Wesley Liddick and GitHub
bfabfe60c8
Merge pull request #4593 from StarryKira/fix/image-storage-env-unreachable
...
fix: 异步生图开关配了却不生效(环境变量被静默丢弃 + 迁移到后台开关)
2026-07-20 09:20:15 +08:00
Jlypx and Sisyphus
f72958d530
feat: 持久化客户端 IP 请求头设置
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:09:11 +08:00
Jlypx and Sisyphus
8b8b6b3132
feat: 定义客户端 IP 请求头系统设置
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:09:00 +08:00
Jlypx and Sisyphus
93717394b2
fix: 迁移客户端 IP 兼容开关
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-19 21:41:45 +08:00
haruka and Claude Opus 4.8
b08cab91a9
feat(image-storage): 异步生图对象存储改为后台配置,保存即生效
...
此前开启异步生图必须改服务器上的 config.yaml 并重启容器(#4542),且若想
复用已配置的备份 S3,还得把同一套凭证再填一遍(#4458)。
- 新增 ImageStorageSettingService:配置存 settings 表,SecretAccessKey 经
SecretEncryptor 加密落库、读回脱敏、留空表示沿用旧值,与备份 S3 配置同一套做法。
- reuse_backup_s3(默认开)直接借用 backup_s3_config 的端点与密钥,只用自己的
bucket/prefix 区分对象,因此备份走 backups/、图片走 images/,且密钥不会在库里存两份。
- ImageTaskService 的启用状态改由 ImageStorageResolver 在运行时解析并缓存,
保存设置后 Invalidate 使下次请求重建客户端——不再需要重启。
- repository 侧由提供实例改为提供工厂,客户端才可能在运行期重建。
- 轮询接口的门控从 enabled() 放宽为 Pollable():关掉开关只拒绝新提交,
已受理的任务仍可取回结果,不再被中途吞掉。
- config.yaml 的 image_storage 保留为回落,后台从未保存过时沿用,
升级前已用配置文件开启的部署不受影响。
- 管理端 GET/PUT/POST /admin/backups/image-storage,PUT 与备份 S3 配置一样要求
step-up 2FA:改写存储目标同样能把生成内容导向外部账号。
注:go generate ./cmd/server 在当前 upstream 基线上即失败(securityaudit.
PromptAdminService 缺 provider),故 wire_gen.go 为手工同步。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01VHreE5pzCkSYz7J45fmd2Y
2026-07-19 00:56:21 -07:00
Wesley Liddick and GitHub
19149ca196
Merge pull request #4558 from fengshao1227/fix/antigravity-plan-type-preserve
...
fix(antigravity): 保留付费 tier 的 PlanType,IneligibleTiers 仅标记异常状态
2026-07-18 21:48:44 +08:00
Wesley Liddick and GitHub
831812b39d
Merge pull request #4556 from superman2003/fix/grok-free-probe-encrypted-recovery
...
fix(grok): stabilize Free probes and encrypted reasoning recovery
2026-07-18 21:48:31 +08:00
li
72b29a7d4e
fix(antigravity): 保留付费 tier 的 PlanType,IneligibleTiers 仅标记异常状态
...
Fixes #4519
2026-07-18 21:43:54 +08:00
shaw
14608dc6d4
Merge origin/main into codex/secure-protected-video-content-4498
...
Reconcile with #4539 (grok media account model mapping), now on main:
- handler/grok_media.go non-failover error path keeps both changes —
#4539 's grokMediaScheduleModel(account, routingModel, nil) schedule
attribution and this branch's IsResponseCommitted guard
- auto-merged sections verified: routing/classify use #4539 's routingModel,
video lookup owner-binding and no-failover semantics intact, ForwardGrokMedia
keeps mapping block (skipped for lookup endpoints via RequiresRequestBody),
empty-image failover, and video-status URL rewrite in order
2026-07-18 21:38:17 +08:00
shaw
8a95a46a69
Merge origin/main into codex/secure-protected-video-content-4498
...
Resolve conflicts with main:
- service/grok_media.go: keep both post-response blocks — #4497 's empty
image-output failover (main) runs first for image endpoints, then this
branch's video-status content-URL rewrite; the endpoint conditions are
mutually exclusive
- handler/openai_gateway_credential_failover_loop_test.go: mark the stub
OAuth accounts media-eligible via the grok_media_eligible extra override,
because this branch moved grok media failover coverage to the generation
endpoint, which is now gated by #4540 's paid-eligibility probe on main
2026-07-18 21:31:28 +08:00
shaw
9d498c2474
Merge origin/main into codex/fix-grok-media-model-mapping-4503
...
Resolve conflicts with main:
- handler/grok_media_test.go: keep both new tests (schedule model test from
this branch, eligibility gating tests from #4540 )
- service/openai_gateway_grok_test.go: keep both new tests; update the image
cases of the mapping table test to return a non-empty image payload because
#4497 (already on main) now converts empty image responses into an upstream
failover error
2026-07-18 21:25:43 +08:00
Wesley Liddick and GitHub
a2f802d409
Merge pull request #4541 from wucm667/fix/issue-4532-renew-expired-subscription
...
fix(subscription): renew expired admin assignments
2026-07-18 21:14:23 +08:00
Wesley Liddick and GitHub
b01196a7a8
Merge pull request #4553 from wp-a/fix/openai-ws-turn-lifecycle
...
[codex] enforce websocket passthrough turn lifecycle
2026-07-18 21:10:48 +08:00
superman2003
e14fb2b6ff
fix(grok): recover invalid encrypted content once
2026-07-18 21:05:50 +08:00
superman2003
dd7a2b22f0
fix(grok): align Free probes with health checks
2026-07-18 21:05:50 +08:00
shaw
4e8ea7d568
fix(test): 池模式临时规则测试适配 #4547 模型级隔离语义
...
#4496 与 #4547 文本无冲突但语义相撞:#4496 的测试断言规则命中后账号级
跨模型封锁,#4547(issue 4527 第4点)将已知模型的临时不可调度改为按
模型隔离(SetModelRateLimit,不再触发账号级 runtime block)。
按 #4547 的语义更新断言:命中模型 gpt-5.4 记模型级封锁、gpt-5.5 不受
影响、不再调用账号级 SetTempUnschedulable;池模式规则仍生效(停止同
账号重试),issue 4470 的诉求不受影响。未知模型的账号级兜底已由
TestOpenAITempUnschedulable_UnknownModelKeepsAccountRuntimeBlock 覆盖。
2026-07-18 21:02:23 +08:00
Wesley Liddick and GitHub
23cdd20606
Merge pull request #4537 from heathermhuang/codex/refresh-anthropic-monitor-1953
...
fix(monitor): refresh Anthropic text-block extraction
2026-07-18 20:49:40 +08:00
Wesley Liddick and GitHub
a62b821b5f
Merge pull request #4478 from yardbirds0/codex/fix-upstream-billing-probe-refresh
...
fix: 完善上游 Sub2API 倍率探测刷新、展示与账号配置
2026-07-18 20:49:14 +08:00
Wesley Liddick and GitHub
774ff5d8c8
Merge pull request #4515 from BenjaminAaron196/feat/filter-noise-rejected-requests
...
(fix) 过滤入口拒绝日志并强化鉴权安全边界
2026-07-18 20:46:50 +08:00
Wesley Liddick and GitHub
e002fbb349
Merge pull request #4508 from wucm667/fix/model-not-found-transient-misclassification
...
fix: 临时账号耗尽时保留 503 错误分类
2026-07-18 20:41:35 +08:00
Wesley Liddick and GitHub
005bc5c8d4
Merge pull request #4497 from heathermhuang/agent/fix-grok-media-fallback-4471
...
fix(grok): fail closed for ineligible OAuth media
2026-07-18 20:41:24 +08:00
Wesley Liddick and GitHub
bc4bd118d8
Merge pull request #4547 from heathermhuang/codex/fix-model-scoped-temp-cooldown-4527
...
fix(routing): isolate temporary cooldowns by model
2026-07-18 20:41:12 +08:00
Wesley Liddick and GitHub
f3925db11b
Merge pull request #4496 from StarryKira/agent/fix-4470-pool-temp-unschedulable
...
fix: honor temp unschedulable rules in pool mode
2026-07-18 20:40:12 +08:00
Wesley Liddick and GitHub
f9a467a4c0
Merge pull request #4520 from StarryKira/codex/fix-4487
...
fix: report Chat Completions stream transport failures
2026-07-18 20:39:49 +08:00
Wesley Liddick and GitHub
8ce9288a6a
Merge pull request #4489 from fengshao1227/fix/grok-free-cache-tool-injection
...
fix(grok): 纯客户端函数工具不再注入原生搜索工具
2026-07-18 20:39:37 +08:00
Wesley Liddick and GitHub
c1e702be5e
Merge pull request #4505 from cyhhao/fix/claude-1m-model-suffix
...
fix(gateway): normalize Claude Code 1m model suffix
2026-07-18 20:39:27 +08:00
haruka and Claude Opus 4.8
37db8d031b
fix(config): 让环境变量能真正配置 image_storage 等凭证
...
viper.Unmarshal 只解码 AllKeys() 返回的键,而 AllKeys() 只汇总 SetDefault、
配置文件和显式 BindEnv 三个来源。AutomaticEnv 仅能覆盖已在其中的键,无法引入
新键;能兜底的 viper_bind_struct 又被 build tag 排除(我们只用 -tags embed)。
因此任何「没有注册默认值、且不在 config.yaml 里」的配置项,其环境变量会被静默
丢弃。image_storage 的 endpoint/bucket/access_key_id/secret_access_key/
public_base_url 正属此列,于是纯环境变量部署落到最坏组合:IMAGE_STORAGE_ENABLED
生效使 Enabled=true,四个凭证却为空 → Active()=false → 异步生图接口整体 404,
运维看到的却是"凭证不完整"。deploy/docker-compose.yml 默认就是纯环境变量驱动,
且自动生成的 config.yaml 从不写 image_storage 段,必然踩中(见 #4458、#4542)。
同类缺口不止于此:github_oauth、google_oauth、dingtalk_connect 三组第三方登录
配置(含 client_secret)同样完全无法用环境变量设置。
- 为这些键注册零值默认,使其进入 AllKeys() 而可被环境变量覆盖。零值与"键缺失"
时的解码结果一致,故行为不变。
- sticky_escape_enabled 例外:它的实际默认是 true(靠 IsSet 守卫在解码后补上),
注册 false 会让 IsSet 恒真而永久关闭该特性,故直接注册 true。
- 启动告警补上 missing_keys 字段,指明到底哪个凭证为空。
- 新增反射守卫测试:Config 结构体上每个可由环境变量表达的字段都必须已注册默认值。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01VHreE5pzCkSYz7J45fmd2Y
2026-07-18 05:24:32 -07:00
王鹏
f0e0b7e6d8
fix(openai-ws): enforce passthrough turn lifecycle
2026-07-18 19:17:53 +08:00
Heatherm Huang
4c845ca697
test(grok): sanitize security fixtures
2026-07-18 17:50:53 +08:00
Heatherm Huang
95d27f2dce
fix(grok): fetch validated signed video content
2026-07-18 17:49:09 +08:00
Heatherm Huang
f2e7a55703
fix(grok): proxy signed video status URLs
2026-07-18 17:21:53 +08:00
Heatherm Huang
b4ad7fd363
test(grok): configure multipart media mapping
2026-07-18 15:49:21 +08:00
Heatherm Huang
ef2a22be70
fix(routing): isolate temporary cooldowns by model
2026-07-18 15:35:30 +08:00
Heatherm Huang
c831bb979f
fix(grok): scope video content to request owner
2026-07-18 14:56:15 +08:00
Heatherm Huang
3edcbfd120
fix(grok): keep media content proxy URLs same-origin
2026-07-18 14:43:08 +08:00
wucm667
1db10dc559
fix(subscription): renew expired admin assignments
2026-07-18 14:42:22 +08:00
Vz7797 and Heatherm Huang
3f6b5c7bd7
fix(grok): proxy protected video content through upstream account
...
(cherry picked from commit a01177e294aa3df1134cd3cf12b49635c1097035)
2026-07-18 14:37:25 +08:00
Heatherm Huang
335edde9c8
fix(grok): apply account model mapping to media
2026-07-18 14:21:47 +08:00
mark-ly-wang and Heatherm Huang
1a855d3e0e
fix(monitor): extract anthropic text blocks
...
(cherry picked from commit 76cf1ee834c78e3b15dee6fc23244fbae94a4bd1)
2026-07-18 13:53:36 +08:00
shaw
539bfc8bad
feat(security): 敏感操作 step-up 2FA 开关化,安全开关默认关闭
...
新增系统设置 step_up_enabled(默认关闭),把敏感操作 2FA 门控做成可开关;
同时将会话 IP/UA 绑定默认值从开启改为关闭,避免用户因 IP 变动登录后掉线。
## 新增功能
- 敏感操作 step-up 2FA 总开关 step_up_enabled(默认关闭):关闭时账号/代理导出、
备份创建/下载、S3 配置修改、提升管理员等操作恢复门控引入前的直接放行行为;
开启后要求当前会话在 15 分钟内完成过 TOTP step-up 验证。
## 优化改进
- 会话 IP/UA 绑定默认改为关闭(功能保留,可在设置页按需开启)。
- 开启 step-up 开关需操作者本人已启用 TOTP(防自锁);关闭开关本身作为敏感操作,
需通过 step-up 验证(防止攻击者拿到会话后先关闸再导出/备份)。
- 两个安全开关请求字段改为可空指针(省略=保持现值),避免旧客户端全量保存时
静默重置安全开关。
- 备份恢复(整库覆盖可回滚安全设置)纳入 step-up 门控。
- 审计摘要 diffSettings 补记 step_up_enabled / session_binding_enabled 变更。
## Bug 修复
- 修复 BackupView 恢复操作 409(恢复进行中)判断未适配 apiClient 扁平化错误对象。
2026-07-18 10:46:42 +08:00
haruka
bd0f2d6405
fix: report chat stream transport failures
2026-07-18 03:24:04 +08:00
benjamin
71afe24710
fix: 修复CI检查问题
2026-07-18 00:42:16 +08:00
benjamin
b92bbf0299
fix: 过滤入口拒绝日志并强化鉴权边界
2026-07-18 00:11:18 +08:00
wucm667
2594950993
fix: classify transient account exhaustion as 503 instead of 404
2026-07-17 22:10:18 +08:00
cyh
2264a33085
fix(gateway): normalize Claude Code 1m model suffix
2026-07-17 21:59:57 +08:00
Tian Lee
d2585097f3
fix: 完善上游 Sub2API 计费倍率探测与账号展示
2026-07-17 20:59:29 +08:00
Heatherm Huang
e86063155f
fix(grok): gate OAuth media on paid eligibility
2026-07-17 19:15:16 +08:00
haruka
1f7b7b9132
fix: honor temp unschedulable rules in pool mode
2026-07-17 18:12:33 +08:00
li
7043982ae3
fix(grok): 纯客户端函数工具不再注入原生搜索工具
...
Fixes #4486
2026-07-17 16:59:40 +08:00
li
e375623abf
fix(gateway): 被动 image_gen namespace 不再强制要求 Responses capability
...
Fixes #4476
2026-07-17 15:07:41 +08:00