Wesley Liddick
7cb98e5bdc
Merge pull request #2007 from PMExtra/feature/user-usage-admin-parity
...
feat: align user usage analytics with admin
2026-06-30 17:10:09 +08:00
shaw
930326116e
fix: 修复订阅支付金额显示错误
2026-06-30 16:26:22 +08:00
PMExtra
cafc95c3e2
feat: align user usage analytics with admin
2026-06-30 15:31:28 +08:00
shaw
345d5c6b56
chore: update sponsors
2026-06-30 14:11:14 +08:00
Wesley Liddick
76e0d90736
Merge pull request #3509 from wucm667/fix/refund-pending-not-success
...
fix(payment): 退款 pending 不再当成最终成功,避免站内账务与网关状态不一致
2026-06-30 13:38:04 +08:00
shaw
bf4f006736
fix: 修复用户列表使用时间排序冲突
2026-06-30 13:36:36 +08:00
Wesley Liddick
efb8b45876
Merge pull request #3560 from StarryKira/feat/issue-3557-oauth-email
...
feat: fix OAuth email completion flow
2026-06-30 10:55:00 +08:00
Wesley Liddick
ac6f2e9693
Merge pull request #3559 from 315944211/fix/privacy-toast-result
...
fix: show privacy setting result accurately
2026-06-30 10:50:17 +08:00
Wesley Liddick
e70e36e4d2
Merge pull request #3484 from bwliangc/feat/risk-control-matched-keyword
...
feat(risk-control): record matched keyword in keyword-block logs
2026-06-30 10:40:30 +08:00
wucm667
93a3bf3077
Fix refund pending finalization gaps
2026-06-30 10:19:50 +08:00
wucm667
7316d83027
fix(payment): 区分退款 pending 并收敛匿名查单
2026-06-30 10:00:48 +08:00
haruka
260fda19b3
feat: fix OAuth email completion flow
2026-06-30 01:11:51 +08:00
315944211
a0a3d0c33e
fix: show privacy setting result accurately
2026-06-30 00:37:21 +08:00
Heatherm Huang
4a7148e203
fix: support grok cli compatibility routes
2026-06-29 17:53:19 +08:00
Wesley Liddick
c99112a9e9
Merge pull request #3515 from bestony/feat/ops-system-log-key-id
...
feat(ops): add key id filter to system logs
2026-06-29 09:24:40 +08:00
Wesley Liddick
a22b12677f
Merge pull request #3517 from bestony/feat/keys-column-settings
...
feat(keys): add API key column settings
2026-06-29 09:24:20 +08:00
Wesley Liddick
b0dbc22fe5
Merge pull request #3510 from wucm667/fix/subscription-confirm-show-converted-amount
...
fix(payment): 订阅订单确认页显示换算后的 CNY 实付金额,而非 USD 套餐价
2026-06-29 09:24:01 +08:00
Wesley Liddick
bebafe7697
Merge pull request #3437 from imfangwenjie/fix/api-base-fetch
...
fix(frontend): use configured API base for direct requests
2026-06-29 09:23:13 +08:00
Wesley Liddick
38577c6ca0
Merge pull request #3533 from Pluviobyte/codex/fix-api-key-unlimited-quota
...
fix(keys): reactivate exhausted keys set to unlimited
2026-06-29 09:19:53 +08:00
Wesley Liddick
47598462f5
Merge pull request #3401 from StarryKira/fix/issue-3394-fallback-pricing-log-spam
...
fix: stop per-request fallback-pricing log spam for unknown models (#3394 )
2026-06-29 09:19:44 +08:00
Pluviobyte
da810c3b43
fix(keys): reactivate exhausted keys set to unlimited
2026-06-28 09:05:28 +08:00
Bestony
b244f850e7
feat(keys): add column settings
2026-06-27 15:14:13 +08:00
Bestony
bad87ff533
feat(ops): add api key filter to system logs
2026-06-27 14:35:19 +08:00
wucm667
88ca0c1d13
fix(payment): 显示订阅 CNY 换算实付金额
2026-06-27 12:15:39 +08:00
shaw
9a0fbcc87d
chore: update sponsors
2026-06-26 17:32:50 +08:00
DaydreamCoding and Claude Opus 4.8
819fda34d9
feat(codex-detect): codex_cli_only 检测加固 + 引擎指纹统一信号列表 + 账号级 app-server
...
将 codex_cli_only 客户端识别从「单一 strict 开关 + 固定 OR 头集合」重构为
可逐项管理的引擎指纹信号列表,加固整条判定链,并补齐账号级 app-server 控制、
对齐前端设置文案。
判定链(每步可短路):
- 账号未开 codex_cli_only → 不限制;gateway.force_codex_cli → 旁路放行
- 全局黑名单命中(OR 宽 deny)→ 立即拒
- 身份候选:官方 UA(strict,仅前缀)/ 官方 originator(OR)/ 全局白名单(双因子 AND)
/ 全局 app-server 开关 OR 账号 app-server 开关;均不命中 → 拒
- 版本门(仅官方候选):UA 须可解析引擎版本,再校验 [min,max] 区间
- 引擎指纹 AND 硬门:按信号列表逐条勾选 AND、每条行内变体 OR;无 Required 信号 → 放行
引擎指纹信号列表(唯一真源)
- 新增 openai.EngineFingerprintSignal 类型 + EvaluateEngineFingerprint 求值器
(勾选 AND / 行内变体 OR / 无勾选 → 放行)
- CodexRestrictionPolicy 增 EngineFingerprintSignals;信号列表单一决定是否启用指纹门,
不再保留独立「要求引擎指纹」总开关(与「信号全不选」语义重复)
- 新设置键 codex_cli_only_engine_fingerprint_signals(默认只勾 x-codex- 前缀);
旧 body 指纹开关幂等迁移并入信号列表;wire 接线
- 黑/白名单自由条目、命名预设、版本区间 全局设置管线
- gateway 缺 settingService(仅测试/误配可达)时指纹门回退默认种子信号、失败关闭,
不再因零值 policy(nil 信号)失败开放
账号级 Codex app-server(替换已失效的 ClaudeCode 放行机制)
- account.IsCodexCLIOnlyAppServerAllowed() 读 extra.codex_cli_only_allow_app_server,
仅在 codex_cli_only 开启时生效;候选身份门「全局 OR 账号」,与旧系统双层控制对齐
- 移除已无入口的 claude_code 预设机制(allowedClientRegistry / MatchAllowedClients /
账号 GetCodexCLIOnlyAllowedClients / reason);白名单 AllowedClientEntry / IsAllowedClientMatch 保留
门加固(反伪 + 写入校验)
- 官方 UA 访问门改 strict:IsCodexOfficialClientRequestStrict 仅前缀匹配,收窄「浏览器前缀 +
中段 codex token」伪造面(strict 仍保留 Codex 家族前缀与 UA 尾部兜底,故对「任意前缀 +
官方尾部 (name;ver)」仍放行——与 UA 可伪造、真正反伪靠引擎指纹门的设计一致)
- 官方客户端识别扩展:新增 codex-tui/、codex_vscode_copilot/ 前缀 + UA 尾部 (name;ver) 兜底
(恢复 CODEX_INTERNAL_ORIGINATOR_OVERRIDE 的真实 client,如 cccc→codex-tui),originator 改
精确集。该识别经 IsCodexOfficialClientByHeaders 被 passthrough 复用,故透传的官方判定一并
修正(codex-tui 等不再被误改写 UA)——非「行为不变」,属有意修正
- 白名单写入校验 ValidateCodexWhitelistEntriesJSON + AllowedClientEntry.IsWhitelistable:
双因子 AND 条目须可命中(非空 originator + 非空 ua_contains),拒绝写入会静默失效的死规则;
黑名单(OR 宽 deny,允许 originator-only)不受约束
管理端 / 前端
- handler / DTO / settings_view / 契约测试;gateway 接入判定链
- 信号列表编辑器(替换 body 开关)、api 类型、SettingsView;无勾选给常驻警告
- Create/Edit/Bulk 三弹窗「Codex Only」下新增 app-server 开关(OR 合并全局)
- 文案:UA/Originator → User-Agent/Originator;黑/白名单重命名为 User-Agent/Originator 黑/白名单;
「允许 App Server 第三方客户端」→「Codex app-server」+ 简介示例;i18n zh/en 同步
- 移除死代码 HasCodex*Fingerprint helper
测试:引擎指纹求值器 / 账号 app-server(OR 语义)/ detector(含 N1 strict、失败关闭)/
白名单写入校验 / BulkEdit spec 等;后端 build + service/openai/admin 单测全绿,前端 vue-tsc + vitest 全绿。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-26 16:19:41 +08:00
Wesley Liddick
2fc4fef847
Merge pull request #3310 from heathermhuang/codex/grok-subscription-support
...
feat: add grok subscription support
2026-06-26 15:41:52 +08:00
Wesley Liddick
683a8d8096
Merge pull request #3421 from syx0310/fork/openai-codex-pat-auth-upstream
...
feat: add codex personal access token auth
2026-06-26 11:15:38 +08:00
bwlc and Claude Opus 4.8
815bc6c9b5
feat(risk-control): record matched keyword in keyword-block logs
...
The risk control center's moderation log records had no field for the
keyword that triggered a keyword block, so the admin UI couldn't show
which keyword was hit (only the application slog logged it).
- migration 156: add matched_keyword column to content_moderation_logs
- ContentModerationLog gains MatchedKeyword; set it on keyword block
- repo CreateLog/ListLogs persist and read the column
- frontend: show "命中关键词" inline in the log table and detail modal
- i18n: add matchedKeyword (zh/en)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-26 10:43:05 +08:00
Heatherm Huang
720db8983f
test: harden grok quota readiness
2026-06-26 10:42:21 +08:00
Heatherm Huang
2a80495880
docs: clarify grok public route scope
2026-06-26 10:37:37 +08:00
Heatherm Huang
939905b8c7
fix: refine grok quota pause behavior
2026-06-26 10:37:37 +08:00
Heatherm Huang
0d28642181
feat: add grok quota probe parity
2026-06-26 10:37:37 +08:00
Heatherm Huang
f29ccc7dfb
fix: reduce grok oauth account-risk paths
2026-06-26 10:36:09 +08:00
Heatherm Huang
39be1ec97f
feat: add grok subscription support
2026-06-26 10:36:09 +08:00
Wesley Liddick
fd9c945fab
Merge pull request #3470 from wucm667/fix/order-currency-symbol-from-field
...
fix(admin): 订单金额币种符号读取 currency 字段,修复 USD 渠道显示为 ¥
2026-06-26 09:46:02 +08:00
Wesley Liddick
94c059c99e
Merge pull request #3471 from wucm667/fix/antigravity-standard-tier-empty-project-fallback
...
fix(antigravity): standard-tier 账号 project_id 为空时兜底,避免全部请求 500
2026-06-26 09:45:54 +08:00
Wesley Liddick
0bff6f9ac5
Merge pull request #3482 from SMGoro/fix/payment
...
fix(payment): 修复后端返回空supported_types时支付提供商卡片消失的问题
2026-06-26 09:42:33 +08:00
Wesley Liddick
d65b4c90ad
Merge pull request #3435 from zichuanwangcloud-gif/fix/ops-dashboard-chart-infinite-height
...
fix(ops): prevent monitoring trend cards from growing unbounded
2026-06-26 09:39:06 +08:00
Wesley Liddick
e89f4b43c0
Merge pull request #3433 from feitianbubu/fix/cc-terminal-attribution-header
...
fix(keys): add CLAUDE_CODE_ATTRIBUTION_HEADER=0 to Claude Code terminal templates
2026-06-26 09:38:57 +08:00
imfangwenjie
2a58a57a7c
fix(frontend): use configured API base for direct requests
...
Route direct fetch calls, setup requests, gateway usage checks, and ops WebSocket connections through the configured API base instead of assuming same-origin backend paths.
Also derive OAuth callback suggestions from the configured API base so split frontend/API deployments show usable redirect URLs.
2026-06-26 02:42:44 +08:00
SMGDev
65ad7df4f4
fix(payment): 修复后端返回空supported_types时支付提供商卡片消失的问题
...
统一处理后端返回的null类型supported_types,将其标准化为空数组,避免调用includes()时报错导致卡片无法显示,同时修复多处相关的类型判断逻辑
2026-06-26 00:50:22 +08:00
wucm667
650c50e34b
fix(antigravity): add project fallback for standard tier
2026-06-25 16:29:33 +08:00
wucm667
55242ffac1
fix(admin): 订单金额币种符号读取 currency 字段
2026-06-25 16:23:45 +08:00
shaw
30adee43bc
feat(admin/accounts): confirm before OpenAI weekly limit reset
2026-06-24 21:56:03 +08:00
zichuanwangcloud-gif and Claude Opus 4.8
9707dedca2
fix(ops): prevent monitoring trend cards from growing unbounded
...
The concurrency / switch-rate / throughput cards on the ops dashboard
sit in grid cells that only set `min-h-[360px]` (no definite height).
Their inner card uses `h-full`, which resolves to `auto` when the parent
height is `auto`. Combined with the Chart.js `responsive` +
`maintainAspectRatio: false` charts, this forms a height feedback loop:
the canvas reads the parent height to size itself, the content then grows,
the next ResizeObserver tick reads an even larger height, and the cards
stretch downward without bound.
On wide screens (`lg:grid-cols-4`) a sibling card usually fixes the row
height via `align-items: stretch`, masking the issue. It surfaces when no
sibling bounds the row height — e.g. the single-column (`grid-cols-1`)
stacked layout on narrow viewports, or when the concurrency card collapses
to little content. `min-h` only sets a floor, not a ceiling.
Fix: give the two Chart.js canvas cells a definite height (`h-[360px]`) so
the responsive resize has a fixed reference and the loop cannot run. The
concurrency card is not a responsive canvas, so it keeps `min-h-[360px]`
to avoid clipping its content.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-23 10:46:17 +00:00
feitianbubu
28e7adef09
fix(keys): add CLAUDE_CODE_ATTRIBUTION_HEADER=0 to Claude Code terminal templates
2026-06-23 18:27:49 +08:00
syx0310
32df33a1c3
feat: add codex personal access token auth
2026-06-22 16:07:41 +00:00
haruka and Claude Opus 4.8
6239e395b8
i18n(channel): explain case-insensitive matching in pricing conflict messages ( #3394 )
...
Update the modelConflict / mappingConflict strings (en + zh) to state that
model names are matched case-insensitively, so an existing entry (e.g.
"GLM-5.2") already covers all case variants and the lowercase variant does not
need to be added. This addresses the confusion in #3394 where the rejection of
a case-only duplicate looked like inconsistent behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-21 07:47:49 -07:00
Wesley Liddick
d2ff9c0c4c
Merge pull request #3369 from skyswordw/codex/default-ccswitch-openai-gpt-55
...
fix(ccswitch): default OpenAI import model to gpt-5.5
2026-06-21 21:16:07 +08:00