IanShaw027
ff4bb3bd2c
fix(grok): 修复授权文案的i18n占位符
2026-08-07 14:18:06 +08:00
IanShaw027
d0930c4bdb
fix(grok): 完善密码与SSO授权能力控制
2026-08-07 14:13:07 +08:00
IanShaw027
2413441b5f
feat(grok): P2 模型额度软封、spending reauth、粘连分轨与观测模型
...
- free-usage 带模型名时按账号+模型软封,其它模型仍可调度
- spending-limit 使用 24h 冷却并标记 needs_reauth(extra + SetError)
- sticky affinity 与 upstream prompt_cache_key 分轨,按 model 隔离粘连
- free-usage recovery 轻量提示窗口;配额查询后异步同步 /v1/models 快照
2026-08-07 14:06:21 +08:00
IanShaw027
cda6de44da
fix(grok): 运行时映射设置即时失效账号缓存
2026-08-07 13:59:32 +08:00
IanShaw027
ec9e733606
feat(grok): stream idle 换号、team+model 冷却与 RT 刷新打散
...
- Grok 流默认启用上游读空闲超时,首包前返回可 failover 错误并短冷却
- 同 team_id 账号在 429/free-usage 后对同模型共享进程内冷却,粘连与选号均过滤
- TokenRefreshService 已覆盖 Grok;NeedsRefresh 增加按账号稳定 jitter 防 stampede
2026-08-07 13:56:38 +08:00
IanShaw027
dfca6246eb
refactor(grok): 将视频模型价纳入 Ent 持久化
2026-08-07 13:55:58 +08:00
IanShaw027
e12e0dc1a6
feat(grok): 对齐 free-usage/empty 失败分类与 sticky/ReAuth 体验
...
从 grokcli 吸收 body-first 失败分类(free-usage/empty/billing),
接到现有 temp_unsched 与 failover,保留 content-policy 与 pool_mode。
Grok 粘连/缓存在无显式 session 时可用 previous_response_id;
ReAuth 预填 email---- 并默认密码 tab(密码不落库)。
2026-08-07 13:47:09 +08:00
IanShaw027
9bc99e8b6e
fix(grok): 防止加权粘连回退绕过免费额度门禁
2026-08-07 13:44:56 +08:00
IanShaw027
e9aaa325fa
fix(grok): 让跨客户端消息映射服从配置开关
2026-08-07 13:43:02 +08:00
IanShaw027
43391de925
fix(grok): 打通按模型视频价格计费链路
2026-08-07 13:41:34 +08:00
IanShaw027
8989d25ed5
docs(grok): 记录 ReAuth 密码/SSO 入口
2026-08-07 13:23:03 +08:00
IanShaw027
91f5b00679
feat(grok): ReAuth 弹窗支持 SSO、密码与 RT 重新授权
...
管理端重新授权对 Grok 展示 SSO Cookie、邮箱密码与 RT 入口;
校验成功后对现有账号 applyOAuthCredentials,不走批量建号。
密码/SSO 仅用于授权 API,经 buildCredentials 写入 OAuth 凭据。
2026-08-07 13:23:03 +08:00
IanShaw027
48fc076ce1
docs(grok): 记录创建账号密码登录 UI 接入
2026-08-07 13:18:59 +08:00
IanShaw027
9b7ea3aabf
feat(grok): 创建账号流程接入邮箱密码登录
...
在 OAuth 授权流中增加 email----password 入口,CreateAccount 批量调用
authorizePassword 后经 buildCredentials 建号;密码与 raw SSO 不落库。
SSO Cookie 批量导入路径保持不变。
2026-08-07 13:18:59 +08:00
IanShaw027
be925d9a42
docs(grok): 更新完整整合进度(阶段 4–6)
2026-08-07 13:08:23 +08:00
IanShaw027
0a28c99aae
feat(grok): 管理端补齐 SSO/密码授权前端入口
...
新增 sso-token 与 password API 封装及 composable 方法;buildCredentials
丢弃 sso/password 字段且不再强行固定 base_url,交由系统 CLI/API 模式选择主机。
2026-08-07 13:08:22 +08:00
IanShaw027
451abc3aa5
feat(grok): 加固媒体计费门控并补齐分组按模型价输入
...
生成类媒体仅在存在真实 image/video 计费单元时写 usage,避免空结果误扣费。
Create/Update 分组输入支持 video_model_prices,与仓储 JSONB 字段打通。
本阶段不引入假 voice 路由(上游音频路径依赖更广协议层)。
2026-08-07 13:08:22 +08:00
IanShaw027
ba58e74b33
feat(grok): free 档本地用量软门禁与支付失败临时下线
...
对明确 free 的 OAuth 账号在调度路径应用可配置用量窗口门禁(统计失败 fail-open)。
402 payment required / 消费上限类 403 继续临时移出调度,管理端探测不走门禁。
2026-08-07 13:04:05 +08:00
IanShaw027
eb6c9663e7
feat(grok): 视频按模型族配置每秒单价,并补齐管理端映射设置
...
分组新增 video_model_prices(JSONB);计费优先模型×分辨率覆盖,
其次旧分辨率三列,最后官方按模型族默认价。同步补齐 admin 设置
中的 grok_default_text_model / 跨客户端映射开关,并保持
grok-imagine-video-1.5 请求模型 identity 不被静默改写。
2026-08-07 12:44:08 +08:00
IanShaw027
370bdcf695
feat(grok): 补齐密码登录与 SSO 校验,统一 OAuth 凭证形态
...
在 main 既有 SSO→Build 批量导入之上增加 sso-token 校验与账号密码授权。
密码仅用于换取 SSO 再转 Build OAuth,明文与 raw SSO 均不落库。
2026-08-07 12:38:49 +08:00
IanShaw027
74249b8fed
feat(grok): 模型目录与可配置映射,默认禁止跨厂商暗默改写
...
补齐 Grok/Imagine 官方模型与别名,并支持运行时默认文本模型。
默认 model_mapping 仅含 Grok 家族;新增 grok_default_text_model 与
grok_cross_client_model_map_enabled,仅在显式开启时将 gpt/claude/codex
等客户端模型名映射到默认文本模型,避免非 Grok 请求被静默改成 grok-4.5。
2026-08-07 12:31:14 +08:00
Wesley Liddick and GitHub
93367b6db4
Merge pull request #5351 from Wei-Shaw/fix/codex-tui-default-identity
...
fix(openai): default OAuth identity to codex-tui
2026-08-07 10:17:00 +08:00
shaw
b6e53c9320
fix(frontend): align Codex UA setting copy
2026-08-07 10:06:28 +08:00
shaw
dbb42881c0
fix(openai): default OAuth identity to codex-tui
2026-08-07 09:56:03 +08:00
Wesley Liddick and GitHub
e4b0e1b66b
Merge pull request #5338 from Wei-Shaw/fix/tencent-captcha-region-csp
...
修复腾讯验证码区域适配、重置与 CSP 加载
2026-08-07 08:37:50 +08:00
shaw
287a9f386b
fix: 修复腾讯验证码票据过期与区域切换
2026-08-06 21:27:06 +08:00
shaw
8e102b3a0f
fix: 完善腾讯验证码区域适配与 CSP 白名单
...
修复国内站和国际站 SDK 构造、验证容器、票据重置及动态资源加载问题,并补充认证流程回归测试。
2026-08-06 20:34:37 +08:00
shaw
a19c9f8d8a
chore: update sponsors
2026-08-06 19:31:17 +08:00
shaw
a1936d42db
chore: update sponsors
2026-08-06 19:30:44 +08:00
shaw
c123caddd4
chore: update sponsors
2026-08-06 14:22:46 +08:00
Wesley Liddick and GitHub
e08aee49ed
Merge pull request #5266 from shentry/fix/transient-streak-rate-dependence
...
fix(openai): keep transient failure streak from resetting on sparse traffic
2026-08-06 14:11:49 +08:00
Wesley Liddick and GitHub
c9e60d1f26
Merge pull request #5031 from keaipiao/fix/easypay-error-utf8
...
fix(payment): preserve UTF-8 in EasyPay errors
2026-08-06 14:10:41 +08:00
Wesley Liddick and GitHub
47c03c75d8
Merge pull request #5232 from fengshao1227/fix/billing-quantize-monetary-scale
...
fix(billing): quantize usage billing amounts to the NUMERIC(20,8) scale
2026-08-06 14:00:04 +08:00
shaw
00b8596176
chore: update sponsors
2026-08-04 21:55:34 +08:00
shaw
c5e046b7d7
chore: update sponsors
2026-08-04 21:54:50 +08:00
github-actions[bot]
aac53afe0e
chore: sync VERSION to 0.1.171 [skip ci]
2026-08-04 13:41:47 +00:00
Wesley Liddick and GitHub
f0e7a9c7a2
Merge pull request #5223 from feeeei/main
...
feat(aliyun-captcha): 人机验证增加阿里云验证码 2.0
2026-08-04 21:16:43 +08:00
feeeei
26e0a89323
人机验证增加阿里云验证码 2.0
...
沿用腾讯天御验证码引入的多服务商模型:aliyun_captcha_enabled 作为独立
开关,与 Cloudflare Turnstile、腾讯天御三方互斥(保存校验 + 运行时
CAPTCHA_PROVIDER_CONFLICT)。后台「安全与认证」合并为单张人机验证卡片:
总开关 + 服务商单选(Turnstile / 腾讯天御 / 阿里云),选中即启用该家并
关闭其它,落库仍是三个独立开关键,由前端映射保证互斥。
阿里云侧同时支持 aliyun 中国站与国际站(alibabacloud.com):两站前端脚本、
region 取值与服务端 API 完全一致,仅账号与 AccessKey 相互独立,因此由
「服务地域」决定线路即可——中国内地走 captcha.cn-shanghai.aliyuncs.com,
非中国内地(新加坡)走 captcha.ap-southeast-1.aliyuncs.com,AccessKey
取自持有该实例的账号,无需在配置中区分站点。
- AliyunCaptchaService 对称 TencentCaptchaService:服务端校验走官方 SDK
VerifyIntelligentCaptcha,调用异常按 fail-closed 拦截,与 Turnstile
网络错误行为对称;保存设置时真实探测 AK/SK 有效性
- 保护面对齐腾讯扩展入口:VerifyTencentCaptchaIfEnabled 通用化为
VerifyActionCaptchaIfEnabled,OAuth 登录启动、passkey 登录在阿里云
启用时同样拦截;Turnstile 维持既有覆盖不扩大
- 前端 AliyunCaptchaWidget 为表单内预验证按钮(popup 模式),同时暴露
verify() 供 OAuth 启动、passkey 等动作入口程序化弹窗;未预验证直接
提交时弹窗兜底。SDK 按钮绑定异步完成,弹窗未出现前按 tick 重试触发,
并轮询弹窗可见性识别用户关闭
- captchaVerifyParam 复用 turnstile_token 请求字段提交;公开设置下发
aliyun_captcha_enabled / scene_id / prefix / region
- CSP 放行验证码 CDN:script-src/style-src 加 *.alicdn.com
2026-08-04 20:57:15 +08:00
Wesley Liddick and GitHub
d431c57f2e
Merge pull request #5268 from Wei-Shaw/fix/pending-oauth-captcha-submit-gate
...
fix(auth-ui): 第三方 OAuth 建号提交前必须持有验证码票据
2026-08-04 20:43:01 +08:00
shaw
635a27189f
fix(auth-ui): gate pending OAuth account creation on a captcha proof
...
#5261 added a captcha check to POST /auth/oauth/pending/create-account, but
the shared create-account form only gates its send-code button on the
Turnstile token — the submit button's disabled condition never included it.
Turnstile tokens are single-use, so handleSendCode resets the widget in its
finally block and clears the token. Submitting inside the window before the
widget re-solves omits turnstile_token from the payload, and the backend
answers ErrTurnstileVerificationFailed (turnstile_service.go:65). With an
interaction-required challenge the widget does not re-solve on its own, so
the failure persists until the user notices and verifies again — while the
button stays enabled and says nothing.
Gate the submit button on the token, mirroring the send-code button and
EmailVerifyView, which already gates its pending-OAuth submit the same way.
handleSubmit repeats the check because implicit form submission (Enter in a
text input) bypasses the button's disabled state.
The Tencent path is unaffected: handleSubmit already acquires a fresh proof
per submit, and turnstile_enabled is false in that configuration.
Verified with the component spec (11 passed) and vue-tsc --noEmit (clean).
2026-08-04 20:29:53 +08:00
shentry and Claude Opus 5
7d38e67120
fix(openai): keep transient failure streak from resetting on sparse traffic
...
The account+model transient breaker reset its failure streak whenever the
gap since the previous failure exceeded a one-minute window. That made the
breaker's sensitivity a function of request rate rather than upstream
health: a gateway called less often than once a minute never advanced past
streak 1, where the cooldown is zero, so a consistently broken account was
never blocked. Every request re-selected it, paid a full upstream attempt,
and only then failed over to a healthy account.
Observed on a low-traffic deployment: two accounts returning 500 and 503
stayed in rotation indefinitely, logging `failure_streak: 1, cooldown_ms: 0`
on every request and adding ~750ms to each one before a working account was
reached.
The streak is already cleared on success — recordSuccess deletes the entry,
and every OpenAI handler reports the schedule result — so the time-based
reset is not needed to recover a healthy account. Keep a TTL purely to bound
the map for account+model pairs that stopped being used, and raise it well
above the cooldowns so it no longer doubles as a streak reset.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-04 17:59:16 +08:00
Wesley Liddick and GitHub
8b3fe664dc
Merge pull request #5261 from lyen1688/feat/tencent-captcha-gate
...
新增腾讯天御验证码认证门禁
2026-08-04 16:39:55 +08:00
Wesley Liddick and GitHub
a4d263f62f
Merge pull request #5224 from wucm667/fix/issue-5190-lock-subscription-renewal
...
fix(subscription): serialize concurrent renewals
2026-08-04 16:28:52 +08:00
Wesley Liddick and GitHub
ae81dfd933
Merge pull request #5177 from r266-tech/fix-nonpassthrough-write-context
...
fix(openai-ws): preserve terminal event on lease loss
2026-08-04 16:28:22 +08:00
Wesley Liddick and GitHub
35cab3c814
Merge pull request #5258 from feeeei/fix/model_plaza
...
fix(model-plaza): Model Plaza image model price display is inconsistent with the actual price
2026-08-04 16:27:53 +08:00
Wesley Liddick and GitHub
770e35b474
Merge pull request #5040 from coo1white/upstream-pr/grok-cli-0.2.114
...
fix(grok): bump pinned Grok CLI version to 0.2.114
2026-08-04 16:16:20 +08:00
Wesley Liddick and GitHub
846dd310a3
Merge pull request #5158 from neboyang/feat/claude-oauth-authorize-url
...
fix(oauth): use claude.com/cai authorize endpoint
2026-08-04 16:15:50 +08:00
Wesley Liddick and GitHub
9b4575e434
Merge pull request #5243 from wucm667/feat/issue-5240-dashboard-username
...
fix(dashboard): show usernames in spending ranking
2026-08-04 16:15:21 +08:00
Wesley Liddick and GitHub
1f4cfc44c1
Merge pull request #5226 from spongehah/codex/fix-prompt-audit-output-text
...
fix(prompt-audit): parse responses output text
2026-08-04 16:15:04 +08:00
lyen1688
e592c5f9e0
新增腾讯天御验证码认证门禁
2026-08-04 15:09:29 +08:00