Wesley Liddick
addcb34e14
Merge pull request #3851 from fengshao1227/fix/responses-to-anthropic-instructions-and-developer-role
...
fix(apicompat): ResponsesToAnthropicRequest 补全 instructions 字段并映射 developer role
2026-07-09 16:34:36 +08:00
Wesley Liddick
843dcddea3
Merge pull request #3853 from fengshao1227/fix/messages-transport-failover
...
fix(messages): /v1/messages 传输层错误对齐 failover 链路
2026-07-09 16:34:00 +08:00
Wesley Liddick
c842c3166c
Merge pull request #3847 from heathermhuang/codex/grok-45-official-support
...
Add official Grok 4.5 support
2026-07-09 16:07:42 +08:00
Heatherm Huang
243678e166
Fix Grok 4.5 alias test expectations
2026-07-09 15:50:58 +08:00
li
7468427e44
fix(messages): /v1/messages 传输层错误对齐 failover 链路,不再直接 502
...
Fixes #3850 (part 2)
2026-07-09 15:49:10 +08:00
shaw
d4952154ff
fix: bill Grok video per second and harden video usage logging
...
Follow-up fixes for the #3775 audit findings:
- Bill Grok video generation per second of output, matching the xAI rate
card: parse the request duration (1-15s, upstream default 8s) and compute
cost as per-second price x duration x count. The built-in rate card values
were already xAI per-second prices but were previously charged per video,
undercharging up to 15x with a user-controlled duration.
- Group video_price_* fields are now documented and surfaced as per-second
rates (USD/s); admin UI labels, placeholders and hints updated accordingly.
- Persist video_count/video_resolution/video_duration_seconds on usage_logs
(migration 172) so video billing is auditable, and exempt any row with
video_count > 0 from the image_size check constraint: a video billed via a
token-mode channel price produces billing_mode='token' with image_count=1
and no image_size, which the previous constraint rejected, dropping the
whole billing transaction.
- Only refetch the group in apiKeyWithFreshGroupMediaPricing when the group
object actually looks like it is missing media pricing fields (both media
multipliers zero and all prices nil, impossible for a normally loaded
group), removing a per-usage DB query for groups without overrides.
- Frontend: drop the unused admin.groups.mediaPricing locale block, map
cleared price inputs to null (create) / -1 (update, cleared via backend
normalizePrice) instead of sending "" that failed *float64 unmarshalling,
and align video price placeholders with the text-to-video default model
(grok-imagine-video 0.05/0.07, 1080p only on 1.5 at 0.25).
2026-07-09 15:38:59 +08:00
li
1785509873
fix(apicompat): ResponsesToAnthropicRequest 补全 instructions 字段并映射 developer role
...
Fixes #3850
2026-07-09 15:34:10 +08:00
Wesley Liddick
9ba0fb3084
Merge pull request #3775 from heathermhuang/codex/grok-media-pricing-labels
...
fix: add Grok video pricing controls
2026-07-09 15:03:38 +08:00
Wesley Liddick
b6d2df24d8
Merge pull request #3800 from Ge-limin/feat/codex-models-manifest
...
feat: Codex 客户端模型清单(manifest)透传接口
2026-07-09 14:40:23 +08:00
Wesley Liddick
52da41fd6e
Merge pull request #3809 from hongheshan-svg/fix/upstream-anthropic-429-fallback
...
fix(ratelimit): Anthropic 无 reset 头的 429 也进入兜底冷却,避免账号永不冷却导致的 429 循环
2026-07-09 14:40:10 +08:00
Wesley Liddick
dfff28ab05
Merge pull request #3843 from InCerryGit/fix/issue-3540-lenient-json-limit
...
fix(gateway): cap lenient JSON normalization
2026-07-09 14:39:55 +08:00
Wesley Liddick
9392d1fc43
Merge pull request #3841 from fengshao1227/fix/html-escape-site-name-and-sanitize-doc-url
...
fix(security): HTML-escape site_name 并对 doc_url 统一应用 sanitizeUrl
2026-07-09 14:39:26 +08:00
Wesley Liddick
a57157b9fa
Merge pull request #3822 from wucm667/feat/api-key-last-used-ip
...
feat(api-key): 展示 API Key 最近使用 IP
2026-07-09 14:38:01 +08:00
Wesley Liddick
0118fa3ce2
Merge pull request #3721 from CHOS1N11111/codex/add-response-format-compat
...
Add response_format compatibility mapping
2026-07-09 14:37:46 +08:00
Wesley Liddick
105ac31c37
Merge pull request #3781 from fengshao1227/fix/openai-oauth-empty-mapping-model-guard
...
fix(scheduler): 空 model_mapping 的 OpenAI OAuth 账号不再吸收全部模型
2026-07-09 14:37:33 +08:00
Wesley Liddick
7302be4d13
Merge pull request #3833 from superman2003/fix/security-and-frontend-hardening
...
fix(gateway,frontend): 修复 Gemini 鉴权绕过与前端支付/会话缺陷
2026-07-09 14:37:19 +08:00
Wesley Liddick
636c452535
Merge pull request #3836 from ShuYeJang/main
...
fix(billing): 渠道定价覆盖写穿 fallbackPrices 共享指针导致全局计费污染
2026-07-09 14:37:05 +08:00
Heatherm Huang
cccba9a82e
Add official Grok 4.5 support
2026-07-09 14:26:10 +08:00
shaw
25a7169601
chore: Go 工具链升级 1.26.4 → 1.26.5——修复 stdlib 漏洞并补齐 CI 版本引用
...
- backend/go.mod 工具链 1.26.5:修复 stdlib crypto/tls 漏洞(GO-2026-5856)
- 同步全部构建/校验点的硬编码版本:根 Dockerfile、backend/Dockerfile、
deploy/Dockerfile 基础镜像;backend-ci / release / security-scan 三个
workflow 的 go version 校验
2026-07-09 14:06:57 +08:00
InCerry
53a5c45bd8
fix(gateway): cap lenient json normalization
...
Fixes #3540
2026-07-09 11:15:52 +08:00
li
bfb827b879
fix(security): HTML-escape site_name 并对 doc_url 统一应用 sanitizeUrl
...
Refs #3839 (第 8、12 点)
2026-07-09 10:03:49 +08:00
superman2003 and Cursor
29a5fcd25e
fix(gateway,frontend): 修复鉴权绕过与前端支付/会话缺陷
...
后端:
- Gemini /v1beta 鉴权中间件补齐主中间件的授权校验: API Key 的 IP 白/黑名单、
专属分组授权、运行时过期/配额二次检查, 修复经 Gemini 端点绕过 IP ACL、
越权访问专属分组、以及状态未刷新时的配额/有效期绕过窗口。
- 粘性会话等待计划分支改走 newSelectionResult 以 hydrate 账号凭证, 修复调度
快照中账号凭证被剥离导致等待路径转发鉴权失败。
- SSE 流式转发客户端断开时不再 break 跳过当前事件 usage 合并, 修复少计费。
- Forward 对 nil gin.Context 的防御补齐; 上游错误体读取失败时记录日志避免静默。
前端:
- logout 将本地会话清理移入 finally, 服务端吊销失败也保证本地登出。
- Stripe 弹窗轮询改用正确的 auth_token 键并加防重入; 收到 INIT 后清除兜底
超时定时器, onUnmounted 清理 message 监听器。
- token 刷新请求补充 30s 超时, 避免挂起导致请求队列与 loading 永久卡死。
- 路由守卫在公共设置未加载时先 await fetchPublicSettings, 避免 payment/
risk_control 被误判为未启用而错误拦截。
- 支付状态轮询回调补充防重入与终态守卫。
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-07-09 09:06:56 +08:00
Wesley Liddick
88581912ba
test: add regression tests for fallback pricing pollution
2026-07-08 19:23:38 +00:00
Wesley Liddick
4a30397623
fix: prevent channel pricing overrides from mutating shared fallback pricing
2026-07-08 18:37:33 +00:00
wucm667
7a11b39d6d
fix(api-key): check usage log rows close
2026-07-08 15:36:12 +08:00
wucm667
e0d149d511
feat(api-key): show last used IP
2026-07-08 15:26:54 +08:00
Heatherm Huang
3b206cc639
test: preserve grok video resolution forwarding
2026-07-08 13:50:49 +08:00
Heatherm Huang
889b657451
test: accept casted video billing constraint
2026-07-08 13:50:49 +08:00
Heatherm Huang
376e03ded1
fix: update Grok media default rate card
2026-07-08 13:50:49 +08:00
Heatherm Huang
4d702e3234
fix: split Grok image and video pricing
2026-07-08 13:50:49 +08:00
Wesley Liddick
6f43986c37
Merge pull request #3811 from jianjianai/hotfix/admin-scheduler-score-opt-in
...
fix(admin): 管理员账号列表默认关闭调度权值计算以降低负载
2026-07-08 10:22:10 +08:00
shaw
a56eb5b4dc
fix(compact): body-signal 提升上移到 handler 层并对齐 path-based 链路
...
合并 main 解决拆分冲突后,将原先 Forward 内的 body-signal 提升重构到
handler 的 compact 归一化入口之前,修复原方案的四个问题:
- reqStream 未重推导:body-signal 原始请求带 stream:true,Forward 级提升
后 compact 上游返回 JSON(Accept: application/json)却被流式 handler
解析,"stream ended before a terminal event" 会触发最多
max_account_switches 次换号 failover,且每次都白烧一次上游 compact 配额;
handler 级提升让白名单归一化先删除 stream,reqStream 自然为 false。
- requireCompact 调度过滤失效:原方案 path 改写发生在 requireCompact 判定
之后,调度器不会过滤不支持 compact 的账号;现在改写先于该判定。
- passthrough / Grok / chat-completions 桥接分支位于 Forward 检测点之前,
passthrough 账号完全无法命中;handler 级改写对所有分支生效。
- body 归一化口径不一致:body-signal 现在与 path-based 一样走白名单归一化
(prompt_cache_key 等一并删除),而非仅依赖 OAuth 黑名单转换。
检测函数导出为 HasCompactionTriggerInInput 供 handler 使用,保留原 PR 的
7 个单测;新增 6 个 handler 级回归测试(提升、codex 别名路由、尾斜杠、
子路径不误伤、path-based 无双重后缀、普通请求不受影响)。
Refs #3777
2026-07-08 10:04:14 +08:00
shaw
a855317624
Merge remote-tracking branch 'origin/main' into fix/compact-body-signal-routing
...
# Conflicts:
# backend/internal/service/openai_gateway_service.go
2026-07-08 09:57:31 +08:00
shaw
bb5d2e84a1
refactor(handler): 纯移动拆分 setting_handler.go(3957→468行)
2026-07-08 08:49:22 +08:00
shaw
f013bc1141
refactor(service): 纯移动拆分 admin_service.go(4409→642行)
2026-07-08 08:49:22 +08:00
shaw
2a4c28e8f5
refactor(service): 纯移动拆分 antigravity_gateway_service.go(4664→639行)
2026-07-08 08:49:22 +08:00
shaw
d0f669338b
refactor(service): 纯移动拆分 openai_ws_forwarder.go(4675→399行)
2026-07-08 08:49:21 +08:00
shaw
db3bd9971e
refactor(repository): 纯移动拆分 usage_log_repo.go(4701→212行)
2026-07-08 08:49:21 +08:00
shaw
4d23ad4bac
refactor(service): 纯移动拆分 openai_gateway_service.go(4872→1095行)
2026-07-08 08:49:21 +08:00
shaw
50043b1176
refactor(service): 纯移动拆分 setting_service.go(5471→263行)
2026-07-08 08:49:20 +08:00
shaw
084d26cbd2
refactor(service): 纯移动拆分 gateway_service.go(7294→1289行)
2026-07-08 08:49:20 +08:00
shaw
a4f942d8a9
fix(deps): 升级 AWS SDK 修复 govulncheck 报告的 GO-2026-5764
...
eventstream v1.7.5→v1.7.8、service/s3 v1.96.2→v1.97.3(含关联 internal 模块),
修复 EventStream 解码器 DoS 漏洞,恢复 backend-security CI。
2026-07-08 08:37:29 +08:00
jjaw
6ae5fc31b3
fix(admin): gate scheduler score calculation
2026-07-08 06:58:35 +08:00
zhengshan and Claude Opus 4.8
3866da508f
fix(ratelimit): Anthropic 无 reset 头的 429 也进入兜底冷却
...
此前 Anthropic 429 若响应头无窗口重置时间(如 Extra usage required),
被视为"非真实限流"直接跳过标记。后果:账号永不冷却,调度器让每个
请求反复撞同一批持续 429 的账号——failover 预算烧尽后客户端稳定
收到 429(生产实测:一次请求 1.3s 内连换 4 账号全 429,而 DB 中
这些账号的限流状态毫无更新)。
改为与其他平台一致走 apply429FallbackRateLimit 秒级兜底回避:
- 默认 5s,管理端 RateLimit429CooldownSettings 可调 1~7200s
- 管理端关闭该设置即恢复旧行为(不标记)
- 日志 reason 标记为 anthropic_no_reset_time 便于运营区分
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-07 23:19:23 +08:00
shaw
d754be0d8e
refactor(gateway): 抽取 CC forwarder 公共管线并拆分两大 service 文件
...
PR #3802 遗留项:三个 CC forwarder(raw 直转 / responses 回退 / messages
回退)间约 85% 重复的 HTTP 管线与 SSE 循环骨架收敛到新文件
openai_gateway_cc_pipeline.go,messages / chat_completions 两条主路径中
逐字相同的错误处理块一并接入。各路径有意保留的行为差异(GLM effort
归一化、fast policy 适用范围、ClientDisconnect 语义、Grok 分支等)留在
调用方,未强行统一。
同时对两个最臃肿的网关文件做纯移动拆分(零语义变化,逐字节校验):
- openai_gateway_service.go 7821→4872 行:
调度 → openai_gateway_scheduling.go
passthrough → openai_gateway_passthrough.go
用量/计费/codex 快照 → openai_gateway_usage.go
- gateway_service.go 10912→7294 行:
调度 → gateway_scheduling.go
Anthropic APIKey 直通 → gateway_anthropic_passthrough.go
Bedrock → gateway_bedrock.go
回归保障:全部搬迁块与 HEAD 逐字节 diff 一致;留存文件经"HEAD 减去搬迁
范围"重构比对,差异仅为 goimports 移除的孤儿 import;定向单测
(fallback/raw/cyber/grok/transport/调度/用量/广域 Forward-Handle 扫描)
全绿;另经独立对抗审计确认零行为差异。
2026-07-07 22:14:46 +08:00
li
2dd2be9922
fix(compact): 识别 /v1/responses body 中的 compaction_trigger 信号
...
Codex remote compact v2 可以把 compact 触发器作为 input item
(type=compaction_trigger)嵌入普通 POST /v1/responses 请求体,
而非直接调用 /v1/responses/compact。此前 isCompactRequest 仅检查
URL path 后缀,导致 body-signal 形式的 compact 请求被当作普通
Responses 处理——上游路径、模型映射、body 归一化全部错误,Codex
收到非 compact 响应后报 "expected exactly one compaction output
item, got 0",长会话无法继续。
新增 hasCompactionTriggerInInput 检测 input 中的 compaction_trigger
item,命中后提升为 compact 请求并改写 URL path,使后续所有
isCompactRequest 分支(模型映射、body 归一化、上游 URL 构建)
自动生效。
Fixes #3777 (part 1: body-signal routing)
2026-07-07 21:23:02 +08:00
shaw
dad92488e5
fix(messages): 修复 /v1/messages CC 回退的错误处理旁路并补齐流式测试
...
针对 #3795 合并后审计发现的问题:
- 非 failover 上游错误分支改走共享 handleAnthropicErrorResponse:恢复
ops 上游错误记录、错误透传规则、cyber_policy 检测与按状态码映射的
错误 type(400→invalid_request_error 等);删除随之失效的
mapUpstreamStatusToAnthropicStatus
- 流式读错误对齐 forwardResponsesViaRawChatCompletions:scanner 出错时
不再 finalize(不再补发 message_stop 把截断伪装成正常完成),返回
stream usage incomplete 错误
- sawDone 由死变量改为与兄弟一致的无 [DONE] 哨兵 debug 日志
- 补充 fast policy 在本路径有意省略的说明注释
- 新增 8 个单测:流式收尾闭块、tool_call 分片聚合、length→max_tokens、
空流补帧、非 failover 400 走共享处理器、读错误不伪造收尾、
Responses 账号门控回归、非流式转换
2026-07-07 20:59:41 +08:00
Wesley Liddick
4bcb13f77f
Merge pull request #3786 from creamtea47/codex/openai-fast-force-priority
...
add force priority fast policy action
2026-07-07 20:45:45 +08:00
Wesley Liddick
9643382bd3
Merge pull request #3795 from fengshao1227/fix/messages-inbound-chat-completions-fallback
...
fix(messages): /v1/messages 入站支持不兼容 Responses API 的 OpenAI 上游
2026-07-07 20:45:14 +08:00
Wesley Liddick
af4b75a77c
Merge pull request #3794 from fengshao1227/fix/image-gen-namespace-permission-bypass
...
fix(image): 识别 Codex namespace image_gen 工具声明以拦截生图请求
2026-07-07 20:42:43 +08:00