Wesley Liddick
5eb9da9c93
Merge pull request #3593 from heathermhuang/codex/grok-media-routing
...
fix: route Grok media endpoints
2026-07-01 17:49:27 +08:00
Wesley Liddick
0a9146c3d1
Merge pull request #3586 from deqiying/codex/fix-subscription-revoke-soft-delete
...
修复订阅撤销操作实际上是软删除的bug
2026-07-01 15:38:45 +08:00
Heatherm Huang
42e471f59a
fix: harden grok media routing
2026-07-01 15:36:08 +08:00
Wesley Liddick
3812e627a8
Merge pull request #3546 from nslogx/fix/platform-quota-five-platforms
...
fix: allow five platform quota updates
2026-07-01 14:07:08 +08:00
DaydreamCoding and Claude Sonnet 5
bdf7ead157
feat(spark-shadow): OpenAI Spark 链接型影子账号
...
背景:gpt-5.3-codex-spark 使用独立于 codex 全局(5h/7d)的配额窗口(数据源是
/wham/usage 响应体的 codex_bengalfox,而非 codex 全局用的 x-codex-* 响应头),且
只能挂在已完成 OAuth 授权的 OpenAI 账号下复用其登录态,不能作为独立账号单独接入。
为此新增“链接型影子账号”(spark shadow account):影子账号本身不持有任何凭据,
通过 parent_account_id 指向母账号,凭据/token/代理透传自母账号并共享母账号的刷新
周期,仅在配额维度(quota_dimension=spark)和用量窗口上与母账号完全独立调度、互不
连坐。
实现:
- 数据模型:migration 154(+154a)给 accounts 表加 parent_account_id /
quota_dimension 列 + 4 条约束(维度合法 / parent⟺非 global 维度一致 / 禁自指 /
FK)+ 2 个 CONCURRENTLY 索引(母账号索引 + 每母账号至多一个影子的唯一索引)。
- 创建:POST /api/v1/admin/accounts/:id/shadow(CreateShadow)—— 一母一影(唯一
索引兜底并发竞态),继承母账号 proxy/分组/并发/优先级(显式传参可覆盖),默认
model_mapping 恒等映射到 spark(拒绝非 spark 模型),母账号必须是真实的 OpenAI
OAuth 账号(非影子)。
- 凭据透传:resolveCredentialAccount 把影子解析回母账号,GetAccessToken / 请求头
/ WS 三条路径统一走此函数;影子自身 Credentials 恒为空(仅允许写 model_mapping),
凭据写入的汇聚点 persistAccountCredentials 对影子早返 no-op,防止误写。
- 调度:parentHealthyForShadow 只看母账号是否仍是 OpenAI OAuth + 凭据/传输是否
可用(active、token 未过期、未处于 401/刷新失败/传输故障导致的临时不可调度冷却),
刻意不看母账号的 global 限流窗口——两条 429 道互不连坐。
- 用量:影子的 codex_5h/7d 走 OpenAIQuotaService.QueryUsage(/wham/usage 的
codex_bengalfox),与母账号走的 WSv2 探测(/responses 头)完全独立的数据源、
刷新节流与 staleness 判定。
- 备份:ExportData 显式排除影子账号(影子不持凭据,通用凭据型导入强制
credentials 非空、无法表达父子链接),按 skipped_shadows 计数提示前端。
- 前端:账号操作菜单新增“创建 Spark 影子”入口,影子行展示回填的母账号信息
(邮箱 / plan / 隐私模式 / 订阅到期 / chatgpt_account_id),批量操作自动跳过
影子账号。
说明:migrations 目录用完整文件名(而非纯数字前缀)标识迁移,故本次新增的
154_account_spark_shadow.sql / 154a_..._notx.sql 与已有的
154_add_ops_system_logs_api_key_id.sql 按序号共存,与目录里 145/151 已有的
先例一致。
测试:新增约 20 个测试文件,覆盖 handler(CreateShadow 校验 / 母账号信息回填)、
repository(影子 round-trip / 一母一影唯一索引 / 迁移 schema)、service(凭据
透传三路径 / 调度母健康门 / 用量窗口来源与刷新节流 / CRS 母账号不变量 / 各类
早返与 fail-closed 场景)及前端组件(账号列表 / 操作菜单 / 用量重置)。
验证(镜像 CI;golangci-lint 首次全量分析耗时过长被跳过,其余全部实测):
- gofmt -l:干净
- go build ./... / go vet ./...:通过
- go test ./... -count=1:全绿(全部包 ok,含 internal/service、
internal/repository、migrations)
- go test -tags integration ./internal/repository/... ./internal/service/...
(真实 Postgres,testcontainers):全绿,含迁移幂等性
(TestMigrationsRunner_IsIdempotent_AndSchemaIsUpToDate)与影子相关全部用例
- pnpm lint:check / pnpm typecheck / pnpm build(真实 vite 构建)/
pnpm vitest run:全绿(124 文件 760 用例)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com >
2026-07-01 12:21:45 +08:00
Heatherm Huang
2fe756e4be
fix: recognize grok media models
2026-07-01 11:43:35 +08:00
Heatherm Huang
3b5d812f7a
fix: route grok media endpoints
2026-07-01 11:43:35 +08:00
shaw
59e9356c51
feat: 抹除 Anthropic OAuth 请求中客户端 dateline 隐写指纹
...
对 /v1/messages 转发到 Anthropic OAuth/setup-token 账号的请求做 dateline
归一化,将 system prompt 与 <system-reminder> 块中 "Today's date is …"
语句里的 4 种撇号变体与 "/" 日期分隔符还原为 ASCII 撇号 + "-",抹除某些
客户端在检测到非官方 base URL 时注入的 3 bit 隐写指纹。API Key 账号不受
影响。新增系统设置开关 enable_client_dateline_normalization,默认开启。
2026-07-01 10:54:18 +08:00
deqiying
03727ac363
fix(subscription): 修复订阅撤销软删除失效
...
总: 增加明确的订阅撤销接口,修复撤销后的缓存失效和管理端 revoked 展示。
分: 同步失效订阅 L1 与 billing cache,补跨实例失效通知、soft-delete-aware 列表查询、revoked_at DTO 字段和回归测试。
2026-07-01 00:37:51 +08:00
PMExtra
cafc95c3e2
feat: align user usage analytics with admin
2026-06-30 15:31:28 +08:00
Wesley Liddick
76e0d90736
Merge pull request #3509 from wucm667/fix/refund-pending-not-success
...
fix(payment): 退款 pending 不再当成最终成功,避免站内账务与网关状态不一致
2026-06-30 13:38:04 +08:00
Wesley Liddick
efb8b45876
Merge pull request #3560 from StarryKira/feat/issue-3557-oauth-email
...
feat: fix OAuth email completion flow
2026-06-30 10:55:00 +08:00
wucm667
93a3bf3077
Fix refund pending finalization gaps
2026-06-30 10:19:50 +08:00
wucm667
7316d83027
fix(payment): 区分退款 pending 并收敛匿名查单
2026-06-30 10:00:48 +08:00
haruka
260fda19b3
feat: fix OAuth email completion flow
2026-06-30 01:11:51 +08:00
Heatherm Huang
10e623f674
fix: allow grok messages compatibility
2026-06-29 18:33:37 +08:00
Heatherm Huang
4a7148e203
fix: support grok cli compatibility routes
2026-06-29 17:53:19 +08:00
Wesley Liddick
d3acd8e96e
Merge pull request #3497 from JRBaggins/fix/openai-count-tokens-bridge
...
Bridge OpenAI count_tokens to responses input_tokens
2026-06-29 15:23:11 +08:00
nslogx
d86e83259e
fix: allow five platform quota updates
2026-06-29 09:40:04 +08:00
Wesley Liddick
c99112a9e9
Merge pull request #3515 from bestony/feat/ops-system-log-key-id
...
feat(ops): add key id filter to system logs
2026-06-29 09:24:40 +08:00
mxyhi
82553c4dca
fix(openai): preserve quota platform in usage billing
2026-06-28 11:13:09 +08:00
Bestony
bad87ff533
feat(ops): add api key filter to system logs
2026-06-27 14:35:19 +08:00
JRBaggins
7a38c66214
Bridge OpenAI count_tokens to responses input_tokens
2026-06-26 17:59:26 +08:00
DaydreamCoding and Claude Opus 4.8
819fda34d9
feat(codex-detect): codex_cli_only 检测加固 + 引擎指纹统一信号列表 + 账号级 app-server
...
将 codex_cli_only 客户端识别从「单一 strict 开关 + 固定 OR 头集合」重构为
可逐项管理的引擎指纹信号列表,加固整条判定链,并补齐账号级 app-server 控制、
对齐前端设置文案。
判定链(每步可短路):
- 账号未开 codex_cli_only → 不限制;gateway.force_codex_cli → 旁路放行
- 全局黑名单命中(OR 宽 deny)→ 立即拒
- 身份候选:官方 UA(strict,仅前缀)/ 官方 originator(OR)/ 全局白名单(双因子 AND)
/ 全局 app-server 开关 OR 账号 app-server 开关;均不命中 → 拒
- 版本门(仅官方候选):UA 须可解析引擎版本,再校验 [min,max] 区间
- 引擎指纹 AND 硬门:按信号列表逐条勾选 AND、每条行内变体 OR;无 Required 信号 → 放行
引擎指纹信号列表(唯一真源)
- 新增 openai.EngineFingerprintSignal 类型 + EvaluateEngineFingerprint 求值器
(勾选 AND / 行内变体 OR / 无勾选 → 放行)
- CodexRestrictionPolicy 增 EngineFingerprintSignals;信号列表单一决定是否启用指纹门,
不再保留独立「要求引擎指纹」总开关(与「信号全不选」语义重复)
- 新设置键 codex_cli_only_engine_fingerprint_signals(默认只勾 x-codex- 前缀);
旧 body 指纹开关幂等迁移并入信号列表;wire 接线
- 黑/白名单自由条目、命名预设、版本区间 全局设置管线
- gateway 缺 settingService(仅测试/误配可达)时指纹门回退默认种子信号、失败关闭,
不再因零值 policy(nil 信号)失败开放
账号级 Codex app-server(替换已失效的 ClaudeCode 放行机制)
- account.IsCodexCLIOnlyAppServerAllowed() 读 extra.codex_cli_only_allow_app_server,
仅在 codex_cli_only 开启时生效;候选身份门「全局 OR 账号」,与旧系统双层控制对齐
- 移除已无入口的 claude_code 预设机制(allowedClientRegistry / MatchAllowedClients /
账号 GetCodexCLIOnlyAllowedClients / reason);白名单 AllowedClientEntry / IsAllowedClientMatch 保留
门加固(反伪 + 写入校验)
- 官方 UA 访问门改 strict:IsCodexOfficialClientRequestStrict 仅前缀匹配,收窄「浏览器前缀 +
中段 codex token」伪造面(strict 仍保留 Codex 家族前缀与 UA 尾部兜底,故对「任意前缀 +
官方尾部 (name;ver)」仍放行——与 UA 可伪造、真正反伪靠引擎指纹门的设计一致)
- 官方客户端识别扩展:新增 codex-tui/、codex_vscode_copilot/ 前缀 + UA 尾部 (name;ver) 兜底
(恢复 CODEX_INTERNAL_ORIGINATOR_OVERRIDE 的真实 client,如 cccc→codex-tui),originator 改
精确集。该识别经 IsCodexOfficialClientByHeaders 被 passthrough 复用,故透传的官方判定一并
修正(codex-tui 等不再被误改写 UA)——非「行为不变」,属有意修正
- 白名单写入校验 ValidateCodexWhitelistEntriesJSON + AllowedClientEntry.IsWhitelistable:
双因子 AND 条目须可命中(非空 originator + 非空 ua_contains),拒绝写入会静默失效的死规则;
黑名单(OR 宽 deny,允许 originator-only)不受约束
管理端 / 前端
- handler / DTO / settings_view / 契约测试;gateway 接入判定链
- 信号列表编辑器(替换 body 开关)、api 类型、SettingsView;无勾选给常驻警告
- Create/Edit/Bulk 三弹窗「Codex Only」下新增 app-server 开关(OR 合并全局)
- 文案:UA/Originator → User-Agent/Originator;黑/白名单重命名为 User-Agent/Originator 黑/白名单;
「允许 App Server 第三方客户端」→「Codex app-server」+ 简介示例;i18n zh/en 同步
- 移除死代码 HasCodex*Fingerprint helper
测试:引擎指纹求值器 / 账号 app-server(OR 语义)/ detector(含 N1 strict、失败关闭)/
白名单写入校验 / BulkEdit spec 等;后端 build + service/openai/admin 单测全绿,前端 vue-tsc + vitest 全绿。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-26 16:19:41 +08:00
shaw
f93a6c50ce
fix: repair CI build & lint regressions on main
...
- openai_gateway_model_availability.go: pass platform through to
listSchedulableAccounts so OpenAI/Grok diagnosis scopes to the
correct candidate pool (build break introduced by Grok subscription
PR #3310 ).
- no_account_error.go: drop redundant context.Context type on
ctx := context.Background() to satisfy staticcheck ST1023.
2026-06-26 16:06:01 +08:00
Wesley Liddick
2fc4fef847
Merge pull request #3310 from heathermhuang/codex/grok-subscription-support
...
feat: add grok subscription support
2026-06-26 15:41:52 +08:00
shaw
fcd3bc1272
fix: return 404 model_not_found instead of 503 when no account supports the model
2026-06-26 15:38:06 +08:00
Heatherm Huang
44f502bab8
fix: address grok review feedback
2026-06-26 14:26:43 +08:00
Wesley Liddick
683a8d8096
Merge pull request #3421 from syx0310/fork/openai-codex-pat-auth-upstream
...
feat: add codex personal access token auth
2026-06-26 11:15:38 +08:00
Heatherm Huang
720db8983f
test: harden grok quota readiness
2026-06-26 10:42:21 +08:00
Heatherm Huang
0d28642181
feat: add grok quota probe parity
2026-06-26 10:37:37 +08:00
Heatherm Huang
e7a4f3f465
test: fix grok oauth validation suite
2026-06-26 10:36:09 +08:00
Heatherm Huang
39be1ec97f
feat: add grok subscription support
2026-06-26 10:36:09 +08:00
wucm667
55242ffac1
fix(admin): 订单金额币种符号读取 currency 字段
2026-06-25 16:23:45 +08:00
syx0310
32df33a1c3
feat: add codex personal access token auth
2026-06-22 16:07:41 +00:00
Wesley Liddick
f597e926da
Merge pull request #3335 from FjlI5/fix/openai-upstream-endpoint-logging
...
fix: 修正 chat-only API-key 账号上游端点被误记为 /v1/responses
2026-06-21 21:12:15 +08:00
Wesley Liddick
7b5fbe5197
Merge pull request #3364 from feitianbubu/fix/promo-clear-expiry
...
fix(promo): allow clearing promo code expiry on edit
2026-06-21 21:12:02 +08:00
wucm667
ecedc7c8d3
fix(auth): enforce email bind suffix whitelist
2026-06-19 21:17:45 +08:00
feitianbubu
2dc1387b59
fix(promo): allow clearing promo code expiry on edit
2026-06-18 23:07:25 +08:00
FjlI5
bab8a9a93e
fix(openai): log /v1/chat/completions upstream endpoint for chat-only API-key accounts
...
DeriveUpstreamEndpoint maps every OpenAI-platform request to /v1/responses, but
API-key accounts whose upstream only speaks Chat Completions
(!ShouldUseResponsesAPI) are forwarded directly to /v1/chat/completions. The
messages, responses and cyber-policy recording sites derived the endpoint via the
bare GetUpstreamEndpoint, so usage/ops records mislabeled those requests as
/v1/responses. Generalize the existing resolveRawCCUpstreamEndpoint into
resolveOpenAIUpstreamEndpoint and use it at every OpenAI recording site, matching
the already-correct chat-completions client path.
2026-06-18 00:29:04 +08:00
Wesley Liddick
7fb3e1aacd
Merge pull request #3247 from alfadb/fix/reasoning-and-thinking-protocol
...
fix(gateway): 整合推理强度与思考协议处理(替代 #2155 / #2136 / #3246)
2026-06-16 20:29:21 +08:00
Wesley Liddick
03ec90a25a
Merge pull request #3223 from feitianbubu/fix/intercept-streaming-haiku-probe
...
fix: 修复CC Switch改为流式测试后请求失败的问题
2026-06-16 20:27:33 +08:00
alfadb
a05d9e87c0
feat(billing): 国产模型 thinking-enabled 自动填充 reasoning_effort 默认值
...
问题:Kimi/GLM/MiniMax 等国产 LLM 协议层只有 thinking on/off 开关,没有
reasoning_effort 档位概念。客户端启用 thinking 后 usage_log.reasoning_effort
长期为 NULL,无法在用量分析里区分 'thinking 开启' 与 'thinking 关闭'。
方案:仅在 'thinking 启用 + 上游属于 passback-required 国产模型 + 客户端
未明确指定 effort' 三者同时成立时,给 usage_log.reasoning_effort 写默认值
'high'(与 DeepSeek thinking-enabled 默认 effort 一致)。
设计原则:
1. **白名单**:仅 ResolveThinkingProtocol == PassbackRequired 集合内,
且排除原生支持 effort 的 DeepSeek(避免覆盖客户端意图)。
2. **fail-open**:客户端显式传 effort 时永远不覆盖。
3. **未来兼容**:如 Kimi 后续加入真 effort 档位,客户端开始发 effort,
guard (3) 自动让出,本逻辑变 no-op。
实现:
- gateway_request.go: 加 DefaultEffortForThinkingEnabled (按模型白名单)
+ OpenAIBodyHasThinkingEnabled (检测 OpenAI 协议 body 里的 thinking.type)
+ ApplyThinkingEnabledFallback (包装现有 extractor 的 nil-then-default 逻辑)
- gateway_handler.go: Anthropic 路径两处(主 + retry)对称补充
- OpenAI 路径全覆盖:openai_gateway_service.go (passthrough + non-passthrough)
+ openai_gateway_chat_completions_raw.go + openai_gateway_responses_chat_fallback.go
+ openai_ws_http_bridge.go + openai_ws_forwarder.go
- 跨协议路径:gateway_forward_as_chat_completions.go (CC client → Anthropic upstream)
+ gateway_forward_as_responses.go (Responses client → Anthropic upstream)
+ gemini_chat_completions_compat_service.go (一致性保持)
未覆盖:openai_ws_v2_passthrough_adapter.go 两处。原因:该 adapter 持有的是
session-level 客户端原始 model,没有 *Account 句柄无法走 GetMappedModel。
WS v2 当前对国产模型场景不重要(pi 调用 Kimi/GLM/MiniMax 走 sync HTTP),
留待后续如果出现 WS v2 + 国产模型用例时单独处理。
测试:
- TestDefaultEffortForThinkingEnabled (14 用例):覆盖 Kimi/GLM/MiniMax 大小写、
Qwen thinking 变体、DeepSeek 排除、Claude/GPT/Gemini 不命中。
- TestOpenAIBodyHasThinkingEnabled (8 用例):covers enabled/adaptive/disabled、
大小写、空 body、缺字段、invalid JSON fail-safe。
- TestApplyThinkingEnabledFallback (9 用例):现有 effort 不覆盖、nil + 启用 +
passback → high、nil + disabled → nil、nil + 启用 + 排除模型 → nil。
2026-06-16 19:37:31 +08:00
shaw
b8a482e127
fix(ci): unblock main after recent merges
...
Three independent CI blockers landed on main from concurrent PR merges:
- openai_quota_service.go (introduced by b8169492 ): const block spacing
not gofmt-compliant + trailing blank line. golangci-lint v2.9 flagged it
on every push after the merge.
- openai_images_failover_test.go (introduced by PR #3155 , da30c599 ):
NewOpenAIGatewayHandler call missing the opsService argument added by
PR #3230 (b62b573f ). Test was authored before #3230 and merged without
rebase, causing "not enough arguments" compile error.
- account_quota_reset_test.go: TestIsFixedDailyPeriodExpired_NotExpired
and TestIsFixedWeeklyPeriodExpired_NotExpired used time.Now()-1min as
periodStart, which crosses the 09:00 UTC reset boundary when CI runs in
the 09:00:00-09:00:59 window. Anchoring periodStart to today's 12:00
UTC removes the race.
2026-06-16 17:59:06 +08:00
Wesley Liddick
9c2c8ab3e5
Merge pull request #3155 from wucm667/fix/openai-images-server-error-failover
...
fix(openai): 图像接口上游 server_error 触发 failover 换号,不再 5xx 透传
2026-06-16 17:00:40 +08:00
Wesley Liddick
e4ccb75d0f
Merge pull request #3220 from wucm667/fix/oauth-signup-apply-promo-code
...
fix(auth): OAuth 注册支持应用 URL 上的 promo_code 优惠码
2026-06-16 16:59:38 +08:00
Wesley Liddick
2e0ff1cfd5
Merge pull request #3258 from bwliangc/feat/channel-monitor-jitter
...
feat(渠道监控): 检测间隔支持正负随机抖动配置
2026-06-16 16:58:23 +08:00
Wesley Liddick
16765bde69
Merge pull request #3230 from DaydreamCoding/feat/openai-cyber-policy-passthrough
...
feat(openai): cyber_policy 硬阻断全链路透传、审计与计费
2026-06-16 16:55:51 +08:00
shaw
b816949291
feat(openai-quota): query + reset rate-limit credits for OpenAI accounts
...
Adds an admin-side action that mirrors the Codex Desktop "rate-limit reset"
flow against chatgpt.com upstream for OpenAI OAuth accounts.
Backend
- OpenAIQuotaService.QueryUsage / ResetCredit hit /wham/usage and
/wham/rate-limit-reset-credits/consume with the Codex Desktop header set,
reusing OpenAITokenProvider for refreshed tokens and PrivacyClientFactory
for the impersonated Chrome TLS fingerprint.
- Honors the account's configured proxy by reading the eager-loaded
account.Proxy directly (falls back to proxyRepo only when missing).
- GET /api/v1/admin/openai/accounts/:id/quota
POST /api/v1/admin/openai/accounts/:id/reset-quota
- Wire DI for the new service + handler dependency.
Frontend
- OpenAIQuotaResetCell renders a single action row in AccountUsageCell's
OpenAI section: the existing local "查询" (active sampling) is injected
via #pre-actions, alongside a "次数 N" button that doubles as the
upstream query trigger and the available-credit indicator, and a "重置"
button that consumes one credit.
- No duplicate 5h/7d window display; the local UsageProgressBar owns those
bars to avoid confusion.
2026-06-16 16:55:07 +08:00
jjaw
b0579c4891
fix: move user wait queue accounting off hot path
2026-06-16 11:41:54 +08:00