Commit Graph
6145 Commits
Author SHA1 Message Date
Seefs cb96ab0208 chore(github): migrate issue templates to required forms (#6452) 2026-07-24 13:46:54 +08:00
CaIon 1721144221 fix(auth): keep login state on rate-limited or failing token refresh
When the dashboard token refresh endpoint returned 429 (shared
critical rate limit) the frontend classified it as out_of_sync,
cleared local auth state, and redirected to /sign-in. The rate limit
itself is working as intended; the bug is that a temporary rejection
was treated as a terminal auth failure.

- Treat 429 refresh responses as transient errors on the frontend,
  keeping the session retryable instead of clearing it. Only explicit
  401 or confirmed session mismatch/race exhaustion clears auth state.
- Return Retry-After on all rate-limited responses (remaining TTL on
  Redis, window duration on the in-memory limiter) so clients can
  back off.
- Log the underlying error with request context when auth session
  errors map to 500 AUTH_INTERNAL_ERROR, and replace fmt.Println with
  request-scoped logging in the Redis rate limiter error paths.

Fixes #6361
2026-07-21 12:39:29 +08:00
feitianbubuandCaIon e0d5156115 fix: prevent duplicate suno task refunds via cas status update (#6074)
* fix: prevent duplicate suno task refunds via cas status update

* fix: reconcile failed task refunds

---------

Co-authored-by: CaIon <i@caion.me>
2026-07-20 22:03:13 +08:00
QuentinHsu 4aa08f917e fix(playground): resolve auto group model listing (#6163)
* fix(playground): resolve auto group model listing

- merge and deduplicate available models in configured auto group order.
- reuse special usable group rules and add model filtering regression coverage.

* refactor: extract GetGroupsEnabledModels to dedupe group model expansion
2026-07-20 18:21:24 +08:00
yyhhyyyyyy e13d4033e5 fix(channel): improve proxy client compatibility and cache lifecycle (#6157)
* fix(channel): improve proxy client compatibility and cache lifecycle

* test(controller): use non-fatal assertions for channel tests
2026-07-20 18:11:22 +08:00
RedwindA 08677566f8 fix(web): show used quota for unlimited API keys (#6224) 2026-07-20 18:08:53 +08:00
QuentinHsu 270accc322 perf(data-table): optimize action column width allocation (#6135)
- apply a minimum width hint to content-sized columns to prevent wasted space.
- preserve remaining table width allocation across regular data columns.
2026-07-20 18:04:05 +08:00
QuentinHsu 2ef4cfff9c fix(playground): prevent model group option stretching (#6120)
* fix(playground): prevent model group option stretching

- keep group options at a fixed 2rem height and align them to the top.
- organize layout code in a dedicated module and cover layout and scrolling behavior.

* docs(web): strengthen frontend testing requirements

- require regression coverage for behavior changes, bug fixes, and UI states.
- define module-scoped test organization, stable assertions, mocks, and verification rules.
2026-07-20 18:03:49 +08:00
feitianbubu 16bfae1750 fix: drop realtime beta header for ga models and register new ones (#6032) 2026-07-20 17:48:09 +08:00
CaIon d0e23e1e0f chore: include frontend in language stats 2026-07-20 16:53:08 +08:00
Calcium-Ion 31d70fca39 refactor(auth): replace dashboard sessions with stateless tokens and session control (#6329)
* refactor(auth): replace dashboard sessions with stateless tokens

* feat(auth): harden session issuance and distributed enforcement

* fix(proxy): preserve trusted proxy compatibility defaults

* refactor: address dashboard auth review feedback

* refactor: remove classic frontend and flatten web app
2026-07-20 16:48:43 +08:00
CaIon 5a6c53d496 feat: standardize OpenAI Models label usage across components 2026-07-18 15:44:48 +08:00
SeefsandCaIon a6cf42c0f1 feat: support upstream model fetch for advanced custom channels (#5971)
* feat: support upstream model fetch for advanced custom channels

* fix: add advanced custom routes as separate groups

* fix: select advanced custom route entry before adding

---------

Co-authored-by: CaIon <i@caion.me>
2026-07-18 13:39:53 +08:00
Seefs 57746fc972 feat(channel): support Codex upstream model discovery (#6184)
* fix(i18n): clarify Go regex and field passthrough copy

* feat(channel): support Codex upstream model discovery

* Revert "fix(i18n): clarify Go regex and field passthrough copy"

This reverts commit d63d7975db3e34ff44e189112d3c15ad8c24ad88.
2026-07-18 13:04:16 +08:00
NikuandClaude Fable 5 1086038f5f fix: prevent duplicate tool calls in Responses-to-Chat streaming (#6225)
When a function call was already registered under its output_index key
via response.output_item.added, the synthetic events built from the
terminal response.completed output carry no output_index and resolve to
a different item-based key. ensureToolForEvent then created a second
tool index and resent the full arguments, so Chat Completions clients
received the same tool call twice.

Reuse the tool registered under itemIDToKey/callIDToKey before creating
a new one, and alias the new key to the existing tool.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 12:50:02 +08:00
CaIon 923a17ca8a fix: update high-risk status code retry confirmation texts 2026-07-17 21:54:29 +08:00
DawnMoon1542 dc9aeab98b fix(data-table): update table body immediately when toggling columns (#6253)
DataTableRow's React.memo did not depend on columnVisibility.
TanStack row references stay stable when visible columns change, so the
table body did not refresh after View -> Toggle columns until another
action rebuilt the column definitions.

Capture a visible column id signature (visibleColumnIds) outside the
memo and compare it, matching the existing isSelected snapshot pattern.
All tables that use DataTableRow pick up the fix.
2026-07-17 19:38:16 +08:00
DawnMoon1542 506e41c116 fix: add server-side sorting to user list, prevent client-side sort on paged data (#6194)
* fix: add server-side sorting to user list, prevent client-side sort on paged data

The user management table applied client-side sorting to the current
page slice while pagination was handled server-side, causing ID-asc
views to show pages out of order (e.g. 23-42, 3-22, 1-2).

Backend: add sort_by/sort_order query params to GetAllUsers and
SearchUsers with a column whitelist for safe ORDER BY generation.
Frontend: pass sorting state to the API and reset to page 1 on sort
change. Generic useDataTable hook now disables client-side sorted row
model and sort UI for tables with manual pagination but no server-side
sort handler.

* fix: add id tie-breaker to non-unique sort columns, remove side effect from state updater

Append secondary ORDER BY id DESC when sorting by non-unique columns
(quota, created_at, etc.) to prevent row duplication/skipping across
OFFSET pages.

Move onPaginationChange out of setSorting updater to avoid side effects
inside a pure function (React Strict Mode double-invocation safety).
2026-07-17 19:36:44 +08:00
fuxdevandduanxufu a63364d156 fix: infer MiniMax vendor for MiniMax models (#6164)
* fix: infer MiniMax vendor for MiniMax models

* Delete model/pricing_default_test.go

---------

Co-authored-by: duanxufu <duanxufu@rededa.com>
2026-07-14 20:32:48 +08:00
QuentinHsu 9a2d660316 fix(users): prevent large quota values from overflowing (#6134)
- widen the quota column and add consistent spacing between remaining and total values.
- extract quota rendering into a dedicated component and truncate oversized text within the cell.
- preserve full-value tooltips, progress indicators, and the zero-quota state.
2026-07-14 20:15:27 +08:00
Seefs b6b97a66e3 fix: purge authentication data on hard user deletion (#6168)
* fix: purge authentication data on hard user deletion

* fix: fail closed when 2FA status lookup fails

* fix: reject stale Telegram login callbacks

* fix(twofa): prevent concurrent backup code and lockout bypasses

* fix(auth): harden user deletion and Telegram verification
2026-07-14 14:25:54 +08:00
同語 7c28993f6b fix: list only channel models in unset price models tab (#6126)
Merge pull request #6126 from feitianbubu/fix/unset-tab-channel-models-only
2026-07-12 00:24:17 +08:00
feitianbubu 93e936f701 fix: list only channel models in unset price models tab 2026-07-11 23:41:11 +08:00
CaIon bde9b2f448 fix: harden unset price models tab batch copy, feedback, and memo equality
Persist committed editor drafts to the source model during batch copy so
targets never carry pricing the source would lose, surface loading/error
states for the enabled-models query, and compare saved* props in the
visual editor memo so rows leave the unset list reliably after save.
2026-07-11 22:57:22 +08:00
feitianbubu 8283df169e feat: add unset price models tab to model pricing settings (#6124)
* feat: add unset price models tab to model pricing settings

* feat: add unset price models tab translations
2026-07-11 22:48:02 +08:00
CaIon 7a2b9d86e8 feat: enhance model search functionality with status and sync filters 2026-07-11 22:36:09 +08:00
CaIon 92d3c9d18f fix: bound uncached remainder by prompt-max(cached,write) and forward compact prompt_cache_key 2026-07-11 22:18:26 +08:00
CaIon 48068ce923 feat: bill OpenAI cache_write_tokens at cache-creation price with zero clamp
Parse OpenAI's native cache_write_tokens (chat prompt_tokens_details /
responses input_tokens_details), bill it at the cache-creation ratio, and
clamp the uncached prompt remainder at zero since cached + cache-write can
exceed prompt_tokens. Propagate the field through chat/responses/claude
format conversions and tiered expression billing (cc variable).
2026-07-11 21:18:49 +08:00
Calcium-Ion c36418c863 feat: enhance text protocol conversion and advanced custom routing (#5825)
* refactor: consolidate relay protocol converters

* refactor relayconvert text converters

* feat: refine relay converters and advanced custom routing

* refactor: enhance logging and add thought signature handling for Gemini requests

* refactor: enhance channel cache and pricing endpoint handling for advanced custom models

* feat: preserve billing usage semantics

* feat: add protocol-aware billing usage

* Delete useless files

* chore: update action versions in workflow files

* chore: update Docker action versions in workflow files

* fix: harden billing usage settlement and hot-path route matching

- estimate Gemini completion tokens locally when billable usageMetadata is
  prompt-only but output content was received (e.g. client aborts the stream
  before the final chunk), and rebuild the attached billing_usage as estimated
  so settlement does not bill zero output tokens
- guard NewClaudeMessagesBillingUsage against all-zero ClaudeUsage, matching
  the OpenAI/Gemini constructors, so a zero billing_usage cannot override a
  non-zero top-level usage during settlement
- cache compiled advanced-custom route model regexes; they run on the request
  hot path and were recompiled per request
- move the effectiveBillingUsage remap to PostTextConsumeQuota only, and
  document that calculateTextQuotaSummary expects remapped usage
- document the updatePricingLock -> channelSyncLock lock ordering that
  InitChannelCache/CacheUpdateChannel rely on, and the aux-struct pitfall in
  GeminiChatResponse.UnmarshalJSON
2026-07-11 20:44:12 +08:00
CaIon 1250fb2eb5 fix: adjust margin for StatusBadge component in logs columns 2026-07-11 20:23:15 +08:00
CaIon e400619656 feat: enhance stale instance handling and update theme colors 2026-07-11 19:37:34 +08:00
CaIon 162f87925c feat: update theme colors 2026-07-11 19:25:04 +08:00
CaIon 6bbddb1046 feat(timing): add timing metrics display for stream logs and enhance localization 2026-07-11 15:32:35 +08:00
CaIon 1b1b23d1d0 revert: restore StatusBadge horizontal padding
Revert 6869cd94b (perf(web): align table badge spacing).
Restores px padding on status badges so usage-log timing/duration
pills are not flush against the edges.
2026-07-11 15:04:12 +08:00
CaIon 337169e0a4 revert: undo t0ng7u UI design-system refactor
Revert the following commits:
- 308e3e347 feat(web): polish themed data views and add task log details
- b2a890e75 fix: Fontsource asset resolution across workspace layouts
- 9d1ca545e refactor(web): refine data-table cards and pricing page layout
- 0918bdb49 refactor(web): consolidate design-system primitives and responsive data views
- 262ab9312 style(web): unify design system across default frontend
2026-07-11 14:51:54 +08:00
t0ng7u ad900bbba7 Merge remote-tracking branch 'origin/main' 2026-07-11 14:30:16 +08:00
t0ng7u 308e3e347a feat(web): polish themed data views and add task log details 2026-07-11 14:30:06 +08:00
CaIon 269e4ff390 feat(image): enhance image stream handling with client disconnect logic and billing adjustments 2026-07-11 13:14:22 +08:00
CaIon d9595831bf fix(billing): improve quota handling and error reporting for pre-consume operations 2026-07-11 13:14:22 +08:00
CaIon 621927f710 fix(billing): reject saturated pre-consume quota 2026-07-11 13:14:21 +08:00
t0ng7u b2a890e755 🐛 fix: Fontsource asset resolution across workspace layouts 2026-07-11 13:02:59 +08:00
Seefs dad57a6bb8 fix: sync codex field (#6018) 2026-07-11 11:04:15 +08:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 00f1cbb6df chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#6096)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.51.0 to 0.52.0.
- [Commits](https://github.com/golang/crypto/compare/v0.51.0...v0.52.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.52.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-11 10:53:05 +08:00
ca971413e9 fix(web): allow user-activated top navigation for custom home iframe (#5955)
The custom home page URL iframe only allows allow-forms/allow-popups/
allow-popups-to-escape-sandbox/allow-scripts, without allow-top-navigation*.
As a result, target="_top" nav/menu links inside the (admin-configured,
trusted) embedded page cannot navigate the top-level window on desktop
browsers, while some mobile browsers still allow it via allow-popups —
causing inconsistent behavior rather than an intended restriction.

Add allow-top-navigation-by-user-activation so user-clicked top-level
links work consistently across devices. This token only permits
user-activated top navigation and does NOT grant same-origin access,
so it avoids the security concern of allow-same-origin.

Co-authored-by: 贺. <kuang@M1.local>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-11 10:52:17 +08:00
t0ng7u 9d1ca545e2 ♻️ refactor(web): refine data-table cards and pricing page layout
Replace collapsible card details with always-visible label/value rows, add badge-list full display for cards, and polish pricing/channel toolbars and mobile cards.
2026-07-11 06:02:16 +08:00
t0ng7u 0918bdb49a ♻️ refactor(web): consolidate design-system primitives and responsive data views 2026-07-11 05:13:16 +08:00
t0ng7u 262ab93123 style(web): unify design system across default frontend
🔤 Typography
- Fix --font-sans stack: 'Public Sans Variable' was never applied (wrong family name), add CJK fallbacks (PingFang SC / Microsoft YaHei UI / Noto Sans SC)
- Sync <html lang> with i18n language for correct CJK glyph selection
- Remove dead fake font system (font-provider.tsx, config/fonts.ts, --font-inter/--font-manrope)
- Typography contract: 3-tier headings, arbitrary text-[10px]/[11px] → text-xs (46 files), no uppercase table headers, font-bold → font-semibold
- Numbers use tabular-nums only; font-mono reserved for keys/IDs/code (29 files)

🎨 Color discipline
- Retire StatusBadge string-hash rainbow (autoColor → neutral); all variants resolve to 5 semantic voices
- Add tintedBadgeClassMap as the single tinted-pill recipe
- Replace hardcoded emerald/amber/rose/sky classes with semantic tokens across ~30 files (timing badges, progress bars, system panels, pricing, rankings, log row tints)
- Drop all !important text overrides and [font-family:var(--font-body)] hacks

🧘 Motion restraint
- Remove admin entrance animations: table row stagger, card hover lift/shadow, button press scale, dashboard shimmer line
- Neuter page-transition stagger components into plain wrappers; page transitions reduced to pure opacity fade
- Decorative motion stays landing-only

📐 Shape
- Single radius source: --radius 1rem → 0.625rem
- Sparklines use solid chart tokens instead of decorative gradients
- PanelWrapper: border-only (no shadow), align radius with Card

📏 Guardrails
- Add "Design System Discipline" section (3.10.1) to web/default/AGENTS.md

 Verified: tsgo typecheck clean, rsbuild production build passes
2026-07-11 02:02:11 +08:00
同語 0cb741d8da perf(model-pricing): optimize upstream price sync tables (#6092)
Merge pull request #6092 from QuantumNous/perf/model-pricing-sync-table
2026-07-11 00:49:03 +08:00
QuentinHsu 6869cd94b2 perf(web): align table badge spacing
- remove built-in horizontal padding from status badges so table columns align with headers.
- drop legacy negative-margin compensation from badge cells and affected table renderers.
- clean touched table components to satisfy lint rules around type imports, keys, and JSX flow.
2026-07-11 00:28:21 +08:00
QuentinHsu 43783286e5 fix(model-pricing): polish sync channel dialog layout
- keep input focus and invalid rings inside the shared Input component to avoid clipping in constrained containers.
- make the sync channel selector table use a fixed header, internal body scrolling, and fixed pagination inside the dialog.
- align status cells with their header and translate channel status labels through existing i18n keys.
2026-07-10 23:56:18 +08:00