Wesley Liddick
93c32fa1a2
Merge pull request #5553 from Wei-Shaw/feat/codex-fingerprint-convergence
...
feat: Codex OAuth 设备指纹收敛
v0.1.175
2026-08-12 18:52:01 +08:00
shaw
04f8cdb194
fix: 修复 golangci-lint errcheck 和 gofmt 格式问题
2026-08-12 18:20:54 +08:00
shaw
c0ab3a00ea
feat: Codex OAuth 设备指纹收敛,减少上游可见的设备数和会话数
...
多人共享同一 OAuth 账号时,各用户 Codex 客户端携带各自不同的 installation_id/session_id/thread_id,
上游据此判定设备数和会话数并限制配额。本功能将这些标识改写为账号级恒定值。
四档策略(账号级 extra 字段 codex_fingerprint_mode):
- off: 不做任何收敛,原样透传
- device: 仅收敛 installation_id
- session(默认): 收敛 installation_id + session_id,thread_id 按客户端原始 session 派生
- full: 收敛所有标识(installation_id + session_id + thread_id)
改写覆盖 6 个指纹载体:x-codex-turn-metadata 头(JSON 内部字段)、x-codex-window-id、
x-codex-installation-id、x-client-request-id、session-id/session_id/thread-id、
请求体 client_metadata。头和体共享同一份预计算 IDs 确保 turn_id 等随机字段一致。
2026-08-12 17:57:50 +08:00
Wesley Liddick
4ec9ceec4a
Merge pull request #5508 from pcmid/fix/show-security-audit-menu-in-simple-mode
...
fix(frontend): show security audit menu in simple mode
2026-08-12 10:01:20 +08:00
Wesley Liddick
46cbb7187b
Merge pull request #5531 from SamizuHM/fix/openai-compat-nested-data-usage
...
fix(openai-compat): parse usage from nested data envelopes
2026-08-12 10:01:09 +08:00
Wesley Liddick
80acae16fa
Merge pull request #5525 from Fool0ntheHill/codex/fix-openai-visible-ttft
...
fix(openai): record Responses TTFT on visible output
2026-08-12 09:59:52 +08:00
Wesley Liddick
19c6007a22
Merge pull request #5342 from wucm667/fix/issue-5340-ws-v2-terminal-ttft
...
fix(openai-ws): exclude terminal events from TTFT
2026-08-12 09:59:43 +08:00
Wesley Liddick
0ed1a9f22a
Merge pull request #5514 from wucm667/fix/issue-5510-cyber-policy-audit-scope
...
fix(audit): scope cyber policy events
2026-08-12 09:58:32 +08:00
Wesley Liddick
a29fce4a61
Merge pull request #5511 from wucm667/fix/pr-5234-ws-audit-logging
...
fix(security-audit): restore websocket audit logs
2026-08-12 09:58:24 +08:00
Wesley Liddick
1225437099
Merge pull request #5502 from pyt111/codex/fix-account-stats-service-tier
...
fix: 修复 service tier 账号成本统计
2026-08-12 09:58:16 +08:00
Wesley Liddick
5192abb6b5
Merge pull request #5503 from fengshao1227/fix/openai-html-403-not-account-penalty
...
fix(openai): 上游 HTML 403 不再被当成账号级错误处罚账号
2026-08-12 09:58:08 +08:00
Wesley Liddick
40aae11888
Merge pull request #5513 from wucm667/fix/issue-5506-gemini-exclusive-minimum
...
fix(gemini): normalize exclusive minimum tool schemas
2026-08-12 09:57:52 +08:00
Wesley Liddick
177bf30867
Merge pull request #5527 from creamtea47/codex/ops-memory-capacity-display
...
fix: 优化运营监控内存容量显示
2026-08-12 09:57:45 +08:00
Wesley Liddick
d76c1af759
Merge pull request #5535 from feitianbubu/fix/account-scheduling-threshold-i18n-nesting
...
fix(i18n): move account scheduling threshold keys out of status block
2026-08-12 09:54:47 +08:00
wucm667
da283854f6
chore: retry CI after registry timeout
2026-08-12 02:25:00 +08:00
feitianbubu
670b03f7e7
fix(i18n): move account scheduling threshold keys out of status block
2026-08-12 00:10:34 +08:00
SamizuHM
a163742fc9
fix(openai): preserve usage path precedence
2026-08-11 22:01:47 +08:00
SamizuHM
04dc540b23
fix(openai): parse nested data usage envelopes
2026-08-11 18:15:31 +08:00
NellPoi
943f09d357
fix: 优化运营监控内存容量显示
2026-08-11 17:34:58 +08:00
Fool0ntheHill
900194fab2
fix(openai): 修正 Responses 可见输出 TTFT
2026-08-11 16:31:09 +08:00
wucm667
662444774f
test(gemini): check cleaned schema assertions
2026-08-11 16:19:18 +08:00
wucm667
e24cb99b79
fix(openai-ws): retain no-delta TTFT fallback
2026-08-11 16:01:34 +08:00
Wesley Liddick
1e618dbc29
Merge pull request #5054 from wucm667/fix/issue-5029-openai-passthrough-pool-auth-retry
...
fix(openai): retry pool auth failures before failover
2026-08-11 14:21:45 +08:00
shaw
a3bbf35cbd
Merge branch 'main' into fix/issue-5029-openai-passthrough-pool-auth-retry
...
Resolve conflict in backend/internal/handler/openai_gateway_handler_test.go.
main and this branch each appended a passthrough upstream stub plus a test at
the same two insertion points:
main openAIHTTPPassthroughSSERateLimitUpstream
TestOpenAIResponses_APIKeyPassthroughSSERateLimitUsesConfiguredPoolRetry
branch openAIHTTPPassthroughAuthFailoverUpstream
TestOpenAIResponses_APIKeyPassthroughPoolAuthFailureRetriesThenSwitchesToHealthyAccount
Both sides are kept verbatim; the only edit is giving each stub its own
calls() body instead of sharing the trailing one. No assertion was changed.
openai_gateway_passthrough.go and openai_oauth_passthrough_test.go merged
automatically.
2026-08-11 14:09:07 +08:00
Wesley Liddick
caa1abb13a
Merge pull request #5404 from wucm667/fix/issue-5400-oauth-image-stream-error
...
fix(openai): fail over OAuth image stream errors
2026-08-11 14:04:42 +08:00
Wesley Liddick
574dfad2dc
Merge pull request #5488 from wucm667/fix/issue-5482-stale-codex-threshold
...
fix(openai): skip stale and reset Codex snapshots in scheduling threshold evaluator
2026-08-11 14:00:33 +08:00
Wesley Liddick
bc0a6a7039
Merge pull request #5480 from scp-planet/fix/admin-usage-request-id-column
...
修复管理端使用记录请求 ID 列显示 / Restore admin usage request ID column visibility
2026-08-11 14:00:07 +08:00
Wesley Liddick
6876477371
Merge pull request #5304 from wucm667/fix/issue-5302-chat-reasoning-alias
...
fix(apicompat): accept chat reasoning alias
2026-08-11 13:59:49 +08:00
Wesley Liddick
b918874f81
Merge pull request #5403 from cyhhao/fix/codex-capacity-exponential-backoff
...
fix(openai): back off capacity retries exponentially
2026-08-11 13:58:06 +08:00
Wesley Liddick
20a2d12dde
Merge pull request #5415 from Yuxin-Qiao/fix/openai-responses-empty-completed-failover
...
fix(openai): fail over empty response.completed streams instead of recording 0/0 success
2026-08-11 13:53:43 +08:00
Wesley Liddick
ca9e2b48ee
Merge pull request #5413 from Yuxin-Qiao/fix/openai-responses-reasoning-item-id
...
fix(openai): strip invalid reasoning item IDs in API key passthrough
2026-08-11 13:53:05 +08:00
Wesley Liddick
e499a54a9d
Merge pull request #5449 from hongheshan-svg/docs/fix-stale-go-golangci-versions
...
docs: sync Go 1.26.5 / golangci-lint v2.9 versions with CI
2026-08-11 13:52:35 +08:00
wucm667
6564d376e5
fix(audit): scope cyber policy events
2026-08-11 13:05:56 +08:00
wucm667
c8d9af6ce1
fix(gemini): normalize exclusive minimum tool schemas
2026-08-11 12:34:51 +08:00
wucm667
2d9920ba7d
fix(security-audit): restore websocket audit logs
2026-08-11 11:56:46 +08:00
pcmid
0d7b6ae64c
fix(frontend): show security audit menu in simple mode
...
The security audit group (Risk Control + Prompt Audit) was hidden from
the sidebar via `hideInSimpleMode`, but nothing else in the stack
restricts it in simple mode:
- `router/index.ts` simple-mode `restrictedPaths` does not cover
`/admin/risk-control` or `/admin/prompt-audit`
- the `/risk-control` and `/prompt-audit` admin route groups have no
`RunMode` gate, and neither does `internal/securityaudit/` nor
`service/content_moderation.go`
- `SettingsView.vue` renders the risk control toggle together with a
`<router-link to="/admin/risk-control">` shortcut, and the settings
page stays visible in simple mode
The feature is therefore fully usable in simple mode and already
reachable through the settings page — only the sidebar entry was
missing. Drop the flag so the menu matches actual behaviour.
The group remains gated by `risk_control_enabled` (opt-in, default
false) through `featureFlag: flagRiskControl`.
2026-08-11 11:27:49 +08:00
li
12abb54700
fix(openai): 上游 HTML 403 不再被当成账号级错误处罚账号
...
上游代理 / CDN 在请求到达 OpenAI API 之前拦下时,回的是 HTML 403 页面而不是
{"error":{...}} 结构化错误。这类响应描述的是「这条链路 / 这个端点被挡了」,
不构成账号凭据或权限失效的证据。
但 handleOpenAI403 不区分响应形态,一律按账号级 403 处理:
- 首次即 SetTempUnschedulable,账号 10 分钟不可调度;
- 连续 openAI403DisableThreshold(3) 次直接 SetError 永久禁用账号;
- 403 又在 failover 状态集里,同一个坏请求会被逐个账号重放。
结果是一个请求级错误被放大成整组账号下线。issue #5334 给出的触发方式是
POST /v1/responses/not-exist —— 该路径能通过只做结构校验的 guardResponsesSubpath,
转发后拿回 HTML 403,任何持有 API Key 的调用方重复几次即可打穿一个分组。
附带问题:整张 HTML 页面会被拼进账号错误信息写库并显示在管理端。
仓库对这类响应早有明确口径,只是没有应用到这条路径:
- openai_gateway_count_tokens.go 的 isOpenAIOAuthInputTokensUnsupported 已把
「HTML 403 page without a structured error」按端点级响应处理;
- shouldApplyOpenAIAlphaSearchAccountErrorSideEffects 的既定不变式是
端点级错误只换号、不写账号错误状态。
本次复用现成的 isHTMLResponse,在 handleOpenAI403 入口跳过账号处罚:不递增
连续 403 计数、不设临时不可调度、不永久禁用。failover 行为不变 —— 换一个走
不同代理的账号仍有可能成功。
Fixes #5334
2026-08-11 10:18:20 +08:00
pyt111
9261dd7734
[verified] fix: apply service-tier pricing to account cost
2026-08-11 09:55:19 +08:00
Wesley Liddick
0f73203e35
Merge pull request #5277 from Pluviobyte/agent/fix-grok-missing-usage-billing
...
fix: reject Grok responses without billable usage
2026-08-11 09:28:43 +08:00
Wesley Liddick
e2d9034d3d
Merge pull request #5327 from fengshao1227/fix/fingerprint-user-agent-validation
...
fix(identity): validate user-agent before persisting account fingerprint
2026-08-11 09:28:27 +08:00
Wesley Liddick
ba4bd0c0b4
Merge pull request #5481 from fengshao1227/fix/responses-deterministic-400-passthrough
...
fix(openai): 原生 Responses 路径不再把上游确定性 400 归一成可重试 502
2026-08-11 09:27:34 +08:00
Wesley Liddick
61acf29125
Merge pull request #5501 from wucm667/fix/issue-5500-unset-scheduling-thresholds
...
fix(settings): cache unset scheduling thresholds
2026-08-11 09:27:22 +08:00
wucm667
3e1674a060
fix(settings): cache unset scheduling thresholds
2026-08-11 04:34:49 +08:00
Wesley Liddick
0b3fe95afd
Merge pull request #5439 from pigzwy/feat/response-model-billing
...
feat(billing): support safe billing by upstream response model
2026-08-10 19:47:22 +08:00
anya
e5b325e481
fix(billing): harden response-model billing admission
...
Three guards on the response_model billing basis, all scoped to the opt-in
channel mode so existing channels are unaffected.
1. Per-unit billing gate was stale. Audio (AudioUsage) and the search
surcharge (SearchCount) reached the billing paths after this branch was
cut; both are priced per unit rather than per token, so they must be
excluded like image/video/web-search already are. Audio pricing ignores
the model entirely, so the previous code "adopted" a basis switch that
changed nothing and emitted a misleading audit log for it.
2. Never zero out a billable request. A catalog entry whose token prices are
explicitly 0 still passes the identified-pricing gate (TokenPricingAbsent
only means both prices are missing), so an upstream could declare a free
model name and drop the bill to zero. Reject a zero (or negative)
recomputation whenever the baseline was billable; an already-zero baseline
is unaffected.
3. Never cross from channel pricing to the global table. Channel pricing
matches exact keys and prefix wildcards and does not strip date suffixes,
while the global table's identified lookup does. Upstreams routinely
declare dated model IDs (claude-opus-4-5-20251101), so allowing a
cross-source comparison would silently bypass an administrator's channel
markup on essentially every request. Admins who want a downgrade target
discounted can price it explicitly on the channel.
Also skip the recomputation entirely when the declared model equals the
baseline: it is provably the same cost and only burned a pricing resolve.
The identified-pricing helpers now return whether the model resolved to
channel pricing so the third guard costs no extra resolve.
2026-08-10 19:11:47 +08:00
shaw
33351c7bc7
fix(billing): gofmt channel.go and drop the redundant response-model hint
...
- channel.go: 常量块里插入注释后 gofmt 会把 BillingModelSourceResponse 单独成组,
原写法沿用了上一组的对齐空格,CI 的 gofmt 检查因此失败
(internal/service/channel.go:45: File is not properly formatted)。
- 撤掉渠道表单里新加的那条提示:说明本就多余,且"只降不升"只在"相对基线收费"
这个口径下成立,容易被读成"上游返回更贵的模型也不会多收",反而误导。
2026-08-10 18:45:16 +08:00
shaw
b689e5b401
fix(billing): harden response-model billing and repair its test fixtures
...
按上游响应模型计费的准入过宽、且自带用例必然失败,本次一并修复。
严格化准入
- 新增 PricingService.GetIdentifiedModelPricing / BillingService.HasIdentifiedTokenPricing:
只接受价格表中能被确定性识别的条目(精确名、已知拼写变体、去掉日期版本后缀),
不再接受 getFallbackPricing / matchByModelFamily 按子串猜出的系列兜底价。
此前上游只要自报一个含 "haiku" 的编造名字就能被判定"已定价",把账单压到最便宜的
系列价(实测 claude-opus-4.8 基线 $0.0019250 → $0.0000963,20 倍少收)。
GetModelPricing 的对外行为不变,仅把前三步查找抽成共用函数。
- 图片 / 视频 / 网页搜索请求不再走响应模型覆盖:这些路径按张、按秒、按次定价,
与准入检查所验的 token 价不是同一套价格表。
- 准入判断抽成 responseModelBillingDeclaration,两条计费主干共用同一套规则。
正确性与可观测性
- 去掉 recordUsageCore 中 billingModel 的无效赋值(ineffassign 已启用,会让
golangci-lint 直接失败),改由日志表达实际生效的计费基准。
- 补 cost != nil 守卫,与 OpenAI 侧及本文件既有写法对齐。
- 每次实际生效的基准切换记一条 billing.response_model_applied,少收可审计。
- 修正 upstreamResponseModelObserver 上"冲突仅用于诊断、永不影响计费"的过期注释。
测试
- gpt-5.1 与 gpt-5.5 实际共用同一条 gpt-5.4 价格,夹具"价格必须不同"的前置断言
必然失败,OpenAI 侧 3 个用例(含 4 个子用例)从未跑通;改用 gpt-5.4-nano /
gpt-5.5。Anthropic 侧 claude-opus-4 不是价格表精确条目,改用 claude-opus-4.8。
- 夹具增加"必须可被确定性识别"的前置断言,避免用例被更靠前的门挡掉而失去判别力。
- 新增:准入规则表驱动用例、可识别性判定用例、编造家族名在两条主干上均被拒的用例。
前端
- 选择该模式时提示"计费基准以上游自报模型为准,只降不升,仅对可信上游启用"。
2026-08-10 18:45:15 +08:00
pigzwy
9096492b55
feat(billing): support safe upstream response model billing
2026-08-10 18:45:14 +08:00
wucm667
3d3aee2e72
fix(openai): skip stale and reset Codex snapshots in scheduling threshold evaluator
2026-08-10 14:27:04 +08:00
li
591d47fb9b
fix(openai): 原生 Responses 路径不再把上游确定性 400 归一成可重试 502
...
上游返回 400(invalid_function_parameters、missing_required_parameter 等)时,
`/v1/responses` 原生路径把它包成 `502 upstream_error / "Upstream request failed"`,
真实的 message/code/param 全部丢弃。
502 属于可重试类,下游网关会把这个永远不会成功的请求反复重放(issue #5479 实测
30 个失败请求被放大成 60 次上游调用),客户端也拿不到「哪个字段非法」的线索。
同一个 service 上的兄弟路径早已做对:
- `handleCompatErrorResponse`(ChatCompletions / Anthropic)回真实状态码 +
invalid_request_error + 真实 message;
- `/v1/images/generations` 还额外透传 code/param。
原生 Responses 是唯一漏掉的一条,本次对齐。
改动只放行 400:走到该分支说明 `shouldFailoverOpenAIUpstreamResponse` 已判定这个
400 不可 failover,即 server_is_overloaded / at capacity 这类可重试的 400 不会到达。
401/402/403(运营方凭据问题)、404/405(可能是 base_url 配错)、429 一律维持原状。
Fixes #5479
2026-08-10 11:25:46 +08:00