fix(openai): normalize API key outbound client identity - #284
Merged
Merged
Conversation
6 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
解决的问题与行为变化
User-Agent原样发给上游。Go 客户端因此可能出现Go-http-client/2.0,同时originator、version可能与客户端身份不配套。platform=openai的 API Key 账号默认使用现有 Codex 身份解析器生成配套的User-Agent、originator和version。版本跟随后台 Codex 版本同步;账号显式header_overrides仍有最终优先级。关联记录与来源
productioncf7398431cfd82ec1a9c7feca8a7b2b7f439d5c7。复现与验收
1.27.0,本地 mock upstream;本 PR 未部署生产。Go-http-client/2.0、浏览器/SDK UA 和旧版 Codex UA。User-Agent、originator、version来自同一规范身份;入站请求头仍保持原值;显式账号覆写和兼容性回滚开关保持有效。backend/internal/service/openai_apikey_identity_test.go覆盖 34 个用例,包含 HTTP、透传、WS、测试请求、动态版本、覆写、回滚开关和其他平台;同时更新两个既有转发断言。没有真实上游抓包,也没有声称风控或 429 已由 UA 触发。协议、调度或传输改动补充
实际验证
GOMAXPROCS=2 GOMEMLIMIT=3GiB go test -p 2 -tags=unit ./internal/service -run 'Test(OpenAIAPIKey.*Identity|AccountTestService_.*OpenAI|ProbeOpenAIAPIKey|.*CodexIdentity.*|.*OpenCode.*UserAgent.*|CommandCodeUpstream.*|.*HeaderOverride.*|.*AlphaSearch.*|.*Embeddings.*|.*CountTokens.*|.*OpenAIImages.*|ForwardAsAnthropic_ResponsesSupportedAccountStillUsesResponsesEndpoint|OpenAIGatewayService_APIKeyPassthrough_PreservesBodyAndUsesResponsesEndpoint)' -count=164885197d8eabb39256b5ab6023f11fa91e37654,相关 service 回归通过。CGO_ENABLED=0 GOMAXPROCS=2 GOMEMLIMIT=3GiB go build -p 2 -o /tmp/sub2api-identity-check ./cmd/servergit diff --checkgo test -tags=unit ./internal/service ./internal/config -count=1internal/config通过;service 中TestPriorityOAuthProfitUsesUserChargeAndTheoreticalCost的浮点精度断言在未修改的 production 基线也失败(期望4,实际3.9999999999999996)。本 PR 未修改该逻辑。golangci-lint可执行文件;本 PR 不声称这些检查通过。兼容性与运行影响
gateway.disable_codex_identity_enforcement=false的统一身份范围至 OpenAI API Key;设置为true时 API Key 恢复原有头透传,作为兼容性回滚入口。gateway.disable_codex_identity_enforcement=true回滚默认 API Key 身份统一。统一 UA 只能消除一类客户端身份差异,不保证上游不会因其他信号限流或风控。文档与用户可见变化
新增
docs/openai-outbound-identity.md说明身份优先级、覆盖范围和回滚开关。未部署、未发布 Release。Agent 使用声明
提交前自查