IanShaw027
363cc4994b
fix: SuperGrokPro 用 4.5 窗口区分 Heavy,容量抖动只封单模型
...
JWT 的 SuperGrokPro 同时覆盖 SuperGrok 与 Heavy,账单月额度又滞后,
账号会误升/误降。multi-agent 容量抖动还会把整号提出调度。
- CanonicalGrokPlan:明确 JWT 优先;模糊档仅采新鲜的 grok-4.5 Responses 窗口
- 配额快照写入 plan_from_45_responses 时间戳,过期信号不用
- engine_overloaded 对 multi-agent 只封当前模型 0.5s–5min
2026-08-13 07:49:14 +08:00
IanShaw027
f3d9491071
feat: 分组支持逐模型定价,并可关闭长上下文阶梯
...
运营需要按分组覆盖渠道/内置价,且部分套餐不应自动吃 200k 倍率。
原先只能改渠道价卡,分组侧只剩 Voice 三列。
- groups 新增 model_pricing / long_context_pricing_enabled,解析链改为 Group → Channel → 内置
- 关闭长上下文时 token 模型只取最低档;video 按秒计费可写进同一价卡
- 回退价对齐官方卡:4.5 缓存 $0.30、4.3/imagine/audio/search 默认值一并校正
2026-08-13 07:49:08 +08:00
IanShaw027
69648476d4
fix: 账号徽章与用量格按实时档位展示,避免账单滞后误判
...
订阅失效刷新后凭证已是 free,但残留的 monthly_limit / usage_percent
仍会把用量格锁在付费 7d/30d,徽章也优先信滞后的 billing.plan。
- 凭证 subscription_tier 优先于账单/配额快照
- 用量格先看实时档位,再回退账单指标;Lite 仍走付费条
- 徽章补齐 SuperGrok Lite / Plus / X Basic
2026-08-13 01:23:54 +08:00
IanShaw027
a04ce49016
feat: 新增 grok-4.6 目录、官方定价与请求路径支持
...
官方目录价:<200k 为 $2 / 缓存读取 $0.50 / $6,≥200k 全部 2 倍。
原先没有独立价卡,/models 宣称可配 reasoning 但请求路径会剥掉 effort。
- 目录与别名接入 grok-4.6 / grok-4.6-latest,默认文本模型仍为 grok-4.5
- 独立回退价卡含缓存读取价与 200k 长上下文倍率
- 保留 reasoning_effort;Chat→Responses 的 cache/vision 桥接同样识别 4.6
2026-08-13 01:23:45 +08:00
IanShaw027
bb9e74285e
feat: 从 JWT tier 识别 Grok 订阅档位,刷新后覆盖失效订阅
...
Grok Build access token 带有数字 tier claim(0=free、1=supergrok、5=heavy、6=lite),
原先只解 email/sub/team_id,refresh 还会把旧档位抄回去,订阅失效后一直显示 Heavy。
- 解码 JWT tier,并归一化 display / header 别名(含 free-tier、SuperGrok Lite)
- 仅从 access token 读取档位;新 JWT 覆盖已存凭证,AT 无 claim 时保留旧值
- 用量与 free-cache 判定以当前 AT 为准,账单月额度仅作降级
2026-08-13 01:23:37 +08:00
shaw
5935e674a8
chore: update sponsors
2026-08-12 19:17:04 +08:00
github-actions[bot]
ef4f99f292
chore: sync VERSION to 0.1.175 [skip ci]
2026-08-12 11:07:43 +00:00
Wesley Liddick
93c32fa1a2
Merge pull request #5553 from Wei-Shaw/feat/codex-fingerprint-convergence
...
feat: Codex OAuth 设备指纹收敛
v0.1.175
2026-08-12 18:52:01 +08:00
shaw
04f8cdb194
fix: 修复 golangci-lint errcheck 和 gofmt 格式问题
2026-08-12 18:20:54 +08:00
shaw
c0ab3a00ea
feat: Codex OAuth 设备指纹收敛,减少上游可见的设备数和会话数
...
多人共享同一 OAuth 账号时,各用户 Codex 客户端携带各自不同的 installation_id/session_id/thread_id,
上游据此判定设备数和会话数并限制配额。本功能将这些标识改写为账号级恒定值。
四档策略(账号级 extra 字段 codex_fingerprint_mode):
- off: 不做任何收敛,原样透传
- device: 仅收敛 installation_id
- session(默认): 收敛 installation_id + session_id,thread_id 按客户端原始 session 派生
- full: 收敛所有标识(installation_id + session_id + thread_id)
改写覆盖 6 个指纹载体:x-codex-turn-metadata 头(JSON 内部字段)、x-codex-window-id、
x-codex-installation-id、x-client-request-id、session-id/session_id/thread-id、
请求体 client_metadata。头和体共享同一份预计算 IDs 确保 turn_id 等随机字段一致。
2026-08-12 17:57:50 +08:00
Wesley Liddick
4ec9ceec4a
Merge pull request #5508 from pcmid/fix/show-security-audit-menu-in-simple-mode
...
fix(frontend): show security audit menu in simple mode
2026-08-12 10:01:20 +08:00
Wesley Liddick
46cbb7187b
Merge pull request #5531 from SamizuHM/fix/openai-compat-nested-data-usage
...
fix(openai-compat): parse usage from nested data envelopes
2026-08-12 10:01:09 +08:00
Wesley Liddick
80acae16fa
Merge pull request #5525 from Fool0ntheHill/codex/fix-openai-visible-ttft
...
fix(openai): record Responses TTFT on visible output
2026-08-12 09:59:52 +08:00
Wesley Liddick
19c6007a22
Merge pull request #5342 from wucm667/fix/issue-5340-ws-v2-terminal-ttft
...
fix(openai-ws): exclude terminal events from TTFT
2026-08-12 09:59:43 +08:00
Wesley Liddick
0ed1a9f22a
Merge pull request #5514 from wucm667/fix/issue-5510-cyber-policy-audit-scope
...
fix(audit): scope cyber policy events
2026-08-12 09:58:32 +08:00
Wesley Liddick
a29fce4a61
Merge pull request #5511 from wucm667/fix/pr-5234-ws-audit-logging
...
fix(security-audit): restore websocket audit logs
2026-08-12 09:58:24 +08:00
Wesley Liddick
1225437099
Merge pull request #5502 from pyt111/codex/fix-account-stats-service-tier
...
fix: 修复 service tier 账号成本统计
2026-08-12 09:58:16 +08:00
Wesley Liddick
5192abb6b5
Merge pull request #5503 from fengshao1227/fix/openai-html-403-not-account-penalty
...
fix(openai): 上游 HTML 403 不再被当成账号级错误处罚账号
2026-08-12 09:58:08 +08:00
Wesley Liddick
40aae11888
Merge pull request #5513 from wucm667/fix/issue-5506-gemini-exclusive-minimum
...
fix(gemini): normalize exclusive minimum tool schemas
2026-08-12 09:57:52 +08:00
Wesley Liddick
177bf30867
Merge pull request #5527 from creamtea47/codex/ops-memory-capacity-display
...
fix: 优化运营监控内存容量显示
2026-08-12 09:57:45 +08:00
Wesley Liddick
d76c1af759
Merge pull request #5535 from feitianbubu/fix/account-scheduling-threshold-i18n-nesting
...
fix(i18n): move account scheduling threshold keys out of status block
2026-08-12 09:54:47 +08:00
wucm667
da283854f6
chore: retry CI after registry timeout
2026-08-12 02:25:00 +08:00
feitianbubu
670b03f7e7
fix(i18n): move account scheduling threshold keys out of status block
2026-08-12 00:10:34 +08:00
SamizuHM
a163742fc9
fix(openai): preserve usage path precedence
2026-08-11 22:01:47 +08:00
SamizuHM
04dc540b23
fix(openai): parse nested data usage envelopes
2026-08-11 18:15:31 +08:00
NellPoi
943f09d357
fix: 优化运营监控内存容量显示
2026-08-11 17:34:58 +08:00
Fool0ntheHill
900194fab2
fix(openai): 修正 Responses 可见输出 TTFT
2026-08-11 16:31:09 +08:00
wucm667
662444774f
test(gemini): check cleaned schema assertions
2026-08-11 16:19:18 +08:00
wucm667
e24cb99b79
fix(openai-ws): retain no-delta TTFT fallback
2026-08-11 16:01:34 +08:00
Wesley Liddick
1e618dbc29
Merge pull request #5054 from wucm667/fix/issue-5029-openai-passthrough-pool-auth-retry
...
fix(openai): retry pool auth failures before failover
2026-08-11 14:21:45 +08:00
shaw
a3bbf35cbd
Merge branch 'main' into fix/issue-5029-openai-passthrough-pool-auth-retry
...
Resolve conflict in backend/internal/handler/openai_gateway_handler_test.go.
main and this branch each appended a passthrough upstream stub plus a test at
the same two insertion points:
main openAIHTTPPassthroughSSERateLimitUpstream
TestOpenAIResponses_APIKeyPassthroughSSERateLimitUsesConfiguredPoolRetry
branch openAIHTTPPassthroughAuthFailoverUpstream
TestOpenAIResponses_APIKeyPassthroughPoolAuthFailureRetriesThenSwitchesToHealthyAccount
Both sides are kept verbatim; the only edit is giving each stub its own
calls() body instead of sharing the trailing one. No assertion was changed.
openai_gateway_passthrough.go and openai_oauth_passthrough_test.go merged
automatically.
2026-08-11 14:09:07 +08:00
Wesley Liddick
caa1abb13a
Merge pull request #5404 from wucm667/fix/issue-5400-oauth-image-stream-error
...
fix(openai): fail over OAuth image stream errors
2026-08-11 14:04:42 +08:00
Wesley Liddick
574dfad2dc
Merge pull request #5488 from wucm667/fix/issue-5482-stale-codex-threshold
...
fix(openai): skip stale and reset Codex snapshots in scheduling threshold evaluator
2026-08-11 14:00:33 +08:00
Wesley Liddick
bc0a6a7039
Merge pull request #5480 from scp-planet/fix/admin-usage-request-id-column
...
修复管理端使用记录请求 ID 列显示 / Restore admin usage request ID column visibility
2026-08-11 14:00:07 +08:00
Wesley Liddick
6876477371
Merge pull request #5304 from wucm667/fix/issue-5302-chat-reasoning-alias
...
fix(apicompat): accept chat reasoning alias
2026-08-11 13:59:49 +08:00
Wesley Liddick
b918874f81
Merge pull request #5403 from cyhhao/fix/codex-capacity-exponential-backoff
...
fix(openai): back off capacity retries exponentially
2026-08-11 13:58:06 +08:00
Wesley Liddick
20a2d12dde
Merge pull request #5415 from Yuxin-Qiao/fix/openai-responses-empty-completed-failover
...
fix(openai): fail over empty response.completed streams instead of recording 0/0 success
2026-08-11 13:53:43 +08:00
Wesley Liddick
ca9e2b48ee
Merge pull request #5413 from Yuxin-Qiao/fix/openai-responses-reasoning-item-id
...
fix(openai): strip invalid reasoning item IDs in API key passthrough
2026-08-11 13:53:05 +08:00
Wesley Liddick
e499a54a9d
Merge pull request #5449 from hongheshan-svg/docs/fix-stale-go-golangci-versions
...
docs: sync Go 1.26.5 / golangci-lint v2.9 versions with CI
2026-08-11 13:52:35 +08:00
wucm667
6564d376e5
fix(audit): scope cyber policy events
2026-08-11 13:05:56 +08:00
wucm667
c8d9af6ce1
fix(gemini): normalize exclusive minimum tool schemas
2026-08-11 12:34:51 +08:00
wucm667
2d9920ba7d
fix(security-audit): restore websocket audit logs
2026-08-11 11:56:46 +08:00
pcmid
0d7b6ae64c
fix(frontend): show security audit menu in simple mode
...
The security audit group (Risk Control + Prompt Audit) was hidden from
the sidebar via `hideInSimpleMode`, but nothing else in the stack
restricts it in simple mode:
- `router/index.ts` simple-mode `restrictedPaths` does not cover
`/admin/risk-control` or `/admin/prompt-audit`
- the `/risk-control` and `/prompt-audit` admin route groups have no
`RunMode` gate, and neither does `internal/securityaudit/` nor
`service/content_moderation.go`
- `SettingsView.vue` renders the risk control toggle together with a
`<router-link to="/admin/risk-control">` shortcut, and the settings
page stays visible in simple mode
The feature is therefore fully usable in simple mode and already
reachable through the settings page — only the sidebar entry was
missing. Drop the flag so the menu matches actual behaviour.
The group remains gated by `risk_control_enabled` (opt-in, default
false) through `featureFlag: flagRiskControl`.
2026-08-11 11:27:49 +08:00
li
12abb54700
fix(openai): 上游 HTML 403 不再被当成账号级错误处罚账号
...
上游代理 / CDN 在请求到达 OpenAI API 之前拦下时,回的是 HTML 403 页面而不是
{"error":{...}} 结构化错误。这类响应描述的是「这条链路 / 这个端点被挡了」,
不构成账号凭据或权限失效的证据。
但 handleOpenAI403 不区分响应形态,一律按账号级 403 处理:
- 首次即 SetTempUnschedulable,账号 10 分钟不可调度;
- 连续 openAI403DisableThreshold(3) 次直接 SetError 永久禁用账号;
- 403 又在 failover 状态集里,同一个坏请求会被逐个账号重放。
结果是一个请求级错误被放大成整组账号下线。issue #5334 给出的触发方式是
POST /v1/responses/not-exist —— 该路径能通过只做结构校验的 guardResponsesSubpath,
转发后拿回 HTML 403,任何持有 API Key 的调用方重复几次即可打穿一个分组。
附带问题:整张 HTML 页面会被拼进账号错误信息写库并显示在管理端。
仓库对这类响应早有明确口径,只是没有应用到这条路径:
- openai_gateway_count_tokens.go 的 isOpenAIOAuthInputTokensUnsupported 已把
「HTML 403 page without a structured error」按端点级响应处理;
- shouldApplyOpenAIAlphaSearchAccountErrorSideEffects 的既定不变式是
端点级错误只换号、不写账号错误状态。
本次复用现成的 isHTMLResponse,在 handleOpenAI403 入口跳过账号处罚:不递增
连续 403 计数、不设临时不可调度、不永久禁用。failover 行为不变 —— 换一个走
不同代理的账号仍有可能成功。
Fixes #5334
2026-08-11 10:18:20 +08:00
pyt111
9261dd7734
[verified] fix: apply service-tier pricing to account cost
2026-08-11 09:55:19 +08:00
Wesley Liddick
0f73203e35
Merge pull request #5277 from Pluviobyte/agent/fix-grok-missing-usage-billing
...
fix: reject Grok responses without billable usage
2026-08-11 09:28:43 +08:00
Wesley Liddick
e2d9034d3d
Merge pull request #5327 from fengshao1227/fix/fingerprint-user-agent-validation
...
fix(identity): validate user-agent before persisting account fingerprint
2026-08-11 09:28:27 +08:00
Wesley Liddick
ba4bd0c0b4
Merge pull request #5481 from fengshao1227/fix/responses-deterministic-400-passthrough
...
fix(openai): 原生 Responses 路径不再把上游确定性 400 归一成可重试 502
2026-08-11 09:27:34 +08:00
Wesley Liddick
61acf29125
Merge pull request #5501 from wucm667/fix/issue-5500-unset-scheduling-thresholds
...
fix(settings): cache unset scheduling thresholds
2026-08-11 09:27:22 +08:00
wucm667
3e1674a060
fix(settings): cache unset scheduling thresholds
2026-08-11 04:34:49 +08:00