Wesley Liddick
9ba0fb3084
Merge pull request #3775 from heathermhuang/codex/grok-media-pricing-labels
...
fix: add Grok video pricing controls
2026-07-09 15:03:38 +08:00
li
bfb827b879
fix(security): HTML-escape site_name 并对 doc_url 统一应用 sanitizeUrl
...
Refs #3839 (第 8、12 点)
2026-07-09 10:03:49 +08:00
Heatherm Huang
4d702e3234
fix: split Grok image and video pricing
2026-07-08 13:50:49 +08:00
Wesley Liddick
6f43986c37
Merge pull request #3811 from jianjianai/hotfix/admin-scheduler-score-opt-in
...
fix(admin): 管理员账号列表默认关闭调度权值计算以降低负载
2026-07-08 10:22:10 +08:00
shaw
bb5d2e84a1
refactor(handler): 纯移动拆分 setting_handler.go(3957→468行)
2026-07-08 08:49:22 +08:00
jjaw
6ae5fc31b3
fix(admin): gate scheduler score calculation
2026-07-08 06:58:35 +08:00
Turtle_Li
1b07fe821a
merge: sync batch image branch with origin main
2026-07-07 03:27:11 +08:00
shaw
d56e94b875
feat(payment): 订阅 CNY 换算改为独立汇率配置的显式 opt-in
...
- 新增 SUBSCRIPTION_USD_TO_CNY_RATE 配置(1 USD = X CNY,默认 0=关闭),
替代复用 balance_recharge_multiplier 的隐式换算,促销倍率与订阅定价解耦
- 未配置汇率时订阅保持 price 直付的存量行为,存量部署升级零影响
- 前端确认页/原价/手续费/方式限额与后端换算条件严格镜像(rate>0 且币种为 CNY)
- 管理后台新增汇率配置输入(zh/en 文案),checkout-info 透出 subscription_usd_to_cny_rate
- 单测锁定:汇率未配置时不换算、换算使用汇率而非余额倍率、余额订单不受影响、返利仍按 USD price
2026-07-06 14:34:17 +08:00
Turtle_Li
9703ca9d33
merge: sync batch image foundation with upstream main
2026-07-06 13:40:09 +08:00
Turtle_Li
8fab636998
feat: complete batch image workflow
2026-07-06 12:22:04 +08:00
shaw
0fd2e9216d
fix(scheduler): 修复 OpenAI 高级调度器审计发现的正确性与性能问题
...
针对 #3692 合并后审计发现的问题集中修复:
- previous_response_id 剥离条件改为按 call_id 全覆盖校验,
部分可重建的工具续链不再被误剥离(不受开关门控的行为回归)
- 粘性加权回退路径补分组归属校验并清理失效绑定,杜绝跨分组账号泄漏
- 账号列表页:无 OpenAI 账号时跳过分数计算、过滤池限定 openai 平台、
负载批查合并为账号并集一次查询,消除全表扫描与 Redis N+1
- 订阅优先模式下常规池不可用时回退订阅池等待计划,
busy-but-waitable 的订阅账号不再导致请求硬失败
- TopK/权重 DB 覆盖显式受总开关门控,与兄弟子开关语义一致
- 前端未分组 OpenAI 账号回退展示基础分,不再显示 "-"
- ListAllWithFilters 等能力正式进入 AccountRepository/AdminService 接口,
移除匿名接口断言与静默降级;负载批查失败补 warn 日志
- SelectAccountWithSchedulerForCapability 增加显式 previousResponseCanMove
参数,移除 "previous_response_can_move" 魔法字符串哨兵
- 设置写入路径补"基础权重不得全为零"聚合校验;
运行时设置批量读取失败的降级路径覆盖全部键并留痕
2026-07-06 11:43:16 +08:00
linshuboy
f26ca5661e
feat: add OpenAI advanced scheduler controls
...
Related: #1089 , #408 , #123
2026-07-05 17:24:38 +08:00
Wesley Liddick
707b87a96f
Merge pull request #3676 from wucm667/fix/codex-import-refresh-token-missing-collision
...
fix(admin): Codex Session 导入 refresh_token 缺失时不再合并同 workspace 不同账号
2026-07-04 10:29:47 +08:00
wucm667
6bd248fd1f
fix(admin): avoid merging Codex access-only imports
2026-07-04 09:53:01 +08:00
DaydreamCoding
ebbdc70311
feat(usage): 错误请求对齐用量明细(UI/排序/筛选/列设置)
...
错误请求列表(/admin/usage 错误 tab、Ops 弹窗、用户端 /usage 错误 tab)
对齐用量明细的交互与信息密度。Squash of:
- feat(usage): 错误请求全面对齐用量明细(UI/列序/排序/筛选/列设置/新列)
- refactor(usage): 错误表提取共享徽章工具与 IP 批量工具条,后端排序解析归并 SetSort
- feat(usage): /admin/usage 错误请求新增分类过滤
- fix(ops): 错误列表 phase=upstream 过滤生效,守卫豁免改为显式 opt-in
- fix(ops): 错误列表用户列回退显示已删除 KEY 所有者
- fix(usage): 错误请求状态码排序对齐展示/过滤,筛选项改固定常用码
2026-07-03 23:02:27 +08:00
Wesley Liddick
87dfc66132
Merge pull request #3659 from jianjianai/fix/ops-realtime-stats-performance
...
fix: 优化运维实时账号统计接口性能
2026-07-03 10:45:24 +08:00
shaw
a5638a4e54
fix: match Codex session imports by chatgpt_user_id before shared account id
...
Members of the same ChatGPT team share chatgpt_account_id, so matching
imports by the account key first could overwrite another member's
account credentials. Identity keys are now ordered by strength
(user > email > access > account), and an account-key hit is rejected
when both sides carry different chatgpt_user_id values.
- Keep the account-key fallback when either side lacks a user id, so
legacy accounts without chatgpt_user_id are updated and backfilled
instead of duplicated
- Index all candidate accounts per shared key so a teammate's row can
no longer shadow a legacy account depending on row order
- Apply the same conflict check to in-batch dedup and emit a warning
when a legacy account is claimed via the shared account key
- Scope a 120s timeout to the Codex session import request instead of
raising the global client timeout
2026-07-03 10:13:51 +08:00
jianjian
3f2ef60468
fix: optimize ops realtime account stats
2026-07-02 20:04:47 +00:00
Wesley Liddick
821399ade1
Merge pull request #3622 from deqiying/feat/subscription-revoke-restore
...
支持恢复已撤销订阅
2026-07-02 17:34:20 +08:00
shaw
11a3da65c0
fix(group): harden peak-rate config handling and label peak windows with server timezone
...
Follow-up fixes to #3569 based on code audit:
- Expose server_timezone / server_utc_offset in public settings (and the
__APP_CONFIG__ injection payload) and label every peak-window display
with the server UTC offset, so users don't misread the billing window
as browser-local time
- Unify CreateGroup/UpdateGroup peak-config sanitization via a single
NormalizePeakRateConfig chokepoint: non-subscription groups always get
peak fields cleared; unparseable window strings and negative
multipliers are scrubbed when peak is disabled
- Replace hot-path time.Parse in PeakMultiplierAt with a manual HH:MM
parser (accept set verified byte-for-byte identical to
time.Parse("15:04") by exhaustive fuzzing) and reuse it in validation
- Revert the zero-behavior CalculateCost indirection churn in
billing_service/gateway_service introduced by #3569
- Remove dead GetGroupPlatformMap and the duplicate deref helper in the
admin handler package
- Share frontend peak formatting via utils/peak-rate.ts, unify the ×N
label format, and move hardcoded Chinese tooltips to i18n keys
2026-07-02 16:11:07 +08:00
deqiying
b26dcc3da2
feat(subscription): 支持恢复已撤销订阅
2026-07-01 22:19:21 +08:00
xueshiji
5e99561d6e
Merge branch 'Wei-Shaw:main' into main
2026-07-01 17:48:42 +08:00
Wesley Liddick
0a9146c3d1
Merge pull request #3586 from deqiying/codex/fix-subscription-revoke-soft-delete
...
修复订阅撤销操作实际上是软删除的bug
2026-07-01 15:38:45 +08:00
Wesley Liddick
3812e627a8
Merge pull request #3546 from nslogx/fix/platform-quota-five-platforms
...
fix: allow five platform quota updates
2026-07-01 14:07:08 +08:00
xueshiji
8b46994dc2
Merge branch 'Wei-Shaw:main' into main
2026-07-01 14:01:03 +08:00
xueshiji
5e9529bb88
Merge branch 'Wei-Shaw:main' into main
2026-07-01 14:00:51 +08:00
DaydreamCoding and Claude Sonnet 5
bdf7ead157
feat(spark-shadow): OpenAI Spark 链接型影子账号
...
背景:gpt-5.3-codex-spark 使用独立于 codex 全局(5h/7d)的配额窗口(数据源是
/wham/usage 响应体的 codex_bengalfox,而非 codex 全局用的 x-codex-* 响应头),且
只能挂在已完成 OAuth 授权的 OpenAI 账号下复用其登录态,不能作为独立账号单独接入。
为此新增“链接型影子账号”(spark shadow account):影子账号本身不持有任何凭据,
通过 parent_account_id 指向母账号,凭据/token/代理透传自母账号并共享母账号的刷新
周期,仅在配额维度(quota_dimension=spark)和用量窗口上与母账号完全独立调度、互不
连坐。
实现:
- 数据模型:migration 154(+154a)给 accounts 表加 parent_account_id /
quota_dimension 列 + 4 条约束(维度合法 / parent⟺非 global 维度一致 / 禁自指 /
FK)+ 2 个 CONCURRENTLY 索引(母账号索引 + 每母账号至多一个影子的唯一索引)。
- 创建:POST /api/v1/admin/accounts/:id/shadow(CreateShadow)—— 一母一影(唯一
索引兜底并发竞态),继承母账号 proxy/分组/并发/优先级(显式传参可覆盖),默认
model_mapping 恒等映射到 spark(拒绝非 spark 模型),母账号必须是真实的 OpenAI
OAuth 账号(非影子)。
- 凭据透传:resolveCredentialAccount 把影子解析回母账号,GetAccessToken / 请求头
/ WS 三条路径统一走此函数;影子自身 Credentials 恒为空(仅允许写 model_mapping),
凭据写入的汇聚点 persistAccountCredentials 对影子早返 no-op,防止误写。
- 调度:parentHealthyForShadow 只看母账号是否仍是 OpenAI OAuth + 凭据/传输是否
可用(active、token 未过期、未处于 401/刷新失败/传输故障导致的临时不可调度冷却),
刻意不看母账号的 global 限流窗口——两条 429 道互不连坐。
- 用量:影子的 codex_5h/7d 走 OpenAIQuotaService.QueryUsage(/wham/usage 的
codex_bengalfox),与母账号走的 WSv2 探测(/responses 头)完全独立的数据源、
刷新节流与 staleness 判定。
- 备份:ExportData 显式排除影子账号(影子不持凭据,通用凭据型导入强制
credentials 非空、无法表达父子链接),按 skipped_shadows 计数提示前端。
- 前端:账号操作菜单新增“创建 Spark 影子”入口,影子行展示回填的母账号信息
(邮箱 / plan / 隐私模式 / 订阅到期 / chatgpt_account_id),批量操作自动跳过
影子账号。
说明:migrations 目录用完整文件名(而非纯数字前缀)标识迁移,故本次新增的
154_account_spark_shadow.sql / 154a_..._notx.sql 与已有的
154_add_ops_system_logs_api_key_id.sql 按序号共存,与目录里 145/151 已有的
先例一致。
测试:新增约 20 个测试文件,覆盖 handler(CreateShadow 校验 / 母账号信息回填)、
repository(影子 round-trip / 一母一影唯一索引 / 迁移 schema)、service(凭据
透传三路径 / 调度母健康门 / 用量窗口来源与刷新节流 / CRS 母账号不变量 / 各类
早返与 fail-closed 场景)及前端组件(账号列表 / 操作菜单 / 用量重置)。
验证(镜像 CI;golangci-lint 首次全量分析耗时过长被跳过,其余全部实测):
- gofmt -l:干净
- go build ./... / go vet ./...:通过
- go test ./... -count=1:全绿(全部包 ok,含 internal/service、
internal/repository、migrations)
- go test -tags integration ./internal/repository/... ./internal/service/...
(真实 Postgres,testcontainers):全绿,含迁移幂等性
(TestMigrationsRunner_IsIdempotent_AndSchemaIsUpToDate)与影子相关全部用例
- pnpm lint:check / pnpm typecheck / pnpm build(真实 vite 构建)/
pnpm vitest run:全绿(124 文件 760 用例)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com >
2026-07-01 12:21:45 +08:00
shaw
59e9356c51
feat: 抹除 Anthropic OAuth 请求中客户端 dateline 隐写指纹
...
对 /v1/messages 转发到 Anthropic OAuth/setup-token 账号的请求做 dateline
归一化,将 system prompt 与 <system-reminder> 块中 "Today's date is …"
语句里的 4 种撇号变体与 "/" 日期分隔符还原为 ASCII 撇号 + "-",抹除某些
客户端在检测到非官方 base URL 时注入的 3 bit 隐写指纹。API Key 账号不受
影响。新增系统设置开关 enable_client_dateline_normalization,默认开启。
2026-07-01 10:54:18 +08:00
deqiying
03727ac363
fix(subscription): 修复订阅撤销软删除失效
...
总: 增加明确的订阅撤销接口,修复撤销后的缓存失效和管理端 revoked 展示。
分: 同步失效订阅 L1 与 billing cache,补跨实例失效通知、soft-delete-aware 列表查询、revoked_at DTO 字段和回归测试。
2026-07-01 00:37:51 +08:00
xueshiji
915c60b150
feat(group): 订阅分组新增可选的高峰时段倍率,以支持智谱等coding plan的高峰时段
2026-06-30 14:17:05 +08:00
wucm667
93a3bf3077
Fix refund pending finalization gaps
2026-06-30 10:19:50 +08:00
Heatherm Huang
4a7148e203
fix: support grok cli compatibility routes
2026-06-29 17:53:19 +08:00
nslogx
d86e83259e
fix: allow five platform quota updates
2026-06-29 09:40:04 +08:00
Bestony
bad87ff533
feat(ops): add api key filter to system logs
2026-06-27 14:35:19 +08:00
DaydreamCoding and Claude Opus 4.8
819fda34d9
feat(codex-detect): codex_cli_only 检测加固 + 引擎指纹统一信号列表 + 账号级 app-server
...
将 codex_cli_only 客户端识别从「单一 strict 开关 + 固定 OR 头集合」重构为
可逐项管理的引擎指纹信号列表,加固整条判定链,并补齐账号级 app-server 控制、
对齐前端设置文案。
判定链(每步可短路):
- 账号未开 codex_cli_only → 不限制;gateway.force_codex_cli → 旁路放行
- 全局黑名单命中(OR 宽 deny)→ 立即拒
- 身份候选:官方 UA(strict,仅前缀)/ 官方 originator(OR)/ 全局白名单(双因子 AND)
/ 全局 app-server 开关 OR 账号 app-server 开关;均不命中 → 拒
- 版本门(仅官方候选):UA 须可解析引擎版本,再校验 [min,max] 区间
- 引擎指纹 AND 硬门:按信号列表逐条勾选 AND、每条行内变体 OR;无 Required 信号 → 放行
引擎指纹信号列表(唯一真源)
- 新增 openai.EngineFingerprintSignal 类型 + EvaluateEngineFingerprint 求值器
(勾选 AND / 行内变体 OR / 无勾选 → 放行)
- CodexRestrictionPolicy 增 EngineFingerprintSignals;信号列表单一决定是否启用指纹门,
不再保留独立「要求引擎指纹」总开关(与「信号全不选」语义重复)
- 新设置键 codex_cli_only_engine_fingerprint_signals(默认只勾 x-codex- 前缀);
旧 body 指纹开关幂等迁移并入信号列表;wire 接线
- 黑/白名单自由条目、命名预设、版本区间 全局设置管线
- gateway 缺 settingService(仅测试/误配可达)时指纹门回退默认种子信号、失败关闭,
不再因零值 policy(nil 信号)失败开放
账号级 Codex app-server(替换已失效的 ClaudeCode 放行机制)
- account.IsCodexCLIOnlyAppServerAllowed() 读 extra.codex_cli_only_allow_app_server,
仅在 codex_cli_only 开启时生效;候选身份门「全局 OR 账号」,与旧系统双层控制对齐
- 移除已无入口的 claude_code 预设机制(allowedClientRegistry / MatchAllowedClients /
账号 GetCodexCLIOnlyAllowedClients / reason);白名单 AllowedClientEntry / IsAllowedClientMatch 保留
门加固(反伪 + 写入校验)
- 官方 UA 访问门改 strict:IsCodexOfficialClientRequestStrict 仅前缀匹配,收窄「浏览器前缀 +
中段 codex token」伪造面(strict 仍保留 Codex 家族前缀与 UA 尾部兜底,故对「任意前缀 +
官方尾部 (name;ver)」仍放行——与 UA 可伪造、真正反伪靠引擎指纹门的设计一致)
- 官方客户端识别扩展:新增 codex-tui/、codex_vscode_copilot/ 前缀 + UA 尾部 (name;ver) 兜底
(恢复 CODEX_INTERNAL_ORIGINATOR_OVERRIDE 的真实 client,如 cccc→codex-tui),originator 改
精确集。该识别经 IsCodexOfficialClientByHeaders 被 passthrough 复用,故透传的官方判定一并
修正(codex-tui 等不再被误改写 UA)——非「行为不变」,属有意修正
- 白名单写入校验 ValidateCodexWhitelistEntriesJSON + AllowedClientEntry.IsWhitelistable:
双因子 AND 条目须可命中(非空 originator + 非空 ua_contains),拒绝写入会静默失效的死规则;
黑名单(OR 宽 deny,允许 originator-only)不受约束
管理端 / 前端
- handler / DTO / settings_view / 契约测试;gateway 接入判定链
- 信号列表编辑器(替换 body 开关)、api 类型、SettingsView;无勾选给常驻警告
- Create/Edit/Bulk 三弹窗「Codex Only」下新增 app-server 开关(OR 合并全局)
- 文案:UA/Originator → User-Agent/Originator;黑/白名单重命名为 User-Agent/Originator 黑/白名单;
「允许 App Server 第三方客户端」→「Codex app-server」+ 简介示例;i18n zh/en 同步
- 移除死代码 HasCodex*Fingerprint helper
测试:引擎指纹求值器 / 账号 app-server(OR 语义)/ detector(含 N1 strict、失败关闭)/
白名单写入校验 / BulkEdit spec 等;后端 build + service/openai/admin 单测全绿,前端 vue-tsc + vitest 全绿。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-26 16:19:41 +08:00
Wesley Liddick
2fc4fef847
Merge pull request #3310 from heathermhuang/codex/grok-subscription-support
...
feat: add grok subscription support
2026-06-26 15:41:52 +08:00
Heatherm Huang
44f502bab8
fix: address grok review feedback
2026-06-26 14:26:43 +08:00
Wesley Liddick
683a8d8096
Merge pull request #3421 from syx0310/fork/openai-codex-pat-auth-upstream
...
feat: add codex personal access token auth
2026-06-26 11:15:38 +08:00
Heatherm Huang
720db8983f
test: harden grok quota readiness
2026-06-26 10:42:21 +08:00
Heatherm Huang
0d28642181
feat: add grok quota probe parity
2026-06-26 10:37:37 +08:00
Heatherm Huang
39be1ec97f
feat: add grok subscription support
2026-06-26 10:36:09 +08:00
wucm667
55242ffac1
fix(admin): 订单金额币种符号读取 currency 字段
2026-06-25 16:23:45 +08:00
syx0310
32df33a1c3
feat: add codex personal access token auth
2026-06-22 16:07:41 +00:00
feitianbubu
2dc1387b59
fix(promo): allow clearing promo code expiry on edit
2026-06-18 23:07:25 +08:00
Wesley Liddick
2e0ff1cfd5
Merge pull request #3258 from bwliangc/feat/channel-monitor-jitter
...
feat(渠道监控): 检测间隔支持正负随机抖动配置
2026-06-16 16:58:23 +08:00
Wesley Liddick
16765bde69
Merge pull request #3230 from DaydreamCoding/feat/openai-cyber-policy-passthrough
...
feat(openai): cyber_policy 硬阻断全链路透传、审计与计费
2026-06-16 16:55:51 +08:00
shaw
b816949291
feat(openai-quota): query + reset rate-limit credits for OpenAI accounts
...
Adds an admin-side action that mirrors the Codex Desktop "rate-limit reset"
flow against chatgpt.com upstream for OpenAI OAuth accounts.
Backend
- OpenAIQuotaService.QueryUsage / ResetCredit hit /wham/usage and
/wham/rate-limit-reset-credits/consume with the Codex Desktop header set,
reusing OpenAITokenProvider for refreshed tokens and PrivacyClientFactory
for the impersonated Chrome TLS fingerprint.
- Honors the account's configured proxy by reading the eager-loaded
account.Proxy directly (falls back to proxyRepo only when missing).
- GET /api/v1/admin/openai/accounts/:id/quota
POST /api/v1/admin/openai/accounts/:id/reset-quota
- Wire DI for the new service + handler dependency.
Frontend
- OpenAIQuotaResetCell renders a single action row in AccountUsageCell's
OpenAI section: the existing local "查询" (active sampling) is injected
via #pre-actions, alongside a "次数 N" button that doubles as the
upstream query trigger and the available-credit indicator, and a "重置"
button that consumes one credit.
- No duplicate 5h/7d window display; the local UsageProgressBar owns those
bars to avoid confusion.
2026-06-16 16:55:07 +08:00
dailingfei
8ce7b9a8f6
feat: configure Claude OAuth system prompt blocks
2026-06-13 04:12:13 +08:00
bwlc and Claude Fable 5
c70c6a2659
feat(渠道监控): 检测间隔支持正负随机抖动配置
...
新增 jitter_seconds 配置:每轮调度在 interval 基础上 ± [0, jitter]
均匀随机偏移触发,避免多个监控以固定节奏同步请求上游。
- ent schema 新增 jitter_seconds 字段(默认 0),附迁移 151
- 校验:jitter >= 0 且 interval - jitter >= 15s(创建/更新均校验)
- runner 由固定 ticker 改为每轮重新随机化的 timer,0 抖动时行为不变
- 前端监控表单新增「随机抖动 (± 秒)」输入框,上限随间隔联动
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-06-12 22:09:53 +08:00
DaydreamCoding and Claude Opus 4.8
b62b573f7f
feat(openai): cyber_policy 硬阻断全链路透传、审计与计费
...
上游对单次请求下发 error.code=cyber_policy 硬阻断时,网关在所有端点
(/v1/responses、/v1/chat/completions、/v1/messages、WebSocket)及流式/
非流式路径下,将该结果原样透传给客户端,绝不 failover、换号或同步拦截;
命中后异步完成审计与计费:
- 风控中心记录 cyber_policy 留痕并发送通知邮件,落库先于发信,SMTP 阻塞
不影响留痕
- ops 错误请求记录,状态码对齐客户端实际接收(流式 200 / 非流式 400)
- 用量明细标记 request_type=cyber,按上游真实 token 计费,HTTP 与
WebSocket 计费口径统一,零 token 命中不误扣
- 会话级自动屏蔽(管理员开关,默认关):命中的会话在可配 TTL 内本地拦截
不再发往上游,仅屏蔽该会话不影响同 Key 其他会话
- 封号计数排除开关:可选让 cyber 命中不计入自动封号,命中当次不判定且
历史行在违规计数中一并排除
WebSocket 多轮连接下 cyber 标记按 turn 生命周期管理,逐轮独立检测与记录;
透传的错误响应不被兜底逻辑追加内容污染。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-06-12 01:47:01 +08:00