mirror of
https://github.com/Wei-Shaw/sub2api.git
synced 2026-09-24 16:05:44 +08:00
Members of the same ChatGPT team share chatgpt_account_id, so matching imports by the account key first could overwrite another member's account credentials. Identity keys are now ordered by strength (user > email > access > account), and an account-key hit is rejected when both sides carry different chatgpt_user_id values. - Keep the account-key fallback when either side lacks a user id, so legacy accounts without chatgpt_user_id are updated and backfilled instead of duplicated - Index all candidate accounts per shared key so a teammate's row can no longer shadow a legacy account depending on row order - Apply the same conflict check to in-batch dedup and emit a warning when a legacy account is claimed via the shared account key - Scope a 120s timeout to the Codex session import request instead of raising the global client timeout