Commit Graph
1710 Commits
Author SHA1 Message Date
song e6eb23eaac feat(openai): add Live gateway support 2026-07-25 12:50:46 +08:00
shaw a5aae5db9a fix(security): 升 postcss 到 >=8.5.18 修复 frontend-security 红灯
新披露两条 high 级公告命中锁文件里的 postcss@8.5.6,frontend-security 的
audit exception 检查失败:

- GHSA-6g55-p6wh-862q(2026-07-23 披露,修复版 8.5.12)
  CSS 注释中攻击者可控的 sourceMappingURL 导致任意文件读取与信息泄露
- GHSA-r28c-9q8g-f849(2026-07-24 披露,修复版 8.5.18)
  Previous Source Map 自动加载存在路径穿越,导致任意 .map 文件泄露

postcss 不只是 devDependency —— 它经 vue → @vue/compiler-sfc 进入生产依赖树,
因此 `pnpm audit --prod` 会命中。用 pnpm.overrides 而非只升直接依赖,可保证
所有引入路径的实例都被抬到修复版(沿用本仓 form-data@<4.0.6 的既有写法)。

锁文件用 pnpm 10 重新解析以匹配现有锁文件的生成工具,避免 pnpm 9 误删
11 处 libc: [glibc|musl] 平台门控字段;lockfileVersion 保持 9.0。
实际解析到 postcss 8.5.23,nanoid 3.3.11→3.3.16 是 postcss 自身依赖的
补丁级跟随,diff 无其他无关变动。

验证:复现 CI 失败步骤(pnpm audit --prod --audit-level=high +
tools/check_pnpm_audit_exceptions.py)已通过;CI 所用 pnpm 9 的
--frozen-lockfile 接受该锁文件;vue-tsc --noEmit、pnpm build、vitest 均通过。
2026-07-25 11:45:42 +08:00
shaw 6c9b84cc7a feat: 适配 Anthropic 新模型 claude-opus-5
模型登记:/v1/models 清单、Bedrock 默认映射(us.anthropic.claude-opus-5-v1)、
定价条目($5/$25 per MTok、1M 上下文、128K 输出)、前端模型清单与
Anthropic/Bedrock 预设映射、限流 scope 简称。

同时修复两个会静默出错的问题:

- 定价家族兜底 3 倍超收:定价数据缺 claude-opus-5 时,matchByModelFamily
  的 Phase 2 关键字兜底会落到 opus-4 系列、getFallbackPricing 会落到
  claude-3-opus,两条路都按 $15/$75 计费(官方 $5/$25),输入输出双双
  3 倍超收且无任何报错。两处补 opus-5 家族并回退到同价的 4.8;判断用
  opus-5/opus5 子串而非裸 "5",避免误伤 claude-opus-4-5。顺带补齐兜底表
  缺失的 claude-opus-4.8(此前同样会掉到 claude-3-opus)。

- Bedrock 版本闸门降级:claudeVersionRe 强制要求 major-minor 两段版本号,
  只有主版本号的 claude-opus-5 / claude-sonnet-5 完全不匹配,被当成旧模型:
  isBedrockOpus47OrNewer 假导致 thinking.enabled 不转 adaptive(Opus 5 上游
  已移除 budget_tokens,透传直接 400)、isBedrockClaude45OrNewer 假导致
  cache_control.ttl 被剥离、bedrockModelSupportsToolSearch 假导致 tool search
  被过滤。改为 minor 可选(缺省 minor=0),claude-sonnet-5 的同一问题一并修复。

Vertex 无需改动:normalizeVertexAnthropicModelID 只处理 -YYYYMMDD→@YYYYMMDD,
无日期后缀的裸 ID 原样透传即正确。context-1m-2025-08-07 白名单不动:Opus 系
上游不接受该 beta,且 Opus 5 的 1M 上下文是默认能力。

Antigravity 暂不接入:无上游支持证据,mapAntigravityModel 对未映射模型返回
空字符串即"该账号不支持",fails closed 安全。

回归测试 internal/service/claude_opus5_test.go 覆盖定价两层兜底、Bedrock
三个闸门、thinking 转换与模型清单;逐个回退上述修复已确认测试会红。
2026-07-25 11:22:42 +08:00
alfadb 5ac4a9fac2 feat(ollama): 支持 Cloud 官方用量自动刷新 2026-07-23 15:50:44 +08:00
Wesley LiddickandGitHub 2c76506e07 Merge pull request #4734 from wjx2951874/feat/alipay-mobile-precreate-deep-link
feat(payment): add mobile Alipay precreate deep link
2026-07-23 14:06:18 +08:00
Wesley LiddickandGitHub aee9ab36cb Merge pull request #4721 from superman2003/fix/ccswitch-grokbuild-4720
fix(frontend): import Grok keys into Grok Build
2026-07-23 11:18:02 +08:00
Wesley LiddickandGitHub 31e7ae8195 Merge pull request #4726 from feitianbubu/fix/model-rate-limit-reset-format
fix(admin): 模型限流恢复时间进位到天并在提示中补全日期
2026-07-23 11:17:54 +08:00
Heatherm Huang ce3272c41b Build composite subscription bucket two 2026-07-23 09:20:52 +08:00
Heatherm Huang a008b63c16 Add composite group route registry 2026-07-23 09:20:18 +08:00
Heatherm Huang c8d1e2e16f Harden composite group product surfaces 2026-07-23 09:19:25 +08:00
Heatherm Huang ebc1028771 Add composite group routing 2026-07-23 09:19:24 +08:00
wjx2951874 7914433011 feat(payment): add mobile Alipay precreate deep link 2026-07-22 19:18:04 +08:00
feitianbubu 48d58d72ff fix(admin): 模型限流恢复时间进位到天并在提示中补全日期 2026-07-22 16:57:51 +08:00
superman2003 a3a1575e9d fix(frontend): import Grok keys into Grok Build 2026-07-22 16:12:47 +08:00
shaw d0bdd7e771 fix(usage): keep significant decimals in cost tooltip rate multiplier
formatMultiplier rounded any value >= 0.01 with toFixed(2), so a
configured multiplier like 0.035 displayed as 0.04x in the /usage and
/admin/usage cost tooltips. Format with up to 4 decimals and trim
trailing zeros while keeping at least 2 decimals; display-only fix,
billing amounts were already computed from the true multiplier.
2026-07-22 14:57:43 +08:00
Wesley LiddickandGitHub ebfaf2496b Merge pull request #4674 from AdrianZhaoDev/main
feat(groups): add OpenAI reasoning policy
2026-07-22 09:37:06 +08:00
Wesley LiddickandGitHub 8e078534c2 Merge pull request #4648 from creamtea47/codex/fix-mobile-account-actions-menu
fix: 修复账号管理移动端更多操作菜单溢出
2026-07-22 09:36:54 +08:00
Wesley LiddickandGitHub ec413f7802 Merge pull request #4709 from Su-cyber-art/agent/fix-ops-mobile-overflow
fix: prevent ops dashboard overflow on mobile
2026-07-22 09:34:53 +08:00
Wesley LiddickandGitHub 30371e64cd Merge pull request #4671 from yan9651688/fix/issue-4551-usage-user-search-race
fix(frontend): ignore stale usage user search responses
2026-07-22 09:34:40 +08:00
Wesley LiddickandGitHub 793f62357f Merge pull request #4700 from feitianbubu/fix/promo-expiry-local-time
fix(promo): 优惠码编辑弹窗过期时间改用本地时间预填
2026-07-22 09:34:27 +08:00
cyber-art a8bfdc6f36 fix ops dashboard mobile overflow 2026-07-22 03:11:19 +08:00
feitianbubu eba7289a8e fix(promo): 优惠码编辑弹窗过期时间改用本地时间预填 2026-07-21 21:38:00 +08:00
feitianbubu 61a80114eb fix(ops): surface backend reason when system log cleanup is rejected 2026-07-21 20:28:01 +08:00
Wesley LiddickandGitHub a978d56c7b Merge pull request #4661 from J606y/fix/mobile-adaptation
fix(mobile): 修复 iOS 页面自动缩放并完善运维监控及全站移动端适配
2026-07-21 14:43:30 +08:00
zhaozewu 6af622c340 feat(groups): add OpenAI reasoning policy
Persist reasoning ceilings and exact mappings for OpenAI groups, enforce them across HTTP and WebSocket forwarding, and invalidate cached auth snapshots.
2026-07-21 11:02:43 +08:00
yan9651688 4696ed7d0b Keep usage user search aligned with the latest query
Debounced requests can finish out of order, allowing an earlier response to replace newer results or repopulate a cleared field. Track a request generation and gate state updates, with deterministic regression coverage.

Constraint: Preserve the existing 300 ms debounce and admin usage API contract
Rejected: Add AbortController plumbing | sequence invalidation matches repository patterns without changing API signatures
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: Keep async filter results gated against superseded queries
Tested: Focused Vitest (4 tests), vue-tsc, ESLint, and full frontend suite except two pre-existing rollback assertion failures
Not-tested: Live browser against production-sized user data
Related: https://github.com/Wei-Shaw/sub2api/issues/4551
2026-07-21 10:52:55 +08:00
Wesley LiddickandGitHub b8b72e1b18 Merge pull request #4666 from TTopoo/redis-username-support
fix(config): support Redis ACL username
2026-07-21 10:43:54 +08:00
Wesley LiddickandGitHub d1dd512bef Merge pull request #4650 from superman2003/fix/plan-validity-unit-display
fix(frontend): 用户侧套餐有效期单位不再把「月/周」显示成「天」
2026-07-21 10:41:16 +08:00
Wesley LiddickandGitHub 0738eadcb5 Merge pull request #4652 from suuuuuu-1/refactor/clean-zh-accounts-redundant-keys
refactor(i18n): 清理 zh/admin/accounts.ts 中重构遗留的冗余 keys
2026-07-21 10:39:46 +08:00
shaw ef3c770d95 fix(deps): 升级 axios 至 1.18.1 修复 GHSA-gcfj-64vw-6mp9 前端安全审计失败 2026-07-21 10:30:41 +08:00
Jingru Shi 49200d4747 fix(config): support Redis ACL username 2026-07-21 01:31:46 +08:00
J606yandClaude Fable 5 442323928d fix(mobile): 运维监控骨架屏固定宽度占位条窄屏溢出
加载骨架屏中 w-80(320px) 占位条在 375px 视口下超出容器,加载期间会把
页面撑宽出横向空白,补 max-w-full 收敛。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 22:14:32 +08:00
J606yandClaude Fable 5 64ab08e4aa fix(mobile): 修复全站排查发现的移动端布局问题
全站排查各页面移动端表现,修复以下确认会溢出/挤压的布局:

- 分组用户倍率/RPM 上限弹窗:7 列宽表滚动容器补横向滚动(min-w-max)
- 设置页联盟自定义用户表:容器 overflow-hidden 改为 overflow-x-auto
- 模型/分组/端点分布、消费排行、用户仪表盘 5 处甜甜圈图例表:
  移动端纵向堆叠(flex-col sm:flex-row),图例表全宽并支持横向滚动
- 安装向导:步骤指示器移动端只显示序号圆点(hidden sm:inline)避免
  硬溢出,表单两列栅格移动端折叠为单列
- 设置页:支付商品名三列、Beta 策略与帮助图片两列输入行移动端折叠
- 分组创建/编辑弹窗:三个 time 输入的三列行移动端折叠(时间控件有
  固有宽度,窄屏弹窗内会硬溢出)
- 密钥页分组选择浮层:min-w-[380px] 改为视口限宽 + JS 夹取 left,
  对齐 AccountGroupsCell 的定位收敛做法

桌面端布局均保持不变。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 22:10:19 +08:00
J606yandClaude Fable 5 0df490961b fix(mobile): 运维监控界面适配移动端
运维监控多处使用裸 table 且无移动端处理,小屏下内容被截断无法查看:

- 系统日志、告警事件、告警规则、OpenAI Token 统计、请求明细五处宽表
  参照 DataTable 的做法,在 < 768px 视口切换为卡片视图(useMediaQuery,
  避免挂载隐藏表格)
- 告警事件工具栏移动端纵向堆叠、筛选器自动换行
- 错误详情弹窗筛选栏 grid-cols-8 改为移动端两列折叠

桌面端布局保持不变;卡片视图完整支持深色模式,告警事件的无限滚动
在卡片视图下同样生效。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 21:58:57 +08:00
J606yandClaude Fable 5 9e072cefec fix(ios): 修复 iOS 端输入框聚焦导致页面自动缩放
iOS Safari 在输入框字号小于 16px 时聚焦会自动放大页面,且失焦后不会恢复,
导致布局错位。启动时仅对 iOS 设备为 viewport 注入 maximum-scale=1 阻止该
行为;iOS 10+ 用户仍可双指手动缩放,Android 不受影响。

- utils/device.ts 新增 detectIOSDevice/isIOSDevice(含 iPadOS 桌面模式识别)
- main.ts 启动阶段执行 initIOSViewportZoomFix
- 补充 detectIOSDevice 单元测试

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 21:58:46 +08:00
suuuuuu-1 3258f7c620 refactor(i18n): 清理 zh/admin/accounts.ts 中重构遗留的 29 个冗余 keys
在 d9e514f98 (2026-07-07) 重构拆分语言包时,部分中文 keys 被错误保留
在 admin/accounts.ts 中。这些 keys 在英文文件中不存在,且代码中无引用。

删除的冗余 keys:
- form 对象(13 个子 keys):nameLabel, platformLabel, typeLabel 等
- filters 对象(6 个子 keys):platform, type, status 等
- 独立 keys(10 个):
  * accountCreatedSuccess, accountUpdatedSuccess, accountDeletedSuccess
  * noAccounts, noAccountsDescription
  * saving, refreshing, testSuccess
  * cookieRefreshedSuccess, failedToSave
  * deleteConfirmMessage, refreshCookie, testAccount
  * api_key, cookie

验证:
- 英文 keys: 1184, 中文 keys: 1184 (修复前: 1220)
- 差异: 0 (修复前: -36)
- 已确认代码中无对 admin.accounts.* 路径的引用
- 正确的翻译在 common.ts 等文件中已存在
2026-07-20 19:11:21 +08:00
superman2003 a6ecc202f0 fix(frontend): 用户侧套餐有效期单位不再把「月/周」显示成「天」
管理端表单保存的有效期单位是复数(days/weeks/months),数据库默认值
与历史数据是单数(day)。用户侧套餐卡片与订单确认面板此前只匹配单数
'month'(以及计费根本不支持的 'year'),管理端存的 'months' 永远落进
默认分支:「1 个月」的套餐被显示成「1天」(#4607),'weeks' 则会把
周数错标成天数。

后端计费 psComputeValidityDays 对 week/weeks、month/months 单复数均
按 ×7/×30 天换算,实扣是对的——这是纯显示缺陷,但直接造成「显示 1 天、
实付 1 个月」的定价误解。

修复:抽出与计费语义一一对应的 planValiditySuffix 辅助函数(单复数
归一化;month→「月/N个月」、week→「N周」、其余含未知单位一律按天,
与后端兜底一致),SubscriptionPlanCard 与 PaymentView 两处共用;
补充 zh/en 的 weeks 文案与单元/组件测试。
2026-07-20 18:40:42 +08:00
NellPoi 53c8ab5b00 fix: 修复账号管理移动端更多操作菜单溢出 2026-07-20 17:18:42 +08:00
shaw fa402b909a feat(branding): 启用新版 SVG logo 并在 README 头部展示
- 新增 assets/logo.svg 作为项目默认 logo(512x512 深色圆角底 + 渐变 S 标)
- 前端 favicon 与组件兜底 logo 由 logo.png 切换为 frontend/public/logo.svg
- 三个 README(EN/CN/JA)头部新增居中 logo 与标题布局
- 删除旧 logo.png 及多余的 lobe 变体 SVG
2026-07-20 16:06:59 +08:00
Wesley LiddickandGitHub 2e5973b165 Merge pull request #4575 from Astrenix/feat/batch-image-guide-i18n
feat(frontend): 批量生图页面完整迁移至 vue-i18n
2026-07-20 15:32:21 +08:00
Wesley LiddickandGitHub ecf199d29d Merge pull request #4573 from Astrenix/fix/dark-palette-slate-consistency
style(frontend): 统一暗色模式表面色板为项目 slate 色系
2026-07-20 15:32:16 +08:00
Wesley LiddickandGitHub 7cbb0d8552 Merge pull request #4629 from yan9651688/fix/issue-4609-plan-currency-symbol
fix(payment): show plan prices with configured currency symbols
2026-07-20 15:32:11 +08:00
Wesley LiddickandGitHub 2ee66c401d Merge pull request #4574 from Astrenix/fix/i18n-hardcoded-strings
fix(frontend): 补齐零星硬编码 UI 文案的国际化
2026-07-20 15:29:05 +08:00
Wesley LiddickandGitHub 3071d41443 Merge pull request #4570 from Astrenix/fix/available-channels-scroll
fix(frontend): 修复可用渠道页面内容过多时无法滚动的问题
2026-07-20 15:29:00 +08:00
Wesley LiddickandGitHub 58ee0c8d75 Merge pull request #4571 from Astrenix/fix/user-balance-modal-dark-text
fix(frontend): 修复余额弹窗暗色模式下用户邮箱不可读
2026-07-20 15:28:56 +08:00
shaw a90c18cbea Merge branch 'main' into fix/issues-4561-4562-4566-4582
Resolve const-block conflict in openai_gateway_grok_cache.go:
keep #4590's client tool cache constants, drop grokFreeRolling24hTokenLimit
(moved to pkg/xai as IsGrokFreeRolling24hTokenLimit with legacy 2M support).
2026-07-20 11:25:11 +08:00
Wesley LiddickandGitHub 6d152893ff Merge pull request #4590 from superman2003/fix/grok-client-cache-codex-trae
fix(grok): cache client tools from Codex, Trae, and Claude Desktop
2026-07-20 10:47:05 +08:00
yan9651688 a05b873215 fix(payment): prevent configured currencies from looking like USD
Subscription plans can carry a display-only ISO currency code, but the admin plan table and user plan cards still used a hard-coded dollar sign. Resolve the symbol through the shared currency helper while retaining existing number formatting, the currency code label, and legacy blank-currency behavior.

Constraint: Plans without a currency must keep the legacy USD display

Rejected: Reformat complete prices with Intl.NumberFormat | it would change existing decimals and remove the explicit currency code

Confidence: high

Scope-risk: narrow

Reversibility: clean

Directive: Keep plan currency symbols aligned across admin and user displays

Tested: targeted Vitest 4 tests; targeted ESLint; vue-tsc; Vite production build; full Vitest 1222 tests passed

Not-tested: Full Vitest has 2 unrelated upstream failures in admin.system.rollback.spec.ts

Related: https://github.com/Wei-Shaw/sub2api/issues/4609
2026-07-20 10:33:04 +08:00
Wesley LiddickandGitHub 8c9cda1803 Merge pull request #4583 from BenjaminAaron196/codex/ops-report-email-template
(feat) 运维定时报表支持可编辑摘要模板与多语言展示
2026-07-20 10:28:44 +08:00
Wesley LiddickandGitHub 34c8dbd604 Merge pull request #4618 from superman2003/fix/system-update-detach-request-ctx
fix(update): detach in-place update from the HTTP request lifetime
2026-07-20 10:26:47 +08:00