片意图判定与透传流式刷新
2026-07-15 10:12:05 +08:00
Wesley Liddick and GitHub
125b03aee6
Merge pull request #4281 from bestony/feat/openai-ws-proxy-failed-host
...
fix(openai): include proxy host in websocket_proxy_failed logs
2026-07-15 09:37:04 +08:00
Wesley Liddick and GitHub
65093591cd
Merge pull request #4282 from bestony/feat/openai-failover-switching-proxy-host
...
fix(openai): include proxy host in upstream_failover_switching logs
2026-07-15 09:36:53 +08:00
shaw
a0593b0bf8
fix(gateway): 客户端断开后 failover 静默终止,不再误报 502 账号耗尽
...
上游请求经 detachUpstreamContext(WithoutCancel) 有意脱离客户端取消(保
计费),但 failover 循环仍用原始 c.Request.Context() 重新选号:客户端
断开后上游返回 520 等可 failover 错误时,重新选号必然得到 context
canceled,被误判为账号耗尽,记录并返回通用 502。
修复:客户端已断开 ⇒ failover 静默终止。
- 新增 failoverClientGone(c):请求 ctx 已取消时先停 compact 心跳
(建立 happens-before,对齐其它终结路径),响应未提交则标 499
(statusClientClosedRequest,与并发槽取消路径同惯例)
- 7 个 OpenAI 内联 failover 循环(Responses/Messages/chat_completions/
embeddings/images/grok_media/alpha_search)加双 guard:换号前 +
选号失败分支入口;guard 位于 ReportOpenAIAccountScheduleResult(false)
之后、RecordOpenAIAccountSwitch/池模式重试之前,账号健康副作用
(service 层 detached ctx)不受影响
- FailoverState.HandleFailoverError/HandleSelectionExhausted 入口加
ctx.Err() 检查返回 FailoverCanceled,取消不再改动 failover 状态;
全部 10 个 FailoverCanceled 分支统一调用 failoverClientGone 归类 499
- 上游 detach 与计费设计不变;真实上游 520 事件仍完整落 ops
(面板显示码 COALESCE(upstream_status_code,status_code)=520,
错误率/告警口径不变)
测试:新增 openai_responses_failover_cancel_test.go 复现 issue 场景
(520+取消 ⇒ 不切号、499、无 502 终态)+ 在线客户端对照(正常切换、
耗尽 502);failover_loop_test.go 补入口取消用例并修正取消语义断言。
Fixes #4257
2026-07-15 09:29:05 +08:00
jjaw
4aedbfc4a8
补充 OpenAI 转发复用边界注释
2026-07-15 06:59:00 +08:00
jjaw
78e09a0f1a
复用请求级图片生成意图判断
2026-07-15 04:20:11 +08:00
王鹏
2c13ed32e7
fix(images): preserve JSON completion boundaries
2026-07-15 03:15:47 +08:00
Tiantianr
74e296703a
fix(openai-ws): make first-message timeout configurable
...
Add a dedicated client first-message timeout while preserving the legacy 30-second default.
Use the resolved value for both the WebSocket read deadline and structured timeout logs, and document tuning for large requests or slow links.
Add configuration, validation, handler, and resolver regression coverage.
Refs #4158
2026-07-14 22:40:05 +08:00
bestony
ba5b6970be
fix(openai): include proxy host in upstream_failover_switching logs
...
Enrich openai.upstream_failover_switching structured logs with proxy
identity fields (proxy_id, proxy_name, proxy_host, proxy_port) so
operators can see which outbound proxy failed when switching accounts.
Matches the existing gateway.forward_failed / websocket_proxy_failed
logging pattern.
2026-07-14 19:33:56 +08:00
bestony
b000aac474
fix(openai): include proxy host in websocket_proxy_failed logs
...
Add proxy_id/proxy_name/proxy_host/proxy_port fields to openai.websocket_proxy_failed so operators can identify which proxy failed without extra lookups. Matches the existing gateway.forward_failed logging pattern.
2026-07-14 19:32:49 +08:00
Heatherm Huang
b32b815e46
fix(grok): harden OAuth pool recovery
2026-07-14 14:55:30 +08:00
Heatherm Huang
343390057d
fix(grok): fail over OAuth credential errors safely
2026-07-14 14:55:30 +08:00
zh239ns
002c0b9fda
fix(images): keep non-stream requests alive
2026-07-14 07:39:21 +08:00
Bestony@Homelab
c8cfc93632
fix(openai-ws): bound ingress session lifecycle
2026-07-13 15:32:42 +08:00
Heatherm Huang
8a22dc7347
fix(grok): diagnose unavailable models by platform
2026-07-13 10:11:34 +08:00
shaw
8d51364c3d
Merge remote-tracking branch 'origin/main' into feat/grok-prompt-cache-identity
...
# Conflicts:
# backend/internal/handler/endpoint.go
# backend/internal/service/openai_gateway_grok_test.go
2026-07-13 09:12:44 +08:00
superman2003
7050070aa3
fix(grok): route cacheable chat requests via responses
2026-07-12 11:50:56 +08:00
Tian Lee
84bb7d0709
fix: 保留 remote_compaction_v2 原生 Responses 链路
2026-07-11 12:51:53 +08:00
shaw
ae9a01d852
fix(compact): 二轮审计加固——心跳字节不得污染 failover 判定与并发写安全
...
对首轮修复的对抗式审计发现并修复以下问题:
1. failover 判定污染(真实回归风险):handler 以 "Forward 前后
c.Writer.Size() 是否变化" 判定响应是否已写出并据此放弃换号。心跳注释
字节会使该判定恒真,compact 请求一旦在上游等待期间发过心跳,上游
429/5xx 将不再 failover。新增
OpenAICompactKeepaliveAdjustedWrittenSize(扣除心跳字节、互斥锁下
一致读取、仅心跳字节归一化为未写哨兵 -1),快照、failover 比较与
openAIForwardErrorAlreadyCommunicated 三处判定统一改用该口径;无心跳
请求完全等价于原 c.Writer.Size()。
2. 并发写竞争:心跳 goroutine 与未被显式拦截的写回路径(Forward 内部
本地拒绝等)存在 ResponseWriter 数据竞争。StartOpenAICompactSSE-
Keepalive 现将 c.Writer 替换为 openAICompactKeepaliveWriter:写侧
方法(Header/Write/WriteString/WriteHeader/WriteHeaderNow/Flush)
先在互斥锁下停拍,读侧(Status/Size/Written)仅加锁不停拍——任何
请求侧响应构造与心跳从构造上互斥,热路径状态读取不误杀心跳。
3. 语义拦截补齐:rejectIfCyberSessionBlocked(在用户槽位长等待之后
执行的直接 c.JSON)与 writeOpenAIFastPolicyBlockedResponse 在心跳
提交后降级为 response.failed 终止事件;未提交时先停拍再写 JSON,
状态码语义不变。失败事件 errType 参数化(permission_error 等)。
4. reconstruct 混合形态:done 事件存在但 compaction 只在
output_item.added 中时也要补入;done 已含 compaction 时跳过 added,
避免无 id 可去重时收集两份(Codex 要求恰好一个)。
5. 观测性:logOpenAIRemoteCompactOutcome 对心跳提交后的失败(wire 200)
以 GetOpsStreamError 纠正 outcome,不再误记 succeeded。
新增 5 个测试:failover 口径不变式、包装器停拍语义(-race)、fast
policy 提交前后两态、混合 done/added 形态(含去重)。
Refs #3887 #3777
2026-07-10 10:18:16 +08:00
shaw
2cffe1cf5f
fix(compact): SSE→JSON 保留 raw output_item.done 并为 unary 等待补下游心跳(修复 #3887)
...
#3887 报告 v0.1.149(已含 #3880 桥接修复)remote compact 仍失败且持续
计费。核实为 #3880 明示的两个遗留:
1. 上游对 unary compact 返回 SSE 且 compaction item 只出现在 raw
response.output_item.done、终态 completed.response.output 为空
(#3777 实录形态)时,reconstructResponseOutputFromSSE 只累加
text/function_call/reasoning 三类 delta,compaction item 被丢弃,
桥接合成 0 个 output_item.done,Codex 报 "expected exactly one
compaction output item, got 0" 后盲目重试,每次重试重新消耗上游
compact 配额。
2. 桥接为全缓冲写回:上游 unary 完成前(大上下文可达数分钟,且上游
处理期间不发送任何字节)下游连响应头都收不到,反向代理
(Nginx/Cloudflare Tunnel)空闲超时掐断连接同样触发盲重连
(同类问题见 #2243/#2976)。
修复:
- reconstructResponseOutputFromSSE 优先以 raw JSON 逐字节收集
output_item.done item(协议上的最终完整形态),不经窄结构体,
encrypted_content/summary/opaque 等 compact 专属字段全部保留;
无 done 事件时退回收集 output_item.added 中的 compaction 类 item;
两者皆无才回到原 delta 重建。path-based v1 JSON 写回同样受益。
- 新增 openAICompactSSEKeepalive:body-signal 客户端流式 compact 在
上游等待期间按 gateway.stream_keepalive_interval 向下游写 SSE 注释
行心跳(eventsource 解析层直接忽略)。首拍延迟一个间隔,快速失败
仍走 JSON+状态码;首拍后状态码固化为 200,桥接/错误链路
(writeOpenAICompactSSEBridge、errorResponse、
handleStreamingAwareError、ensureForwardErrorResponse、
writeOpenAINonStreamingProtocolError)统一降级为 response.failed
终止事件并标记 ops 流内错误。
- API-key 账号的 compact 上游请求也强制 accept: application/json
(#3777 期望行为 4;透传白名单原会放行客户端的 text/event-stream)。
测试:#3777 实录形态经 handleSSEToJSON / 透传 / path-based 三条链路
的修补断言;raw-done 优先不与 delta 重复;added 回退门控;心跳提交、
提交后 2xx 续写、提交后失败降级、未提交行为不变;-race 通过。
Fixes #3887
Refs #3777 #3875 #3880
2026-07-10 09:56:56 +08:00
shaw
16c0613b21
fix(compact): body-signal 客户端流式请求的响应合成回 SSE
...
v0.1.147 的 body-signal 提升(#3804)把 Codex remote compact v2 的流式
/responses 请求改写为上游 unary /responses/compact(JSON),但把 JSON
文档原样写回给了按 Responses SSE 协议消费的客户端。Codex 只从
response.output_item.done 收集 item 且必须收到 response.completed,
收到 JSON 后报 "stream disconnected before completion: stream closed
before response.completed" 无限重连,每次重连再白烧一次上游 compact
配额(#3875,v0.1.146 无提升逻辑故正常)。
修复保留提升的全部收益(requireCompact 调度过滤、compact 模型映射、
白名单归一化、上游 unary JSON),补上协议转换缺失的响应半程:
- handler 在 body-signal 提升时记录原始 body 的 stream:true 意图
(MarkOpenAICompactClientStream);path-based 请求不标记,Codex v1
unary 协议与链式 sub2api 的 JSON 写回行为保持不变。
- 四个非流式写回点(handleNonStreamingResponse / handleSSEToJSON /
handleNonStreamingResponsePassthrough / handlePassthroughSSEToJSON)
对已标记的 2xx JSON 响应经 writeOpenAICompactSSEBridge 合成最小
Responses SSE:每个 output[] item 一条 response.output_item.done
(原始字段逐字节保留),最后一条 response.completed 携带完整
response 对象。
- 按 codex-rs 解析器硬约束兜底:先 json.Compact 防 pretty JSON 换行
破坏 SSE 帧;response.id 缺失时注入 resp_*(必填 string);usage
缺 input_tokens/output_tokens/total_tokens 整数字段时整体删除,
避免整条 completed 事件解析失败。
- 非 2xx 一律保持 JSON 原样,Codex 依赖 HTTP 状态码走重试链路。
新增 9 个 service 测试 + 4 个 handler 测试覆盖合成形态、id/usage 兜底、
path-based 不受影响、主链路/透传链路/上游 SSE 提取再合成三条端到端。
Fixes #3875
Refs #3777
2026-07-09 21:40:51 +08:00
InCerry
53a5c45bd8
fix(gateway): cap lenient json normalization
...
Fixes #3540
2026-07-09 11:15:52 +08:00
shaw
a56eb5b4dc
fix(compact): body-signal 提升上移到 handler 层并对齐 path-based 链路
...
合并 main 解决拆分冲突后,将原先 Forward 内的 body-signal 提升重构到
handler 的 compact 归一化入口之前,修复原方案的四个问题:
- reqStream 未重推导:body-signal 原始请求带 stream:true,Forward 级提升
后 compact 上游返回 JSON(Accept: application/json)却被流式 handler
解析,"stream ended before a terminal event" 会触发最多
max_account_switches 次换号 failover,且每次都白烧一次上游 compact 配额;
handler 级提升让白名单归一化先删除 stream,reqStream 自然为 false。
- requireCompact 调度过滤失效:原方案 path 改写发生在 requireCompact 判定
之后,调度器不会过滤不支持 compact 的账号;现在改写先于该判定。
- passthrough / Grok / chat-completions 桥接分支位于 Forward 检测点之前,
passthrough 账号完全无法命中;handler 级改写对所有分支生效。
- body 归一化口径不一致:body-signal 现在与 path-based 一样走白名单归一化
(prompt_cache_key 等一并删除),而非仅依赖 OAuth 黑名单转换。
检测函数导出为 HasCompactionTriggerInInput 供 handler 使用,保留原 PR 的
7 个单测;新增 6 个 handler 级回归测试(提升、codex 别名路由、尾斜杠、
子路径不误伤、path-based 无双重后缀、普通请求不受影响)。
Refs #3777
2026-07-08 10:04:14 +08:00
li
40c563c4ae
fix(gateway): 记录请求体解析失败的真实原因,不再吞错
...
400 "Failed to parse request body" 此前丢弃底层错误,无法区分
JSON 真非法、还是 body 被截断/被中间件提前消费。
- 服务层 invalid json 错误增补 len/offset/非法字符信息
(仅诊断元数据,不含 body 内容,可安全 wrap);
- handler 层新增 logRequestBodyParseFailure,向服务端日志输出
底层错误 + body 长度 + 转义后的 head/tail 片段(各 256B),
客户端响应文案保持不变;
- 接入全部 9 处入站解析点(messages/count_tokens/responses/
chat_completions/embeddings,Anthropic 与 OpenAI 网关)。
Fixes #3715
2026-07-07 13:53:39 +08:00
Wesley Liddick and GitHub
d1d3400b69
Merge pull request #3645 from bestony/worktree/lucky-harbor-dbe4
...
feat(keys): add api key concurrency stats
2026-07-06 16:45:15 +08:00
shaw
0fd2e9216d
fix(scheduler): 修复 OpenAI 高级调度器审计发现的正确性与性能问题
...
针对 #3692 合并后审计发现的问题集中修复:
- previous_response_id 剥离条件改为按 call_id 全覆盖校验,
部分可重建的工具续链不再被误剥离(不受开关门控的行为回归)
- 粘性加权回退路径补分组归属校验并清理失效绑定,杜绝跨分组账号泄漏
- 账号列表页:无 OpenAI 账号时跳过分数计算、过滤池限定 openai 平台、
负载批查合并为账号并集一次查询,消除全表扫描与 Redis N+1
- 订阅优先模式下常规池不可用时回退订阅池等待计划,
busy-but-waitable 的订阅账号不再导致请求硬失败
- TopK/权重 DB 覆盖显式受总开关门控,与兄弟子开关语义一致
- 前端未分组 OpenAI 账号回退展示基础分,不再显示 "-"
- ListAllWithFilters 等能力正式进入 AccountRepository/AdminService 接口,
移除匿名接口断言与静默降级;负载批查失败补 warn 日志
- SelectAccountWithSchedulerForCapability 增加显式 previousResponseCanMove
参数,移除 "previous_response_can_move" 魔法字符串哨兵
- 设置写入路径补"基础权重不得全为零"聚合校验;
运行时设置批量读取失败的降级路径覆盖全部键并留痕
2026-07-06 11:43:16 +08:00
linshuboy
f26ca5661e
feat: add OpenAI advanced scheduler controls
...
Related: #1089 , #408 , #123
2026-07-05 17:24:38 +08:00
Wesley Liddick and GitHub
3020652fa1
Merge pull request #3565 from zy6p/zy6p/pr-openai-ws-http-bridge
...
feat(openai-ws): 支持 http_bridge ingress 模式
2026-07-02 17:40:32 +08:00
Bestony@Homelab
089a7b7fae
feat(keys): add api key concurrency stats
2026-07-02 15:58:29 +08:00
bdf7ead157
feat(spark-shadow): OpenAI Spark 链接型影子账号
...
背景:gpt-5.3-codex-spark 使用独立于 codex 全局(5h/7d)的配额窗口(数据源是
/wham/usage 响应体的 codex_bengalfox,而非 codex 全局用的 x-codex-* 响应头),且
只能挂在已完成 OAuth 授权的 OpenAI 账号下复用其登录态,不能作为独立账号单独接入。
为此新增“链接型影子账号”(spark shadow account):影子账号本身不持有任何凭据,
通过 parent_account_id 指向母账号,凭据/token/代理透传自母账号并共享母账号的刷新
周期,仅在配额维度(quota_dimension=spark)和用量窗口上与母账号完全独立调度、互不
连坐。
实现:
- 数据模型:migration 154(+154a)给 accounts 表加 parent_account_id /
quota_dimension 列 + 4 条约束(维度合法 / parent⟺非 global 维度一致 / 禁自指 /
FK)+ 2 个 CONCURRENTLY 索引(母账号索引 + 每母账号至多一个影子的唯一索引)。
- 创建:POST /api/v1/admin/accounts/:id/shadow(CreateShadow)—— 一母一影(唯一
索引兜底并发竞态),继承母账号 proxy/分组/并发/优先级(显式传参可覆盖),默认
model_mapping 恒等映射到 spark(拒绝非 spark 模型),母账号必须是真实的 OpenAI
OAuth 账号(非影子)。
- 凭据透传:resolveCredentialAccount 把影子解析回母账号,GetAccessToken / 请求头
/ WS 三条路径统一走此函数;影子自身 Credentials 恒为空(仅允许写 model_mapping),
凭据写入的汇聚点 persistAccountCredentials 对影子早返 no-op,防止误写。
- 调度:parentHealthyForShadow 只看母账号是否仍是 OpenAI OAuth + 凭据/传输是否
可用(active、token 未过期、未处于 401/刷新失败/传输故障导致的临时不可调度冷却),
刻意不看母账号的 global 限流窗口——两条 429 道互不连坐。
- 用量:影子的 codex_5h/7d 走 OpenAIQuotaService.QueryUsage(/wham/usage 的
codex_bengalfox),与母账号走的 WSv2 探测(/responses 头)完全独立的数据源、
刷新节流与 staleness 判定。
- 备份:ExportData 显式排除影子账号(影子不持凭据,通用凭据型导入强制
credentials 非空、无法表达父子链接),按 skipped_shadows 计数提示前端。
- 前端:账号操作菜单新增“创建 Spark 影子”入口,影子行展示回填的母账号信息
(邮箱 / plan / 隐私模式 / 订阅到期 / chatgpt_account_id),批量操作自动跳过
影子账号。
说明:migrations 目录用完整文件名(而非纯数字前缀)标识迁移,故本次新增的
154_account_spark_shadow.sql / 154a_..._notx.sql 与已有的
154_add_ops_system_logs_api_key_id.sql 按序号共存,与目录里 145/151 已有的
先例一致。
测试:新增约 20 个测试文件,覆盖 handler(CreateShadow 校验 / 母账号信息回填)、
repository(影子 round-trip / 一母一影唯一索引 / 迁移 schema)、service(凭据
透传三路径 / 调度母健康门 / 用量窗口来源与刷新节流 / CRS 母账号不变量 / 各类
早返与 fail-closed 场景)及前端组件(账号列表 / 操作菜单 / 用量重置)。
验证(镜像 CI;golangci-lint 首次全量分析耗时过长被跳过,其余全部实测):
- gofmt -l:干净
- go build ./... / go vet ./...:通过
- go test ./... -count=1:全绿(全部包 ok,含 internal/service、
internal/repository、migrations)
- go test -tags integration ./internal/repository/... ./internal/service/...
(真实 Postgres,testcontainers):全绿,含迁移幂等性
(TestMigrationsRunner_IsIdempotent_AndSchemaIsUpToDate)与影子相关全部用例
- pnpm lint:check / pnpm typecheck / pnpm build(真实 vite 构建)/
pnpm vitest run:全绿(124 文件 760 用例)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com >
2026-07-01 12:21:45 +08:00