The local go.mod replace directive for go-sora2api pointed to a Windows
path which breaks CI on Linux. Revert sora.NewWebClient back to sora.New
since the remote module doesn't have this method yet.
- Backend: detect and classify 403 responses (validation/violation/forbidden)
- Backend: extract verification/appeal URLs from 403 response body
- Frontend: display forbidden status badges with color coding
- Frontend: show clickable/copyable verification links
- Also includes: sora SDK client rename, table header style fix, tier badge in accounts list
chore: bump version to 0.1.93.23
P0 fixes:
- StorageType: UploadFromURL now returns actual storageType, fixing
GDrive tasks being incorrectly recorded as "s3"
- Concurrency: selectAccount returns ReleaseFunc to caller, fixing
premature slot release before task creation
- Race condition: applyRecoveredToken uses copy-on-write for
account.Credentials map to prevent concurrent write panic
- GetCameoStatus: use direct HTTP call to populate missing fields
(StatusMessage, InstructionSetHint, InstructionSet)
- Frontend: progress bar uses reactive now.value instead of
non-reactive Date.now()
P1 fixes:
- EditImage: pass req.Image through to CreateImageRequest
- ListPending: add LIMIT 200 to prevent unbounded queries
- Worker encapsulation: add ListPendingTasks/UpdateTask proxy methods
to SoraTaskService, worker no longer accesses repo directly
- Frontend polling: add retry counter (3 attempts) before giving up
P2-P3 fixes:
- QuotaBar: handle both quota_source and source field names
- i18n: replace hardcoded Chinese labels in SoraPromptBar and
example prompts in SoraGeneratePage with i18n keys
- Fix regenrate → regenerate i18n typo
- SoraMediaPreview: skip Escape handler when not visible
- SoraGeneratePage: void handleGenerate promise in handleRetry
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- selectAccountByID: use original task's account for remix instead of
random selection, preventing permission issues in OAuth path
- Upstream error passthrough: forward HTTP status code and body from
upstream instead of always returning 500
- Add accountRepo to SoraTaskService for direct account lookup
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add ClearAccountAffinity to mockGatewayCacheForPlatform,
openAIWSStateStoreTimeoutProbeCache, mockGatewayCacheForGemini
- Add allow_messages_dispatch field to groups/available contract test
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Windows terminals may send request bodies in GBK encoding, causing
garbled prompts and upstream failures. Validate UTF-8 encoding in
readBody and return 400 for invalid encodings.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
pq driver treats []byte as bytea, not jsonb. Convert charJSON and
reqBody to *string before passing to ExecContext for character_info
and request_body JSONB columns.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add async task management for Sora video/image generation with two
forwarding modes: OAuth (SDK) and API Key (HTTP upstream). Includes
background worker for status polling and 3-layer storage degradation
(S3 > local disk > upstream URL passthrough).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
classifyByAffinityZone was running before filterByMinPriority, causing
high-priority accounts in the red zone to be removed before priority
filtering, allowing low-priority accounts in the green zone to be
selected instead. Move zone classification into the priority loop so
it operates within same-priority groups, with fallback to next priority
group when current group is entirely in the red zone.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Backend: Add AffinityZone type with GetAffinityBase/GetAffinityBuffer/GetAffinityZone
methods. Integrate classifyByAffinityZone into Layer 2 scheduling and red zone
check into Layer 1.6 affinity hit path. 17 unit tests covering all zone boundaries.
Frontend: Add AffinityConfigCard for base/buffer configuration in EditAccountModal.
Move affinity badge from status column to capacity column with zone-based coloring
(count/limit format). Extract CapacityBadge and QuotaBadge components to reduce
AccountCapacityCell from 444 to 215 lines.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Anthropic OAuth/setup-token accounts are throttled by actual proxy
connection (host:port:username). Other platforms bypass the queue
entirely. Also adds unit tests for affinity and usage queue features.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- New API: GET /accounts/:id/affinity-clients returns client list with
last_active timestamps from Redis ZSET scores
- New Lua script: get_affinity_clients_with_scores.lua uses ZREVRANGEBYSCORE
WITHSCORES to return both client IDs and their timestamps
- New frontend component: AffinityBadge.vue replaces inline badge with
hover popover that lazy-loads client details on first hover
- Shows client ID (monospace) + relative time (e.g. "3h ago")
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Pipeline mode only sends EVALSHA (no automatic fallback to EVAL).
If Redis restarts and script cache is lost, all pipeline Lua calls
silently fail with NOSCRIPT. Add ensureScriptLoaded() to pre-load
scripts before pipeline execution.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Previously the count was only returned when Redis had data, causing
the badge to not display for accounts with zero affinity clients.
Now returns count=0 for all affinity-enabled accounts.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add missing CountByStorageType method to stubSoraGenRepo test mock
- Suppress SA1019 for WithCredentialsJSON (admin-controlled source)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix struct tag alignment in dto/types.go (AffinityClientCount)
- Fix struct literal alignment in sora_generation_service.go
- Replace deprecated google.CredentialsFromJSONWithParams with
option.WithCredentialsJSON for service account auth (SA1019)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix struct field alignment in dto/types.go, settings_view.go,
sora_generation_service.go for gofmt compliance
- Remove embedded field "Account" from selector in account_handler.go (QF1008)
- Remove unused settingService field from SoraGDriveOAuthService
- Replace deprecated google.CredentialsFromJSON with CredentialsFromJSONWithParams (SA1019)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add colored circle badge showing affinity client count before the account
status indicator. Badge color reflects count severity (gray=0, green=1-5,
yellow=6-15, red=16+). Tooltip shows full client ID list on hover.
Backend: AccountHandler batch queries reverse affinity index via
GetAccountAffinityClientsBatch, returns affinity_client_count and
affinity_clients in DTO. GatewayCache interface extended with the new
batch method backed by a Lua script (get_affinity_clients.lua).
All test mocks synchronized with updated GatewayCache interface.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Remove RemoveClientAffinity from GatewayCache interface, implementation,
Lua script, and all test mocks (never called in production code)
- Add 26 unit tests for affinity scheduling: filterByMinAffinityCount,
populateAffinityCounts, Layer 1/2 sort chain integration
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Separate clientAffinityTTL (24h) from stickySessionTTL (1h)
- Atomic Lua dual-write for forward (client→accounts) and reverse
(account→clients) affinity indexes with lazy expiry cleanup
- Extract Lua scripts to standalone .lua files with //go:embed
- Add filterByMinAffinityCount to Layer 1 & 2 scheduling so new
clients are routed to accounts with fewest existing affinities
- Skip Redis query when no affinity-enabled accounts exist (zero
overhead for non-affinity users)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix gofmt: align struct field comments in UsageCache, trim trailing
whitespace on const comments
- Fix errcheck: use comma-ok on type assertion for singleflight result
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Prevents 429 rate-limit retry storms and reduces upstream correlation risk
for Anthropic usage API queries.
Three changes:
1. Negative caching (1 min TTL) — 429/error responses are now cached,
preventing every subsequent page load from re-triggering failed API calls.
2. singleflight dedup — concurrent requests for the same account are
collapsed into a single upstream call, preventing cache stampede.
3. Random jitter (0–800 ms) — staggers multi-account cache-miss bursts so
requests from different accounts don't hit upstream simultaneously with
identical TLS fingerprints, reducing anti-abuse correlation risk.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add quota_daily_limit/used and quota_weekly_limit/used to DTO and
frontend Account type
- AccountCapacityCell shows D (daily), W (weekly), and $ (total) badges
with color-coded status (green/yellow/red)
- AccountActionMenu shows reset button when any quota dimension is set
- Extract quotaBadgeClass/quotaBadgeTooltip as shared functions
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Split compound "Profile" column into separate Profile ID and Name columns
- Replace "Endpoint" column with "Storage Path" showing bucket/prefix or folder info
- Add GDrive quota display (capacity/used) via new backend API endpoint
- Add video count statistics per storage type via new backend API endpoint
- Add inline test button per profile with 15s timeout and per-profile loading state
- Backend: GetQuotaInfo, CountByStorageType, GetGDriveQuota, GetStorageVideoStats
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace single-period-selector (三选一) with three independently configurable
quota dimensions (日/周/总) that can all be set simultaneously. Account is
paused when ANY dimension is exceeded. Periodic quotas (daily/weekly) use
lazy reset via atomic SQL — no cron job needed.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>