song
988d4b577e
feat(openai): add macOS Live attestation
2026-07-25 12:50:46 +08:00
song
ec23716ee4
fix(openai): align Live request metadata
2026-07-25 12:50:46 +08:00
song
e6eb23eaac
feat(openai): add Live gateway support
2026-07-25 12:50:46 +08:00
Wesley Liddick
37ed639d1e
Merge pull request #4852 from Wei-Shaw/fix/bump-postcss-audit
...
fix(security): 升 postcss 到 >=8.5.18 修复 frontend-security 红灯
2026-07-25 12:01:42 +08:00
shaw
a5aae5db9a
fix(security): 升 postcss 到 >=8.5.18 修复 frontend-security 红灯
...
新披露两条 high 级公告命中锁文件里的 postcss@8.5.6,frontend-security 的
audit exception 检查失败:
- GHSA-6g55-p6wh-862q(2026-07-23 披露,修复版 8.5.12)
CSS 注释中攻击者可控的 sourceMappingURL 导致任意文件读取与信息泄露
- GHSA-r28c-9q8g-f849(2026-07-24 披露,修复版 8.5.18)
Previous Source Map 自动加载存在路径穿越,导致任意 .map 文件泄露
postcss 不只是 devDependency —— 它经 vue → @vue/compiler-sfc 进入生产依赖树,
因此 `pnpm audit --prod` 会命中。用 pnpm.overrides 而非只升直接依赖,可保证
所有引入路径的实例都被抬到修复版(沿用本仓 form-data@<4.0.6 的既有写法)。
锁文件用 pnpm 10 重新解析以匹配现有锁文件的生成工具,避免 pnpm 9 误删
11 处 libc: [glibc|musl] 平台门控字段;lockfileVersion 保持 9.0。
实际解析到 postcss 8.5.23,nanoid 3.3.11→3.3.16 是 postcss 自身依赖的
补丁级跟随,diff 无其他无关变动。
验证:复现 CI 失败步骤(pnpm audit --prod --audit-level=high +
tools/check_pnpm_audit_exceptions.py)已通过;CI 所用 pnpm 9 的
--frozen-lockfile 接受该锁文件;vue-tsc --noEmit、pnpm build、vitest 均通过。
2026-07-25 11:45:42 +08:00
shaw
6c9b84cc7a
feat: 适配 Anthropic 新模型 claude-opus-5
...
模型登记:/v1/models 清单、Bedrock 默认映射(us.anthropic.claude-opus-5-v1)、
定价条目($5/$25 per MTok、1M 上下文、128K 输出)、前端模型清单与
Anthropic/Bedrock 预设映射、限流 scope 简称。
同时修复两个会静默出错的问题:
- 定价家族兜底 3 倍超收:定价数据缺 claude-opus-5 时,matchByModelFamily
的 Phase 2 关键字兜底会落到 opus-4 系列、getFallbackPricing 会落到
claude-3-opus,两条路都按 $15/$75 计费(官方 $5/$25),输入输出双双
3 倍超收且无任何报错。两处补 opus-5 家族并回退到同价的 4.8;判断用
opus-5/opus5 子串而非裸 "5",避免误伤 claude-opus-4-5。顺带补齐兜底表
缺失的 claude-opus-4.8(此前同样会掉到 claude-3-opus)。
- Bedrock 版本闸门降级:claudeVersionRe 强制要求 major-minor 两段版本号,
只有主版本号的 claude-opus-5 / claude-sonnet-5 完全不匹配,被当成旧模型:
isBedrockOpus47OrNewer 假导致 thinking.enabled 不转 adaptive(Opus 5 上游
已移除 budget_tokens,透传直接 400)、isBedrockClaude45OrNewer 假导致
cache_control.ttl 被剥离、bedrockModelSupportsToolSearch 假导致 tool search
被过滤。改为 minor 可选(缺省 minor=0),claude-sonnet-5 的同一问题一并修复。
Vertex 无需改动:normalizeVertexAnthropicModelID 只处理 -YYYYMMDD→@YYYYMMDD,
无日期后缀的裸 ID 原样透传即正确。context-1m-2025-08-07 白名单不动:Opus 系
上游不接受该 beta,且 Opus 5 的 1M 上下文是默认能力。
Antigravity 暂不接入:无上游支持证据,mapAntigravityModel 对未映射模型返回
空字符串即"该账号不支持",fails closed 安全。
回归测试 internal/service/claude_opus5_test.go 覆盖定价两层兜底、Bedrock
三个闸门、thinking 转换与模型清单;逐个回退上述修复已确认测试会红。
2026-07-25 11:22:42 +08:00
github-actions[bot]
cb24522dd5
chore: sync VERSION to 0.1.164 [skip ci]
2026-07-23 09:54:18 +00:00
Wesley Liddick
cd8bb98c44
Merge pull request #4774 from superman2003/fix/issues-4763-4765-4769-20260723
...
fix: optimize Codex identity imports and OpenAI account tests
v0.1.164
2026-07-23 17:38:05 +08:00
shaw
1be6f30188
fix(ollama): 测试仓储到期查询深拷贝消除数据竞争
...
ollamaUsageTestRepo.ListDueOllamaCloudUsageAccounts 返回浅拷贝共享
Extra/Credentials map,RunDue 过滤循环的无锁读与组写协程在 r.mu 下的
map 删改构成数据竞争(-race 可复现;无 -race 时也可能触发 runtime
concurrent map read/write fatal 导致 CI 偶发崩溃)。两条返回路径改为
r.mu 下 mergeMap 深拷贝,并补全 ListOllamaCloudUsageGroupAccounts
只拷 Extra 不拷 Credentials 的半克隆,与基类 GetByID 惯例对齐。
生产仓储每次查询返回全新行,不受影响。
2026-07-23 17:14:10 +08:00
shaw
2faa0891e4
fix(ollama): 审计日志不落会话明文并收紧凭证清理守卫
...
- PUT /admin/accounts/:id/ollama-cloud-usage/session 加入审计整体不入库
路由,并把裸键 session 纳入键级脱敏兜底,防止浏览器会话 Cookie 明文
留存 audit_logs.request_body
- UpdateCredentials 的 Ollama 清理分支加顶层 credentials DISTINCT 守卫,
凭证未变化的持久化不再误清 openai 探测快照或重写 NULL extra
2026-07-23 16:43:18 +08:00
Wesley Liddick
3f03c93bc6
Merge pull request #4776 from alfadb/feature/ollama-cloud-usage
...
feat(ollama): 支持 Cloud 官方用量自动刷新
2026-07-23 16:36:59 +08:00
alfadb
5ac4a9fac2
feat(ollama): 支持 Cloud 官方用量自动刷新
2026-07-23 15:50:44 +08:00
Wesley Liddick
2c76506e07
Merge pull request #4734 from wjx2951874/feat/alipay-mobile-precreate-deep-link
...
feat(payment): add mobile Alipay precreate deep link
2026-07-23 14:06:18 +08:00
superman2003
dd5956be5e
fix(openai): prefer concrete GPT-5.6 test model
2026-07-23 13:44:15 +08:00
superman2003
5dfe838c21
fix(admin): optimize Codex identity import index
2026-07-23 13:43:57 +08:00
Wesley Liddick
6aeea70ee0
Merge pull request #4749 from heathermhuang/codex/fix-openai-proxy-stream-quarantine
...
fix(openai): quarantine proxies after incomplete SSE streams
2026-07-23 11:20:01 +08:00
Wesley Liddick
6f7bad3f2f
Merge pull request #4751 from heathermhuang/codex/fix-grok-402-account-cooldown
...
fix(grok): cool down accounts after upstream 402
2026-07-23 11:19:30 +08:00
Wesley Liddick
fbc88edf90
Merge pull request #4750 from heathermhuang/codex/fix-simple-default-grok-image
...
fix(simple-mode): enable images for auto-created Grok default
2026-07-23 11:19:20 +08:00
Wesley Liddick
da5c80e113
Merge pull request #4724 from fengshao1227/fix/passthrough-input-normalize
...
fix(openai): OAuth 透传路径补齐 input 规范化,修复 Input must be a list
2026-07-23 11:19:12 +08:00
Wesley Liddick
09b1309c91
Merge pull request #4755 from wucm667/fix/issue-4754-channel-pricing-model-normalization
...
fix(billing): normalize channel pricing model names
2026-07-23 11:18:10 +08:00
Wesley Liddick
aee9ab36cb
Merge pull request #4721 from superman2003/fix/ccswitch-grokbuild-4720
...
fix(frontend): import Grok keys into Grok Build
2026-07-23 11:18:02 +08:00
Wesley Liddick
31e7ae8195
Merge pull request #4726 from feitianbubu/fix/model-rate-limit-reset-format
...
fix(admin): 模型限流恢复时间进位到天并在提示中补全日期
2026-07-23 11:17:54 +08:00
shaw
ba88cc239c
fix(billing): bill composite alias requests by the concrete forwarded model
...
Composite public aliases (e.g. all/claude) reach the Anthropic/Gemini
billing core via OriginalModel/ChannelMappedModel source overrides.
Unknown aliases resolved to no pricing and silently recorded $0 cost,
while family-word aliases were mispriced by the fallback family match
(Opus traffic billed at the Sonnet fallback rate). The OpenAI path
already guards this via usageBillingModelCandidates; the shared
recordUsageCore had neither the guard nor a fallback.
- composite groups: unless the admin explicitly configured channel
pricing for the alias (OpenRouter-style custom pricing), bill by the
concrete forwarded model
- general safety net: when the selected billing model has no resolvable
pricing at all, fall back to the concrete forwarded model instead of
silently recording $0
- grok media usage records now attribute OriginalModel to the client
requested public alias, consistent with every other endpoint
(billing unaffected: empty BillingModelSource never triggers source
overrides)
Priced traffic and non-composite groups are unaffected.
2026-07-23 10:26:58 +08:00
shaw
90c4f50a5e
fix(admin): restore currency and timestamps in admin plan list response
...
The composite-groups PR (#3581 ) replaced the raw ent SubscriptionPlan
response of GET /admin/payment/plans with a projection struct but
dropped the currency field added by #4323 . PlanEditDialog then read an
undefined currency, sent an empty string on save, and silently wiped
the stored plan currency. Restore currency plus created_at/updated_at
so the projection preserves the full original response shape.
2026-07-23 10:26:46 +08:00
Wesley Liddick
3e5d4af411
Merge pull request #3581 from heathermhuang/codex/composite-groups
...
feat: Add composite group route registry
2026-07-23 10:09:39 +08:00
Heatherm Huang
ca6b192728
fix: preserve composite video content routing
2026-07-23 09:26:43 +08:00
Heatherm Huang
cb81e17fea
test: align composite route contracts after rebase
2026-07-23 09:20:52 +08:00
Heatherm Huang
1c7959d0de
fix: allow composite grok chat completions
2026-07-23 09:20:52 +08:00
Heatherm Huang
1d2dfab86d
fix: allow composite grok messages routing
2026-07-23 09:20:52 +08:00
Heatherm Huang
06e7d12640
Fix composite Grok video status routing
2026-07-23 09:20:52 +08:00
Heatherm Huang
ee332cee64
Fix composite model defaults for linked platforms
2026-07-23 09:20:52 +08:00
Heatherm Huang
2e774a48b3
Align Grok composite example with live model
2026-07-23 09:20:52 +08:00
Heatherm Huang
ce3272c41b
Build composite subscription bucket two
2026-07-23 09:20:52 +08:00
Heatherm Huang
3a683fff55
Fix composite route alias attribution
2026-07-23 09:20:52 +08:00
Heatherm Huang
ff666be530
Fix composite route lint issues
2026-07-23 09:20:18 +08:00
Heatherm Huang
a008b63c16
Add composite group route registry
2026-07-23 09:20:18 +08:00
Heatherm Huang
c8d1e2e16f
Harden composite group product surfaces
2026-07-23 09:19:25 +08:00
Heatherm Huang
ebc1028771
Add composite group routing
2026-07-23 09:19:24 +08:00
shaw
fa2da0409e
chore: update sponsors
2026-07-23 09:04:08 +08:00
wucm667
44093579e9
fix(billing): normalize channel pricing model names
2026-07-22 20:25:27 +00:00
Heatherm Huang
47ad29db3e
fix(openai): quarantine proxies after stream disconnects
2026-07-23 00:12:28 +08:00
Heatherm Huang
33d694b89b
fix(simple-mode): enable images for auto Grok default
2026-07-23 00:08:23 +08:00
Heatherm Huang
ca0d3314cf
fix(grok): cool down accounts after 402
2026-07-23 00:06:04 +08:00
shaw
63cef60594
chore: update sponsors
2026-07-22 22:21:43 +08:00
wjx2951874
7914433011
feat(payment): add mobile Alipay precreate deep link
2026-07-22 19:18:04 +08:00
github-actions[bot]
60013c5f10
chore: sync VERSION to 0.1.163 [skip ci]
2026-07-22 09:08:53 +00:00
feitianbubu
48d58d72ff
fix(admin): 模型限流恢复时间进位到天并在提示中补全日期
2026-07-22 16:57:51 +08:00
li
3e26dfa5bb
style: 统一 input 包装类型为 []any,与正常 OAuth 路径一致
2026-07-22 16:49:31 +08:00
li
851436c552
fix(openai): OAuth 透传路径补齐 input 规范化,修复 Input must be a list
...
openai_passthrough=true 的 OAuth 账号透传路径
(normalizeOpenAIPassthroughOAuthBody) 未对 input 字段做
string→array 转换,导致上游拒绝 "Input must be a list"。
正常 OAuth 路径 (openai_codex_transform.go:290) 已有此逻辑,
透传路径遗漏。补齐三种非数组 input 的规范化:
- string → [{type:"message",role:"user",content:<text>}]
- 空白 string → []
- 单 object → [<object>]
2026-07-22 16:46:29 +08:00
superman2003
a3a1575e9d
fix(frontend): import Grok keys into Grok Build
2026-07-22 16:12:47 +08:00