Resolve conflict in backend/internal/handler/openai_gateway_handler_test.go.
main and this branch each appended a passthrough upstream stub plus a test at
the same two insertion points:
main openAIHTTPPassthroughSSERateLimitUpstream
TestOpenAIResponses_APIKeyPassthroughSSERateLimitUsesConfiguredPoolRetry
branch openAIHTTPPassthroughAuthFailoverUpstream
TestOpenAIResponses_APIKeyPassthroughPoolAuthFailureRetriesThenSwitchesToHealthyAccount
Both sides are kept verbatim; the only edit is giving each stub its own
calls() body instead of sharing the trailing one. No assertion was changed.
openai_gateway_passthrough.go and openai_oauth_passthrough_test.go merged
automatically.
Three guards on the response_model billing basis, all scoped to the opt-in
channel mode so existing channels are unaffected.
1. Per-unit billing gate was stale. Audio (AudioUsage) and the search
surcharge (SearchCount) reached the billing paths after this branch was
cut; both are priced per unit rather than per token, so they must be
excluded like image/video/web-search already are. Audio pricing ignores
the model entirely, so the previous code "adopted" a basis switch that
changed nothing and emitted a misleading audit log for it.
2. Never zero out a billable request. A catalog entry whose token prices are
explicitly 0 still passes the identified-pricing gate (TokenPricingAbsent
only means both prices are missing), so an upstream could declare a free
model name and drop the bill to zero. Reject a zero (or negative)
recomputation whenever the baseline was billable; an already-zero baseline
is unaffected.
3. Never cross from channel pricing to the global table. Channel pricing
matches exact keys and prefix wildcards and does not strip date suffixes,
while the global table's identified lookup does. Upstreams routinely
declare dated model IDs (claude-opus-4-5-20251101), so allowing a
cross-source comparison would silently bypass an administrator's channel
markup on essentially every request. Admins who want a downgrade target
discounted can price it explicitly on the channel.
Also skip the recomputation entirely when the declared model equals the
baseline: it is provably the same cost and only burned a pricing resolve.
The identified-pricing helpers now return whether the model resolved to
channel pricing so the third guard costs no extra resolve.
DEV_GUIDE.md and the three READMEs still advertise Go 1.25.7 and
golangci-lint v2.7, but CI has since moved on:
- backend/go.mod declares go 1.26.5, and backend-ci.yml / release.yml /
security-scan.yml all resolve the toolchain via
`go-version-file: backend/go.mod` and then hard-assert
`go version | grep -q 'go1.26.5'`.
- backend-ci.yml pins golangci-lint to v2.9.
So a contributor following DEV_GUIDE.md installs a linter two minor
versions behind CI (different findings locally vs. in CI) and expects a
Go version that the workflow's own assertion step rejects.
Update all ten stale references, and note in the CI section which files
the Go version assertion lives in so future bumps don't miss one.
Docs only, no code or workflow changes.
PR #5423 relaxed the email suffix whitelist: once a whitelist is
configured, non-whitelisted registrable domains are each allowed to
register one account. That behavior activated unconditionally.
Add registration_email_domain_quota_enabled (default false) to gate it:
- Off (default): restore pre-#5423 strict whitelist semantics — with a
non-empty whitelist, non-whitelisted domains are rejected with
EMAIL_SUFFIX_NOT_ALLOWED; the register/verify views restore the
client-side whitelist pre-check and allowed-domain hint.
- On: keep #5423 behavior — one account per non-whitelisted registrable
domain (EMAIL_DOMAIN_REGISTRATION_LIMIT).
- Empty whitelist keeps allowing all domains in both states.
Gating lives in validateRegistrationEmailQuota and (as a race-safety
backstop) createUserWithRegistrationEmailGuard; the repository-level
domain lock + in-tx recheck is unchanged. The admin update field is
*bool (omitted = keep current) so stale full-payload saves cannot
silently flip the switch. Email binding and OAuth auto-signup keep
their strict policy, and pending-OAuth bind-login for existing
accounts is unaffected because the handler resolves existing emails
before the quota check.
Frontend adds the toggle to admin settings (zh/en copy; whitelist hint
restored to strict wording, quota wording moved to the new toggle) and
exposes the flag via public settings + SSR injection payload.
Tests: #5423 quota tests now enable the switch explicitly; new
default-off regression tests cover register/send-code/async/pending
OAuth/OIDC create-account plus both register views; API contract JSON
and the injection drift guard are updated.