fengsilin
  • Присоединился Mar 23, 2026
Загрузка тепловой карты…

fengsilin выполнил(а) push в master в server/new-api

  • e9975df35c feat(web): 素材凭据输入框增加已配置占位符 编辑 54/61 渠道时 AccessKey/SecretKey 输入框此前完全留空,容易误以为 凭据未保存。已配置时占位符显示"已配置,留空保持不变",未配置时显示 "请输入 AccessKey/SecretKey"。后端仍不回传真实密钥,仅依据 asset_credential_configured 状态区分占位符文案。顺带补齐凭据卡片 已有文案的英文翻译。
  • 62bda9526a chore(e2e): 凭据与进程清理工具安全加固 按 Mimosa 安全扫描建议处理 e2e 测试工具的存量高危项: - e2e 集群的 root/admin 密码、会话密钥、同步 API Key 改为环境变量 优先(E2E_ROOT_PASSWORD/E2E_ADMIN_PASSWORD/E2E_SESSION_SECRET/ E2E_SYNC_API_KEY),本地回退值仅服务于 127.0.0.1 测试集群, Go 与 Playwright 两侧默认值保持一致 - killWindowsProcessTree 对 pid 强制正整数校验后再交给 taskkill, 消除命令注入误报入口
  • 0ab4867130 fix(channel): 修复豆包视频渠道素材凭据摘要不回显 attachChannelAssetCredentialSummaries 收集查询 ID 时只纳入了中国移动 Seedance(61) 渠道,豆包视频(54) 渠道的凭据永远不会回显,导致管理端 编辑 54 渠道时素材 API 地址显示为空。提取 isAssetCredentialSummaryChannel 统一两处类型判断,并补充 54 渠道回归测试。
  • Сравнить 3 коммитов »

1 месяц назад

fengsilin выполнил(а) push в master в server/new-api

  • 8a891364c1 feat(volcengine): decouple asset endpoint and persist asset binding Complete the DoubaoVideo asset library integration on top of the managed per-user asset groups: - Asset endpoint resolution is an explicit three-level priority: a hard-coded override wins, otherwise the per-channel credential base_url from channel_asset_credentials is used verbatim (it already contains the full /openApi/portrait path), otherwise the official default. The channel video base URL no longer participates in asset routing, so video (official Ark) and asset (gateway) addresses stay fully independent. The channel form gains an "素材 API 地址" field with a hint that the official address has no asset API, and the channel type label becomes "豆包视频(素材网关)" to surface the split. Credential summaries now cover DoubaoVideo channels and echo the base URL back for editing. - After an asset request auto-matches a channel (no existing user binding), persist it to user_asset_channels so subsequent asset and video requests stay on the same channel, keeping asset:// references consistent with the upload channel. This mirrors the video-task binding backfill; binding failure logs a warning and does not fail the asset operation. Co-Authored-By: ZCode <noreply@anthropic.com>

1 месяц назад

fengsilin выполнил(а) push в master в server/new-api

  • 6f6c68787f feat(volcengine): manage per-user asset groups on DoubaoVideo channels Bring official Volcengine channels in line with the China Mobile asset isolation model: the platform owns the upstream asset group lifecycle per (user, channel). asset_group.* APIs are forbidden for clients; CreateAsset is scoped to the user's managed group (client GroupId is overwritten), ListAssets is scoped with Filter.GroupIds to the managed group, and Get/Update/Delete verify ownership via GetAsset before forwarding, returning not-found for foreign assets. Generalize the shared managed-group plumbing (GetOrCreateUserAssetGroup, ScopeManagedAssetRequest, RequireManagedAssetOwnership) and add the DoubaoVideo-specific group creator (Ark CreateAssetGroup returns the id in Result.Id; GroupType must be omitted). The DoubaoVideo asset adapter now serializes the request body from req.Body so platform rewrites take effect (RawBody was bypassing the scoping) and the V4 signature always covers the actual payload. Verified end-to-end: group ops rejected, forged GroupId overwritten by the auto-created managed group, ListAssets returns only the managed group, foreign assets hidden from get/delete. Co-Authored-By: ZCode <noreply@anthropic.com>
  • b9edaa1ad3 feat(volcengine): add asset library support for official DoubaoVideo channels Register a DoubaoVideo asset adapter that forwards the Ark-compatible asset API (POST /api/v1/volcengine/asset?Action=xx) to the official /openApi/portrait endpoint with a Volcengine V4 HMAC-SHA256 signature (canonical request over content-type/host/x-content-sha256/x-date, date/cn-beijing/ark/request scope). The AK/SK pair and optional project code are stored in channel_asset_credentials (pool_id holds the project code), so asset credentials stay separate from the video Bearer key; the channel form now accepts them for type 54. DoubaoVideo joins the seedance asset family so a user's asset upload channel and video task channel stay the same (asset:// references pass through to the upstream). Both resolution chains (asset proxy resolver and video asset family matcher) now require the asset credential to be configured before a type-54 channel can serve, bind, or be auto-matched for assets, falling through to compatible channels otherwise. The /api/v3 native-path whitelist simplifies back to the family list now that 54 is a member. Verified end-to-end against the real upstream: CreateAssetGroup, CreateAsset (real video upload, Processing -> Active moderation), ListAssets/GetAsset, and a video generation task referencing the asset via asset://video reference (succeeded, 432900 tokens). Co-Authored-By: ZCode <noreply@anthropic.com>
  • b2d43b6c29 fix(doubao-video): parse camelCase fields from Volcengine task responses The taskdoubao adaptor expected snake_case JSON keys (video_url, completion_tokens, total_tokens, framespersecond, service_tier, created_at, updated_at) but Volcengine returns camelCase (videoUrl, completionTokens, totalTokens, framesPerSecond, serviceTier, createdAt, updatedAt). As a result the video URL was never parsed: successful tasks fell back to the platform proxy URL (BuildProxyURL) as result_url, which broke the video proxy in containerized deployments (localhost:port not reachable inside the container) and zeroed the usage tokens used for billing. Align the responseTask JSON tags with the real Volcengine response shape and add a regression test with the exact production payload. Co-Authored-By: ZCode <noreply@anthropic.com>
  • 12686067c5 feat(volcengine): serve native /api/v3 video path on official DoubaoVideo channels The native /api/v3/contents/generations/tasks route was restricted to the seedance asset channel family (58/60/61); official Volcengine Ark channels (DoubaoVideo, type 54) could only be reached via the standardized /v1/video/generations path. Allow type 54 on the native route in both the distributor and the task retry channel selection, while keeping it out of the seedance asset binding system. The taskdoubao adaptor now reuses a pre-parsed task request from the context (native path) instead of re-parsing the body as TaskSubmitReq, whose prompt validation would reject the Volcengine-native format. When req.Prompt is empty (native path), content text items from metadata are preserved instead of being replaced with an empty prompt; the standardized path behavior (prompt replaces metadata text) is unchanged and covered by existing tests. Co-Authored-By: ZCode <noreply@anthropic.com>
  • Сравнить 4 коммитов »

1 месяц назад

fengsilin выполнил(а) push в master в server/new-api

  • 83724d4930 chore: add image build script, drop binary artifact, add missing go.sum Add deploy/build_newapi.sh for tagged Aliyun image builds, remove the 94MB compiled binary new-api.exe~ accidentally committed to the repo, and add the missing go.sum for third_party/ecloudsdkcore. Co-Authored-By: ZCode <noreply@anthropic.com>
  • ce40bfe92f feat(chinamobile): support doubao-seedance-2-0-mini-260615 billing model Register the Seedance mini model in the matrix usage capability table (both native name and doubao-seedance-2.0 alias) and keep SupportsAnyMatrixUsageBillingModel in sync so the model bills via matrix usage on the ChinaMobile Seedance channel. Co-Authored-By: ZCode <noreply@anthropic.com>
  • 0b79e4ee07 fix(db): skip logs AutoMigrate for pg_partman-managed PostgreSQL tables On PostgreSQL the logs table is a RANGE-partitioned table on created_at owned by pg_partman; GORM AutoMigrate would alter its composite primary key (id, created_at) and create redundant per-partition indexes, breaking startup. Extract ensureLogTable() to skip AutoMigrate on PostgreSQL (existence check only) while keeping the original behavior on SQLite/MySQL. The dedicated LOG_SQL_DSN PostgreSQL branch follows the same rule. Ship the matching postgres-partman image (Dockerfile + 01-partition.sql) that creates and maintains the partitioned table via pg_partman + pg_cron. Co-Authored-By: ZCode <noreply@anthropic.com>
  • 17c12fd41e feat: harden services and add video channel bindings Co-Authored-By: Codex <noreply@anthropic.com>
  • cd35e66b33 feat(chinamobile): add channel asset credentials Co-Authored-By: Codex <noreply@anthropic.com>
  • Сравнить 11 коммитов »

1 месяц назад

fengsilin выполнил(а) push в master в server/new-api

  • 4533c24fa1 merge: dynamic video asset channel selection
  • f6321b3910 feat(channel): support dynamic video asset channel selection Co-Authored-By: Codex <noreply@anthropic.com>
  • 3fbf48313a feat(pricing): support usage billing and endpoint fixes Add KlingAiping usage-token settlement from upstream final_unit_deduction and duration fallback handling. Normalize model endpoint config persistence and convert model pricing values between stored USD and display currency in the editor. Co-Authored-By: Codex <noreply@anthropic.com>
  • dd14839996 merge: tianyiyun seedance channel
  • 678add297f feat(channel): add tianyiyun seedance channel Co-Authored-By: Codex <noreply@anthropic.com>
  • Сравнить 58 коммитов »

2 месяцев назад

fengsilin выполнил(а) push в master в server/new-api

  • 8f89828ca3 fix(user-migration): 禁止冲突用户非法合并 - 前端冲突处理页面禁用 cn_already_synced_to_ov 场景的 merge 操作 - 后端 resolve 接口拒绝将已存在 synced copy 的 CN 用户作为 merge 目标 - 补充对应控制器测试 Co-Authored-By: Codex <noreply@anthropic.com>
  • 2f7a71d61e fix(user-migration): 补齐主节点保护与导入校验 - 为 user-migrations 管理路由增加仅 master 节点可访问的保护 - 为导入创建用户补充用户名、显示名、邮箱长度校验及测试 - 调整测试环境部署脚本,自动写入 CN/OV 的 NODE_TYPE Co-Authored-By: Codex <noreply@anthropic.com>
  • 9aaa6baa4c merge: user migration selective batches into master # Conflicts: # controller/user.go # web/src/i18n/locales/en.json # web/src/i18n/locales/zh-CN.json
  • 65e6a82d34 feat(user-migration): support selective batches and cancellation Add candidate user selection and explicit_ids batch creation flow for overseas migration. Also add cancellable batches to release selected-user locks and extend backend, frontend, and e2e coverage for the new flow. Co-Authored-By: Codex <noreply@anthropic.com>
  • ca3f8765bb test(user-migration): complete migration coverage and e2e flow Co-Authored-By: Codex <noreply@anthropic.com>
  • Сравнить 88 коммитов »

3 месяцев назад

fengsilin выполнил(а) push в master в server/new-api

  • 155aa12014 perf(docker): BuildKit 缓存加速构建 + fix: 模型列表改用 enabled 接口 Dockerfile 添加 --mount=type=cache 持久化 bun/go 缓存, 前端改代码时跳过后端构建(~10s),后端改代码时跳过前端(~30s)。 模型限流下拉改用 /api/channel/models_enabled 只返回已启用模型。
  • f07f2c25f4 feat(rate-limit): 用户模型限流配置改用下拉选择模型 将添加模型限流时的文本输入改为从渠道模型列表中选择, 并自动过滤已配置的模型,提升配置体验和准确性。
  • 9ee5f535c8 Merge branch 'feat/relay-capture' Relay 请求抓包日志 + 用户模型 RPM 限流
  • 714d8239d1 feat: Relay 请求抓包日志 + 用户模型 RPM 限流 两个独立功能: 1. Relay Capture:对开启 capture_relay 的用户记录完整请求/响应到本地文件 - 单 writer goroutine + 128 槽 channel 架构,无 OOM 风险 - 支持流式 SSE 和非流式请求 - 30s 超时保护 2. User-Model RPM Rate Limiting:按 用户+模型 维度的 RPM 限流 - Redis 令牌桶 + 内存滑动窗口双路径,Redis 故障自动降级 - 请求失败时退还令牌/配额(Redis Refund Lua 脚本 + 内存 Refund) - Redis pipeline 错误处理:失败时清理缓存 key - 前端用户编辑弹窗新增模型限流配置面板 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • 69ed7d85d7 feat(sidebar): 添加监控外部链接菜单项 在管理员菜单区域新增「监控」入口,仅 root 用户可见, 点击后在新窗口打开外部监控面板。支持在侧边栏模块管理中切换显示/隐藏。 同时在 renderWrapper 中添加外部链接的通用支持。 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • Сравнить 6 коммитов »

4 месяцев назад

fengsilin выполнил(а) push в master в server/new-api

  • e6b4a06557 feat(logs): 隐藏使用日志中的分组信息展示 使用注释方式隐藏分组列和分组倍率标签,便于后续恢复: 1. 注释 UsageLogsColumnDefs.jsx 中的分组列定义 2. 注释 useUsageLogsData.jsx 中的 COLUMN_KEYS.GROUP 和默认可见性配置 3. 将计费详情中的"分组倍率"改为"倍率" 后端计费逻辑不变,仍正常应用分组倍率。 Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
  • f9eeb7e47e fix(billing): 修复 Claude 计费明细未应用用户渠道折扣的问题 renderClaudeModelPrice 函数缺少 userChannelRatio 参数声明,导致运行时 ReferenceError;同时价格计算未乘以用户倍率,明细文本也未显示折扣信息。 Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
  • f7ff684d0d feat(pricing): 渠道定价展示用户折扣价格 登录用户查看渠道定价时,按用户分组倍率和渠道个人倍率计算实际折扣价 并在价格列展示划线原价与折扣价,新增 /pricing/user/*model 接口。 Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
  • e1b6aff7e1 fix(log): 对普通用户隐藏 Chat ID 和 Upstream ID 后端 GetUserLogs 返回前清空 chat_id/upstream_id(omitempty 不输出), 前端搜索框和展开行详情加 isAdminUser 守卫。 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • 02e0940555 fix(playground): 清空互斥模型默认列表 初始不预填任何模型,由管理员在运营设置页面手动配置。 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • Сравнить 5 коммитов »

4 месяцев назад

fengsilin выполнил(а) push в master в server/new-api

  • 2d1a8d2f28 fix: 设置 chat_id + 优化日志查询参数构建 - Claude 和 OpenAI Responses 转发中设置 RelayChatID - 日志查询使用 URLSearchParams 替代手动字符串拼接 - 日志查询日期范围改为可选,不再强制默认今天 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • 3e86f523db feat(playground): temperature/top_p 参数互斥设置 部分上游模型不允许同时设置 temperature 和 top_p,新增管理员可配置的 模型前缀列表,匹配的模型在 Playground 中自动互斥切换两个参数。 - 后端新增 PlaygroundSetting 配置 + GET /api/playground/config 公开端点 - 运营设置页面新增 Playground 互斥模型前缀编辑 textarea - Playground 自动检测模型名匹配,启用一个参数自动禁用另一个 - 默认包含 deepseek-v4-flash/pro、deepseek-reasoner、o1-/o3-/o4-、gpt-5 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • d26ad9e635 feat: 渠道-模型级联选择 + 隐藏首页统计卡片 - UserRatioSection 模型输入改为级联下拉,选渠道后自动加载模型列表 - models 信息嵌入 channelOptions 消除冗余 channelMap 状态 - 注释掉首页 HeroSection 统计数据卡片 Co-Authored-By: Claude <noreply@anthropic.com>
  • bb708510fe docs: 用户倍率渠道-模型级联选择器设计文档 Co-Authored-By: Claude <noreply@anthropic.com>
  • b026f6bc04 feat: 用户倍率前端展示 + 渠道下拉选择 + 上游调试日志 - UserRatioSection 渠道 ID 输入改为带搜索的下拉选择器 - 使用日志详情、计费过程、展开行均显示用户倍率 - renderLogContent suffix 统一追加,消除 4 处重复 - 提取 dumpUpstreamRequest 辅助函数,debug 日志走 SysLog Co-Authored-By: Claude <noreply@anthropic.com>
  • Сравнить 10 коммитов »

4 месяцев назад

fengsilin выполнил(а) push в master в server/new-api

  • b2cb7bcf60 feat: record chat and upstream ids in usage logs

5 месяцев назад

fengsilin выполнил(а) push в master в server/new-api

  • caf457ce9e feat: 错误时记录上游响应体,支持流式 - 提取 TruncateBody 公共函数,截断到 2KB 避免日志过大 - 新增 handleResponsesStreamError 统一 SSE 错误提取逻辑 - 流式/非流式 Responses API 错误路径均捕获 UpstreamBody - 添加 upstream_body 和 truncate_body 单元测试 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • 575f84064e feat: codex API key 模式 + 前端凭证回显修复 - codex adaptor 支持 API key 和 OAuth 两种认证模式 - 提取 setupOAuthHeader 和 shouldUseChatCompletionsViaResponses - 修复编辑页 codex_credential_mode 切换/回显不同步问题 - ResponsesStreamResponse 添加 Error 字段支持独立错误事件 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
  • ca91922904 docs: add log chat/upstream id design
  • 332d5a62f2 feat: support codex api key credentials
  • 1c0898257c feat: add redemption remarks
  • Сравнить 62 коммитов »

5 месяцев назад

fengsilin выполнил(а) push в master в server/new-api

5 месяцев назад

fengsilin выполнил(а) push в feat/alipay-payment в server/new-api

  • e8ade3abae feat(payment): 集成支付宝当面付扫码支付 + 补全前端 i18n 硬编码中文 支付宝支付: - 后端:新增 topup_alipay.go、payment_alipay.go,实现当面付(扫码支付)下单、 回调验签、订单状态查询完整流程,支持 RSA2 签名 - 前端:新增 QRCodePayModal 通用二维码支付弹窗(泛化微信支付弹窗)、 SettingsPaymentGatewayAlipay 管理配置页面、充值流程接入支付宝 - 充值历史:管理员视图新增用户邮箱列,后端 fillTopUpEmails 批量填充 i18n 补全: - 54 个缺失翻译 key 添加到全部 7 个 locale 文件(zh-CN/zh-TW/en/fr/ja/ru/vi) - 涵盖渠道名称、仪表盘标签、兑换码状态、控制台时间筛选、Playground 错误消息、 Dashboard 设置页面提示等 - 14 个源码文件中约 31 处 showError/showSuccess/showWarning 硬编码中文改用 t() - ChannelsColumnDefs、helpers、services 中散落的硬编码中文统一国际化 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
  • befde35afa feat(i18n): 全面国际化前端硬编码中文文本 将 14 个源码文件中的硬编码中文 UI 文本统一包裹到 t()/i18n.t() 调用, 覆盖登录注册、首页、设置页、工具函数等核心模块,并为 7 个语言文件 补充约 80+ 翻译键;修复 zh-CN.json 值误用繁体问题。 Co-Authored-By: Claude <noreply@anthropic.com>
  • e08b5a447f fix(router): 移除微信支付创建订单接口的 CriticalRateLimit 限流 避免用户扫码支付时因限流导致 429 错误。 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
  • cf2a0a7992 fix(payment): 修复微信支付集成多项问题 - 修复订单号超 32 字符限制(微信支付要求),改用时间戳+随机字符格式 - 修复密钥解析:添加 wrapAsPEM 兼容 PEM/Base64/DER 多种输入格式 - 修复前端:RechargeCard 未识别 enableWechatTopUp 导致充值表单不显示 - 修复前端:支付按钮禁用逻辑未区分 epay/wechat_pay - 移除状态轮询接口的 CriticalRateLimit 防止 429 - 过滤未启用易支付的旧支付方法避免混淆 - 修复 SiLinkedin 图标不存在导致构建失败 - 简化 webhook 冗余条件判断 - 添加密钥解析相关测试 Co-Authored-By: Claude <noreply@anthropic.com>
  • 00e266cd77 feat(payment): 集成微信支付 Native(扫码支付)V3 API 完整实现微信支付充值和订阅购买功能,支持配置热更新、二维码扫码支付、 回调验签、订单状态轮询,以及管理后台支付网关设置。 后端: - 新增微信支付 V3 客户端(支持 Base64/文件路径两种密钥加载) - Native 下单、回调处理、订单状态查询 API - 充值订单幂等完成(事务+行锁) - 订阅购买支持微信支付 - 配置变更自动重置客户端 - 提取 createWechatNativeOrder 消除重复下单逻辑 前端: - 二维码扫码弹窗(含倒计时、自动轮询状态) - 微信支付设置页面(AppID、商户号、密钥等 12 项配置) - 充值页集成微信支付流程 依赖:go-pay/gopay v1.5.117 Co-Authored-By: Claude <noreply@anthropic.com>

5 месяцев назад