shaw
287a9f386b
fix: 修复腾讯验证码票据过期与区域切换
2026-08-06 21:27:06 +08:00
shaw
8e102b3a0f
fix: 完善腾讯验证码区域适配与 CSP 白名单
...
修复国内站和国际站 SDK 构造、验证容器、票据重置及动态资源加载问题,并补充认证流程回归测试。
2026-08-06 20:34:37 +08:00
feeeei
26e0a89323
人机验证增加阿里云验证码 2.0
...
沿用腾讯天御验证码引入的多服务商模型:aliyun_captcha_enabled 作为独立
开关,与 Cloudflare Turnstile、腾讯天御三方互斥(保存校验 + 运行时
CAPTCHA_PROVIDER_CONFLICT)。后台「安全与认证」合并为单张人机验证卡片:
总开关 + 服务商单选(Turnstile / 腾讯天御 / 阿里云),选中即启用该家并
关闭其它,落库仍是三个独立开关键,由前端映射保证互斥。
阿里云侧同时支持 aliyun 中国站与国际站(alibabacloud.com):两站前端脚本、
region 取值与服务端 API 完全一致,仅账号与 AccessKey 相互独立,因此由
「服务地域」决定线路即可——中国内地走 captcha.cn-shanghai.aliyuncs.com,
非中国内地(新加坡)走 captcha.ap-southeast-1.aliyuncs.com,AccessKey
取自持有该实例的账号,无需在配置中区分站点。
- AliyunCaptchaService 对称 TencentCaptchaService:服务端校验走官方 SDK
VerifyIntelligentCaptcha,调用异常按 fail-closed 拦截,与 Turnstile
网络错误行为对称;保存设置时真实探测 AK/SK 有效性
- 保护面对齐腾讯扩展入口:VerifyTencentCaptchaIfEnabled 通用化为
VerifyActionCaptchaIfEnabled,OAuth 登录启动、passkey 登录在阿里云
启用时同样拦截;Turnstile 维持既有覆盖不扩大
- 前端 AliyunCaptchaWidget 为表单内预验证按钮(popup 模式),同时暴露
verify() 供 OAuth 启动、passkey 等动作入口程序化弹窗;未预验证直接
提交时弹窗兜底。SDK 按钮绑定异步完成,弹窗未出现前按 tick 重试触发,
并轮询弹窗可见性识别用户关闭
- captchaVerifyParam 复用 turnstile_token 请求字段提交;公开设置下发
aliyun_captcha_enabled / scene_id / prefix / region
- CSP 放行验证码 CDN:script-src/style-src 加 *.alicdn.com
2026-08-04 20:57:15 +08:00
lyen1688
e592c5f9e0
新增腾讯天御验证码认证门禁
2026-08-04 15:09:29 +08:00
shaw
e1b76e2245
fix(codex): normalize load-shed originators to avoid upstream capacity shedding
...
上游 /backend-api/codex 按 Originator 头分桶调度容量:落在降载桶的请求即使返回
HTTP 200,也会立刻推 SSE `event: error`(code=server_is_overloaded)并以
response.failed 收尾。2026-07-29 起 codex-tui 落入降载桶,codex_cli_rs 正常——
判定因子是 originator 而非 User-Agent(codex_cli_rs 配 curl UA 亦可正常返回)。
网关会把该错误判定为瞬时上游故障并冷却账号,对外表现为 Codex 账号频繁过载不可用:
server_is_overloaded → isOpenAITransientProcessingError →
shouldCooldownOpenAITransientUpstreamError → 账号冷却 → 客户端 503。
本项目有三处降载身份来源:浏览器 UA 兜底的默认 UA、客户端透传的真实 TUI 身份、
以及指纹缓存注入探针的 UA。
修复收口在 enforceCodexIdentityHeaders——HTTP / 透传 / WS 握手 / compat 桥接 /
探针 / PAT / 模型列表 / alpha-search 八条出站路径共用的唯一纯函数收口点:
- 新增 NormalizeCodexClientIdentityToCLI,把降载桶身份改写为 codex_cli_rs,
只替换身份段并裁掉尾部 (name; version) 客户端标识组,保留版本 / OS / 架构 /
终端指纹;改写后 originator 与 UA 首段仍然配套,不破坏 #3901 的配对不变式,
且改写幂等。
- DefaultOpenAICodexUserAgent 从 TUI 身份改为 CLI 身份(浏览器兜底路径上最大的
降载身份来源)。
- 管理端 Codex UA 的 placeholder / hint 原本在把管理员往降载桶引导,一并修正。
新增 gateway.disable_codex_originator_normalization(默认 false,即归一化开启),
供上游调整分桶后回滚。该开关经 NewOpenAIGatewayService 发布为进程级快照,故必须
保持反义命名:正向命名的 Go 零值 false 会让未经 viper 加载而手工构造的 Config
静默关掉全局保护,viper.SetDefault 救不了这条路径。已加用例钉住该属性。
降载桶集合是上游容量策略快照而非协议常量,上游调整分桶后需同步修订。
2026-08-02 23:00:12 +08:00
shaw
da49ce3f29
fix(openai): fail open proxy stream circuit and collapse burst disconnects
...
The proxy stream circuit introduced in v0.1.164 (#4749 ) removes every
account behind a quarantined proxy from scheduling. When all schedulable
accounts share one proxy (a common deployment), two mid-stream
disconnects within a minute zeroed out capacity for 10 minutes and every
request failed with 502. One HTTP/2 connection loss also killed all
multiplexed streams at once, tripping the threshold from a single event.
- Quarantine now degrades to a preference: when the only reason no
account is available is proxy quarantine, selection retries once with
the quarantine bypassed, so capacity can never reach zero.
- Disconnects within 3s per proxy collapse into one failure event.
- Add gateway.openai_proxy_stream_circuit.disabled escape hatch.
- A completed stream still clears the quarantine immediately; TTL,
thresholds and recording guards are unchanged.
2026-07-31 10:30:30 +08:00
Wesley Liddick
2e432173f7
Merge pull request #4920 from alexj11324/feat/passkey-auth
...
feat: add passkey authentication
2026-07-28 14:58:37 +08:00
alfadb
7e65eafbe4
feat: add Kimi K3 support
2026-07-28 10:08:39 +08:00
Zhixuan Jiang
cc62979aa7
feat: add passkey authentication
2026-07-26 09:50:28 -04:00
song
e6eb23eaac
feat(openai): add Live gateway support
2026-07-25 12:50:46 +08:00
Heatherm Huang
47ad29db3e
fix(openai): quarantine proxies after stream disconnects
2026-07-23 00:12:28 +08:00
Jingru Shi
49200d4747
fix(config): support Redis ACL username
2026-07-21 01:31:46 +08:00
Jlypx and Sisyphus
6becd11e39
docs: 更新客户端 IP 边缘安全配置
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-20 00:10:32 +08:00
Jlypx and Sisyphus
41b58b640a
docs: 更新可信代理部署说明
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-07-19 21:42:33 +08:00
Jlypx
732aeef880
fix: 兼容反代和 Docker 客户端 IP 解析
2026-07-19 19:41:01 +08:00
Wesley Liddick
774ff5d8c8
Merge pull request #4515 from BenjaminAaron196/feat/filter-noise-rejected-requests
...
(fix) 过滤入口拒绝日志并强化鉴权安全边界
2026-07-18 20:46:50 +08:00
wucm667
8b75dd5576
docs: clarify OpenAI WS mode router prerequisite
2026-07-18 08:37:15 +08:00
benjamin
b92bbf0299
fix: 过滤入口拒绝日志并强化鉴权边界
2026-07-18 00:11:18 +08:00
haruka and Claude Opus 4.8
0eb6e21aaa
feat: 异步图片任务结果落对象存储
...
为异步生图任务增加 S3 兼容对象存储支持,任务结果不再把大图内联存进 Redis:
- 新增可插拔接口 service.ImageStorage(Save -> url),适配别的厂商只需实现它
- S3 实现 S3ImageStorage(AWS S3 / R2 / 阿里云 OSS / MinIO),与备份共用 S3 客户端构造
- 新增 image_storage 配置(config.yaml + IMAGE_STORAGE_* 环境变量),默认关闭
- enabled 同时作为总开关:关闭或未配置对象存储时,异步生图接口返回 404 且不写
Redis,从根上避免几 MB 的 b64_json 结果撑爆 Redis
- 完成时把图片上传对象存储并把结果改写为短链接(公开直链或 presigned),
上传失败则任务标记为失败
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01SM1tf3CFVRzC7guuhBXvMd
2026-07-15 19:57:37 -07:00
Tian Lee
90ee85f3ef
feat: 按上游计费倍率调度 OpenAI 账号
2026-07-16 00:40:46 +08:00
Wesley Liddick
0de768e8be
Merge pull request #4221 from heathermhuang/codex/fix-grok-oauth-pool-health
...
fix(grok): refresh OAuth pools proactively
2026-07-15 16:07:09 +08:00
Wesley Liddick
bac925624f
Merge pull request #4289 from Tiantianr/fix/openai-ws-first-message-timeout
...
fix(openai-ws): make first-message timeout configurable
2026-07-15 15:45:24 +08:00
王鹏
fc4089f292
fix(openai): bound native responses first output wait
...
Add an opt-in first semantic output budget for native HTTP Responses, including response-header wait. Keep preamble and keepalive bytes non-semantic so a stalled account can fail over once without replaying its response IDs. Defaults remain disabled.
Related to #4201 , #4185 , and #4248 . Complements the HTTP/2 dead-connection fix in #4207 .
2026-07-15 13:01:16 +08:00
Heatherm Huang
6b25900403
fix(grok): refresh OAuth pools proactively
2026-07-15 09:40:08 +08:00
Tiantianr
74e296703a
fix(openai-ws): make first-message timeout configurable
...
Add a dedicated client first-message timeout while preserving the legacy 30-second default.
Use the resolved value for both the WebSocket read deadline and structured timeout logs, and document tuning for large requests or slow links.
Add configuration, validation, handler, and resolver regression coverage.
Refs #4158
2026-07-14 22:40:05 +08:00
Wesley Liddick
c361b0606d
Merge pull request #4219 from zh239ns/codex/fix-openai-images-nonstream-keepalive
...
fix(images): add opt-in non-stream JSON keepalive
2026-07-14 11:30:28 +08:00
zh239ns
002c0b9fda
fix(images): keep non-stream requests alive
2026-07-14 07:39:21 +08:00
bestony and multica-agent
54d228dda5
feat(admin): add opt-in server timing metrics
...
Co-authored-by: multica-agent <github@multica.ai >
2026-07-14 01:29:30 +08:00
Bestony@Homelab
c8cfc93632
fix(openai-ws): bound ingress session lifecycle
2026-07-13 15:32:42 +08:00
shaw
498f010ec3
fix(部署): 统一 Docker 部署 URL 安全默认值为开发友好模式
...
docker-compose.yml / docker-compose.local.yml 中
SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP 与
SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS 的兜底值由 false 改为 true,
与代码默认值(0c7a58fc)保持一致,避免未配置 .env 的 Docker 部署
在测试账号连接时因 http base URL 报 "invalid url scheme: http"。
同步更新 README(三语)、.env.example、config.example.yaml 中
过时的"默认拒绝 HTTP"描述,改为默认允许并指导生产环境显式收紧。
2026-07-04 13:51:37 +08:00
zy6p
901958ba1b
feat(openai-ws): add http_bridge ingress mode and account ws selector
...
(cherry picked from commit 58647ff63d7ff994c7c14c84c4913a8d3ed6be05)
(cherry picked from commit 9f18fb7c24e187fb20e90d1d9e89fcec91c56937)
2026-06-30 10:40:05 +08:00
Wesley Liddick
7c857bd080
Merge pull request #3441 from deqiying/feature/openai-quota-headroom-scheduler
...
新增 OpenAI 剩余额度调度权重
2026-06-29 09:23:32 +08:00
deqiying
a2cf297d90
feat: 新增 OpenAI quota headroom 调度权重
2026-06-24 00:13:22 +08:00
wucm667
9f5b57fc96
fix(billing): 防止余额计费持续透支
2026-06-22 10:30:27 +08:00
kangjwme
510adf703c
feat(scheduling): add opt-in "prefer soonest reset" account selection
...
Adds a use-it-or-lose-it scheduling strategy: prefer accounts whose
session window resets soonest, so near-reset accounts get drained first
instead of accounts whose reset is still far away.
Both schedulers, opt-in, default behavior unchanged:
- Anthropic (gateway_service.go): new GatewaySchedulingConfig
.PreferSoonestReset flag. When on, the layered load-aware selection
inserts a filterBySoonestReset stage (priority -> soonest-reset ->
load -> LRU). Accounts with no active SessionWindowEnd are treated as
lowest priority; ties fall through to LRU.
- OpenAI/Codex (openai_account_scheduler.go): new "reset" score weight
in GatewayOpenAIWSSchedulerScoreWeights. Soonest-reset accounts score
higher; weight defaults to 0 (no effect).
SessionWindowEnd (upstream 5h/quota ResetsAt) is already carried in the
scheduler snapshot, so no snapshot changes are needed.
Documented in deploy/config.example.yaml. Adds unit tests for the
Anthropic filter and the OpenAI reset factor.
2026-06-18 22:50:46 +08:00
wucm667
415d08f255
fix(scheduler): add sticky health escape
2026-05-29 10:25:26 +08:00
Wesley Liddick
bebc082306
Merge pull request #2766 from DaydreamCoding/feat/user-platform-quota
...
feat(quota): 用户 × 平台 USD 配额
2026-05-26 14:13:18 +08:00
mt21625457
33ac8eb27d
fix openai http2 response header timeout
2026-05-26 13:57:59 +08:00
DaydreamCoding and Claude Opus 4.7
6b39b344d8
feat(quota): 用户 × 平台 USD 配额
...
为用户在 anthropic/openai/gemini/antigravity 四个平台上提供日/周/月
三个窗口的 USD 配额管控。配额语义:未设置=不限制,0=禁用,>0=美元上限。
两层模型:
- 配置层:系统默认配额,以及 email/linuxdo/oidc/wechat/github/google/
dingtalk 七个鉴权来源的默认配额,存于 settings,以嵌套 JSON 整体读写
(系统 1 个 key + 每个来源 1 个 key),整体替换语义。
- 运行时层:user_platform_quota 表按用户记录实际配额,与配置层解耦。
后端:新增 ent schema 与 140_user_platform_quotas.sql 迁移、repository
与 service 端口、计费链路集成、管理端与用户端读写接口。
前端:管理端设置页配额编辑、用户配额管理 Modal、用户 Dashboard 展示、
中英文案。
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-26 10:49:20 +08:00
shaw
1e406fed52
fix: optimize OpenAI account cooldown scheduling
2026-05-23 10:18:43 +08:00
shaw
b23055af5b
feat: add Airwallex payments and multi-currency support
2026-05-11 11:17:26 +08:00
Jlypx and Sisyphus
9c1f207bff
docs: document Codex image bridge switch
...
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-05-07 00:10:20 +08:00
shaw
11ae6f2105
fix(rate-limit): remove 429 cooldown config option
2026-05-05 20:11:12 +08:00
Wesley Liddick
37f7c7128c
Merge pull request #2120 from gaoren002/fix/rate-limit-429-cooldown-config
...
fix(rate-limit): make 429 fallback cooldown configurable
2026-05-05 19:46:11 +08:00
2ue
6faa344916
feat: add OpenAI image generation controls
2026-05-05 03:26:54 +08:00
gaoren002
4b904c887c
fix(rate-limit): make 429 fallback cooldown configurable
2026-04-30 03:01:39 +00:00
IanShaw027
9de7a72cce
fix(upgrade): close payment and oidc compatibility gaps
2026-04-22 18:01:51 +08:00
Wesley Liddick
bbc79796dc
Merge pull request #1529 from IanShaw027/feat/group-messages-dispatch-redo
...
feat: 为openai分组增加messages调度模型映射并支持instructions模板注入
2026-04-09 21:14:38 +08:00
Wesley Liddick
74302f60ab
Merge pull request #1010 from Glorhop/pr/oidc-login
...
feat(auth): support OIDC login and prefer IdP real email on sign-in
2026-04-09 21:13:22 +08:00
IanShaw027
4de4823a65
feat(openai): 支持messages模型映射与instructions模板注入
2026-04-09 12:29:49 +08:00