yan9651688
e2e375d694
Make repeated channel-monitor setup safer
...
Admins often recreate monitors with the same endpoint, model, and request settings. A server-side duplicate keeps the stored API key out of the browser, creates a disabled copy for review, and uses stable operation identity to recover ambiguous retries without creating extra rows.
Constraint: Stored monitor API keys must never be returned to the browser
Constraint: Applying a request template must preserve internal duplicate recovery metadata
Rejected: Rebuild the monitor from list data | list responses only contain a masked API key
Rejected: Copy runtime state and history | a duplicate should start as an unverified configuration
Confidence: high
Scope-risk: moderate
Reversibility: clean
Directive: Keep duplicated monitors disabled until an administrator reviews and enables them
Tested: Go unit tests for repository, service, and admin handler; integration-tag compile; go vet; golangci-lint v2.9; frontend Vitest, ESLint, typecheck, production build; Playwright duplicate flow
Not-tested: PostgreSQL container integration locally because Docker is unavailable; CI will execute the database-backed suite
2026-07-16 16:30:19 +08:00
zhaozewu
7947619cc3
feat(admin): batch update user limits
2026-07-16 15:37:35 +08:00
Wesley Liddick and GitHub
393a8fe56a
Merge pull request #4424 from StarryKira/fix/4417-responses-image-account-capability
...
fix(gateway): route image-intent /v1/responses only to Responses-capable accounts (#4417 )
2026-07-16 15:35:45 +08:00
shaw
590efe29a5
Merge remote-tracking branch 'origin/main' into agent/fix-4326-async-image-object-storage
...
# Conflicts:
# backend/cmd/server/wire_gen.go
2026-07-16 15:32:38 +08:00
haruka and Claude Opus 4.8
605b026cc4
fix(gateway): route image-intent /v1/responses only to Responses-capable accounts ( #4417 )
...
For OpenAI-compatible API-key accounts, /v1/responses requests with
image-generation intent could be scheduled to accounts whose upstream
does not support the Responses API (extra.openai_responses_supported=false).
The flag was only consulted at forward time, where such accounts are
silently downgraded to a Chat-Completions path that cannot produce images,
causing upstream 4xx/5xx or canceled requests.
Fix:
- Add endpoint capability OpenAIEndpointCapabilityResponses. Its check in
SupportsOpenAIEndpointCapability excludes only OpenAI API-key accounts
probed as unsupported (mirroring the forward-time downgrade condition);
OAuth/Grok/unprobed accounts keep existing behavior, and a responses-
capable upstream must still pass the chat_completions gate. Reusing the
existing requiredCapability plumbing makes every scheduler filter path
enforce it with no scheduler signature changes.
- Request the responses capability at the HTTP Responses and
ResponsesWebSocket call sites only when imageIntent && platform==openai,
so non-image requests keep the downgrade path and Grok's own image path
is untouched.
- Normalize max_tokens -> max_output_tokens on the native responses
forward path (PlatformOpenAI), and strip prompt_cache_options alongside
prompt_cache_retention/safety_identifier.
/v1/images/generations continues to use native image capability (unchanged).
Tests: capability truth table, scheduler exclusion of unsupported accounts,
and forward-path transform behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KXpzKKvsb5jW2GvgBQqnnZ
2026-07-16 00:23:40 -07:00
shaw
0ddd58aaf9
feat(security): 操作审计日志 + 会话IP/UA绑定 + 敏感操作 step-up 2FA
...
应对管理员访问凭证失守导致的数据外泄风险,新增三层防护:
审计日志(admin-only 可见,用户不可见)
- 新增 append-only audit_logs 表(migration 180)+ 异步批量写入 + 保留期清理
- 审计中间件挂在 admin/user/auth/admin-payment 组认证之后:记录所有变更类
请求 + 白名单敏感读取(账号/代理导出、备份下载、admin/user API key 读取)
- 请求头凭证首尾掩码;请求体 JSON 递归脱敏(api_key/password 等擦除,base_url
保留以便追责);非 JSON body 不入库
- 无单条删除;全量清空需现场 TOTP 校验、拒绝 admin API key、未启用 2FA 不允许,
清空后同步写入留痕记录
会话 IP/UA 绑定(默认开启,可在系统设置关闭)
- JWT 携带 session id + IP/UA 指纹哈希;IP 或 UA 任一变化即撤销会话家族并要求
重新登录;旧 token 无指纹时放行以平滑升级
敏感操作 step-up 2FA(sudo 窗口 15 分钟)
- 账号/代理导出、DB 备份创建/下载、S3 目标修改要求近期 TOTP 二次验证;admin API
key 一律拒绝;前端 useStepUp 组合式 + TotpStepUpDialog 弹码后自动重试
- API key 查看按需求暂不加强管控
前端:新增 /admin/audit-logs 操作日志页面(筛选/详情/2FA 清空)、侧边栏入口、
step-up 弹窗接入导出与备份流程、安全设置项(绑定开关 + 日志保留天数)、zh/en i18n
2026-07-16 13:47:50 +08:00
haruka and Claude Opus 4.8
0eb6e21aaa
feat: 异步图片任务结果落对象存储
...
为异步生图任务增加 S3 兼容对象存储支持,任务结果不再把大图内联存进 Redis:
- 新增可插拔接口 service.ImageStorage(Save -> url),适配别的厂商只需实现它
- S3 实现 S3ImageStorage(AWS S3 / R2 / 阿里云 OSS / MinIO),与备份共用 S3 客户端构造
- 新增 image_storage 配置(config.yaml + IMAGE_STORAGE_* 环境变量),默认关闭
- enabled 同时作为总开关:关闭或未配置对象存储时,异步生图接口返回 404 且不写
Redis,从根上避免几 MB 的 b64_json 结果撑爆 Redis
- 完成时把图片上传对象存储并把结果改写为短链接(公开直链或 presigned),
上传失败则任务标记为失败
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01SM1tf3CFVRzC7guuhBXvMd
2026-07-15 19:57:37 -07:00
haruka
1fb942dd77
feat: add async image generation tasks
2026-07-15 19:57:37 -07:00
shaw
0408bdb34f
Merge remote-tracking branch 'origin/main' into feat/upstream-rate-scheduling
...
# Conflicts:
# backend/internal/handler/openai_gateway_handler.go
2026-07-16 10:31:21 +08:00
Wesley Liddick and GitHub
ab978e615e
Merge pull request #4385 from yardbirds0/feat/upstream-billing-probe
...
feat: 增加上游 Sub2API 计费倍率探测与账号展示
2026-07-16 10:27:45 +08:00
Wesley Liddick and GitHub
8d36ce3d20
Merge pull request #4108 from yardbirds0/feat/key-billing-info
...
feat: 增加 API Key 计费倍率自省接口
2026-07-16 10:27:35 +08:00
Wesley Liddick and GitHub
502097026f
Revert "feat: 支持异步生图任务与结果轮询"
2026-07-16 09:47:27 +08:00
Wesley Liddick and GitHub
a3a227c858
Merge pull request #4381 from StarryKira/agent/fix-4326-async-image-tasks
...
feat: 支持异步生图任务与结果轮询
2026-07-16 09:44:26 +08:00
Wesley Liddick and GitHub
531ae04a0b
Merge pull request #4395 from wp-a/fix/openai-body-limit-failover
...
[codex] fail over account-specific OpenAI body limits
2026-07-16 09:33:48 +08:00
Wesley Liddick and GitHub
e4329a04e8
Merge pull request #4393 from superman2003/fix/grok-codex-compatibility
...
fix(grok): improve Codex compatibility and key setup
2026-07-16 09:33:20 +08:00
Wesley Liddick and GitHub
f3138ceb43
Merge pull request #4384 from wp-a/fix/openai-model-scoped-transient-cooldown
...
[codex] scope OpenAI transient cooldowns by model
2026-07-16 09:33:09 +08:00
Wesley Liddick and GitHub
1c5c42c183
Merge pull request #4394 from siyuan-123/codex/pr-gpt56-pat-alpha-search
...
fix(openai): route PAT alpha search via responses web_search
2026-07-16 09:32:59 +08:00
Wesley Liddick and GitHub
3fc0336e1d
Merge pull request #4377 from wp-a/fix/openai-ws-ingress-lifecycle
...
[codex] close OpenAI WS ingress reads cleanly
2026-07-16 09:32:50 +08:00
Wesley Liddick and GitHub
807850769f
Merge pull request #4396 from StarryKira/fix/4386-image-input-pricing
...
fix(billing): 图像输入 token 按独立单价计费(gpt-image-2 图片编辑)
2026-07-16 09:32:29 +08:00
Wesley Liddick and GitHub
7e43ebc792
Merge pull request #4369 from wp-a/fix/openai-wsv2-malformed-json
...
[codex] reject malformed OpenAI WS v2 events
2026-07-16 09:31:39 +08:00
haruka and Claude Opus 4.8
62d57c02d8
feat(billing): usage_logs 单独记录图片输入 token 与费用
...
图片编辑/图生图请求的图片输入 token 此前并入 input_tokens/input_cost,
无法对账。拆分上报口径,total_cost 保持不变。
后端:
- CostBreakdown 新增 ImageInputCost;computeTokenBreakdown 将图片输入费用
从 InputCost 拆出(InputCost 从此仅含文本输入),并纳入 tier 倍率与总额;
长上下文合并路径同步携带 ImageInputCost
- 迁移 179:usage_logs 新增 image_input_tokens / image_input_cost 列
- UsageLog、insert/query 仓储(含定位参数数组、CTE 列表、扫描顺序)、
DTO 与 mapper 补齐两列
- openai_gateway_usage 从 usage 与 cost 落库图片输入 token/费用
前端:
- UsageLog 类型、imageUsage 工具(hasImageInputTokens/Cost、textInputTokens)
- 用量表 token 徽标、Token/费用 tooltip 与单价行按图/文输入拆分展示
- zh/en usage.* i18n
测试:
- 新增 gpt-image-2 图片编辑复现用例(复现 #4386 的 $0.016081 期望值)
- 新增 usage 提取器图片输入 token 解析用例(input_tokens_details.image_tokens)
- 更新 doubao 图文分价用例与仓储/契约测试以匹配新的 input/image 拆分口径
相关 #4386。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_015wcJTKDddxXSQrepSs3wrU
2026-07-15 10:03:38 -07:00
王鹏
ad5e2a85b7
test(openai): validate body-limit error envelope
2026-07-16 00:52:26 +08:00
Tian Lee
90ee85f3ef
feat: 按上游计费倍率调度 OpenAI 账号
2026-07-16 00:40:46 +08:00
siyuan
776f3f0de7
fix(openai): align alpha search PAT forwarding
2026-07-16 00:36:38 +08:00
haruka and Claude Opus 4.8
06e03f467a
feat(billing): 渠道自定义定价支持图片输入 token 单价 image_input_price
...
渠道 token 计费模式此前无法为图片输入 token 单独定价,gpt-image-2
图片编辑等请求的图像输入被按文本 input_price 计费。新增
channel_model_pricing.image_input_price 列及全链路支持。
后端:
- 迁移 178:channel_model_pricing 新增 image_input_price 列
- ChannelModelPricing 新增 ImageInputPrice 字段,repo 读写、校验补齐
- model_pricing_resolver / GetModelPricingWithChannel 映射到
ImageInputPricePerToken;未配置时归零,由 computeTokenBreakdown
回退文本输入价(向后兼容,与 image_output_price 的渠道权威规则一致)
- admin / 用户侧定价 DTO 与 model-pricing 自动填充接口补充该字段
前端:
- 渠道定价表单新增「图片输入」价格输入(token 模式)
- API 类型、表单模型、form↔API 换算、自动填充、用户侧模型定价卡展示
- zh/en i18n 标签
相关 #4386。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_015wcJTKDddxXSQrepSs3wrU
2026-07-15 09:35:34 -07:00
王鹏
3db00d3fee
fix(openai): fail over account-specific body limits
2026-07-16 00:19:20 +08:00
superman2003
410ea8490c
fix(grok): allow passive Codex image tool declarations
2026-07-16 00:16:21 +08:00
Tian Lee
0765d10c1d
feat: 增加上游 Sub2API 计费倍率探测与账号展示
2026-07-15 23:58:46 +08:00
王鹏
40b8f04a6a
fix(openai): scope transient cooldowns by model
2026-07-15 22:52:35 +08:00
Tian Lee
f59a6ed74c
feat: 增加 API Key 计费倍率自省接口
2026-07-15 22:42:53 +08:00
wucm667
2fe7df9b81
fix(openai): reject image models on chat completions
2026-07-15 22:22:51 +08:00
王鹏
4f641208a0
fix(openai-ws): close ingress reads cleanly
2026-07-15 22:15:44 +08:00
haruka
134179085c
feat: add async image generation tasks
2026-07-15 22:13:37 +08:00
王鹏
716fcc6f3d
fix(openai): reject malformed WS v2 events
2026-07-15 21:20:41 +08:00
Wesley Liddick and GitHub
be6cd1250c
Merge pull request #4367 from Wei-Shaw/feat/grok-custom-base-url-and-headers
...
feat(grok): 支持账号级自定义上游地址与请求头覆写
2026-07-15 20:55:16 +08:00
Wesley Liddick and GitHub
34015a1791
Merge pull request #4359 from catoncat/agent/fix-agent-identity-import-expiry
...
fix(openai): make Agent Identity usable end to end
2026-07-15 20:55:05 +08:00
Wesley Liddick and GitHub
a733e66330
Merge pull request #4358 from DanisJiang/feat/admin-recharge-affiliate-rebate
...
feat(affiliate): support rebates for admin balance deposits
2026-07-15 20:54:48 +08:00
Wesley Liddick and GitHub
960d1886f3
Merge pull request #4323 from turingcat/feat/plan-currency-label
...
feat(payment): 订阅套餐支持币种标注,区分 $ 符号对应币种
2026-07-15 20:54:34 +08:00
shaw
221581400b
feat(grok): 支持账号级自定义上游地址与请求头覆写
...
将账号级请求头覆写从 anthropic/openai 的 api_key 账号扩展到 Grok 的
api_key 与 oauth 账号,并放开 Grok OAuth 账号的自定义上游地址(仅作用于
转发端点,授权与 token 刷新链路不变)。
后端:
- IsHeaderOverrideEligible 扩展到 Grok(api_key+oauth),禁止名单新增
x-grok-conv-id(逐请求会话路由头)。
- 所有 Grok 上游请求路径接线 ApplyHeaderOverrides(Responses/Chat 桥/
媒体/配额探测/billing 探测/连通性测试),统一置于内置默认头之后。
- GetGrokBaseURL/GetGrokMediaBaseURL 放开 OAuth 自定义地址:官方地址
视同未定制回落官方网关,仅显式第三方 host 改发转发流量。
- 非官方 host 允许任意 path 前缀,官方 host 仍强制 /v1。
- OAuth base_url 校验按 host 判定官方/自定义,自定义 host 恒受运营方
URL 策略约束,不受 XAI_ALLOW_UNSAFE_URL_OVERRIDES 调试开关放宽。
- 给 GrokQuotaService 注入 config,使配额/billing 探测与转发共用同一
URL 策略。
前端:
- Edit 模态为 Grok OAuth 账号新增「自定义上游地址」开关。
- 请求头表单新增 JSON 快速导入与按 JSON 一键复制(复用 useClipboard,
兼容非安全上下文 HTTP 页面)。
- 门控改为平台×类型判定,Bulk 批量 base_url 增加格式校验,zh/en 文案同步。
2026-07-15 20:30:23 +08:00
cat
529744c7c7
fix(openai): 修复 Agent Identity 导入过期校验
2026-07-15 17:52:10 +08:00
Yuhao Jiang
736824dd7a
feat(affiliate): add admin recharge rebate option
2026-07-15 04:28:55 -05:00
shaw
4e4ce440b3
fix(test): align duplicate account test with new NewAccountHandler signature
2026-07-15 16:13:22 +08:00
shaw
bdb5be1c42
Merge remote-tracking branch 'origin/main' into pr4241-fix
2026-07-15 16:11:28 +08:00
Wesley Liddick and GitHub
0de768e8be
Merge pull request #4221 from heathermhuang/codex/fix-grok-oauth-pool-health
...
fix(grok): refresh OAuth pools proactively
2026-07-15 16:07:09 +08:00
Wesley Liddick and GitHub
bac925624f
Merge pull request #4289 from Tiantianr/fix/openai-ws-first-message-timeout
...
fix(openai-ws): make first-message timeout configurable
2026-07-15 15:45:24 +08:00
Wesley Liddick and GitHub
8e84071f21
Merge pull request #4307 from wp-a/fix/openai-first-output-timeout
...
fix(openai): bound native responses first output wait
2026-07-15 14:41:11 +08:00
Wesley Liddick and GitHub
2d218fbe61
Merge pull request #4317 from yan9651688/feat/account-one-click-copy
...
feat(accounts): add safe one-click account duplication
2026-07-15 14:23:35 +08:00
王鹏
fc4089f292
fix(openai): bound native responses first output wait
...
Add an opt-in first semantic output budget for native HTTP Responses, including response-header wait. Keep preamble and keepalive bytes non-semantic so a stalled account can fail over once without replaying its response IDs. Defaults remain disabled.
Related to #4201 , #4185 , and #4248 . Complements the HTTP/2 dead-connection fix in #4207 .
2026-07-15 13:01:16 +08:00
turingcat and Claude Fable 5
2bbdd47002
feat(payment): 订阅套餐支持币种标注,区分 $ 符号对应币种
...
后台配置与用户端展示的套餐价格统一使用 $ 符号,而实际扣款币种随
支付渠道配置漂移(如 Stripe 配置 NZD 时按新西兰元扣款),用户易
误认为美元。本次为套餐新增可选的展示性币种标注:
- SubscriptionPlan 新增 currency 字段(ISO 4217 三字母码,默认空)
- 空值不展示任何标注,存量套餐行为完全不变
- 非空值复用 payment.NormalizePaymentCurrency 校验并规范化为大写
- 后台套餐编辑弹窗新增可选币种输入,列表价格列展示币种小字
- 用户端套餐卡片价格与划线原价旁展示币种小字
- 纯展示性质,不影响任何支付/扣款逻辑
Closes #4315
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-07-15 11:17:45 +08:00
Wesley Liddick and GitHub
5b5e41450c
Merge pull request #4310 from jianjianai/codex/perf-scheduler-final
...
perf(scheduler): 完善缓存桶生命周期并复用重建批次查询
2026-07-15 11:09:47 +08:00