Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
150 commits
Select commit Hold shift + click to select a range
34e02de
Refactor request handling and related integrations
DR-lin-eng Jul 14, 2026
9efe31b
Refine request handling and response mapping
DR-lin-eng Jul 14, 2026
36849ea
Refine request handling and UI flow across the app
DR-lin-eng Jul 14, 2026
6b38bb0
Refactor request handling and update related UI flows
DR-lin-eng Jul 14, 2026
af2ab29
Add Redis-only mode for system logs
DR-lin-eng Jul 14, 2026
c68b92f
Add runtime override for user request log retention
DR-lin-eng Jul 14, 2026
6b7c51c
Add user usage stats and explicit system log clear-all support
DR-lin-eng Jul 14, 2026
4e1e720
Add global temp unschedulable settings and cleanup flow
DR-lin-eng Jul 15, 2026
afebc9a
Fix post-rebase validation issues
DR-lin-eng Jul 15, 2026
f6d2b1f
Refactor settings, cleanup, and admin console flows
DR-lin-eng Jul 15, 2026
2bcfa5f
Add stream mode performance setting and lazy failover state maps
DR-lin-eng Jul 15, 2026
6c2836b
Add batch admin APIs and richer ops dashboard snapshot
DR-lin-eng Jul 15, 2026
41e2613
Optimize account load batch cache keying and concurrency
DR-lin-eng Jul 15, 2026
12beeb6
Add generated image proxy and refresh image keepalive defaults
DR-lin-eng Jul 15, 2026
f5cb51a
Add Docker image workflow
DR-lin-eng Jul 15, 2026
9be3d0b
Fix backend lint violations
DR-lin-eng Jul 15, 2026
20598bb
Normalize empty image SSE keepalives
DR-lin-eng Jul 16, 2026
431241b
Fix Images pseudo-stream keepalives
DR-lin-eng Jul 16, 2026
5624ad8
Split dashboard snapshot loading to unblock fast stats rendering
DR-lin-eng Jul 16, 2026
56a679a
Refine API routing and admin UI behavior
DR-lin-eng Jul 16, 2026
56cd36c
Add account TTFT usage statistics
DR-lin-eng Jul 16, 2026
29f4bee
Optimize upstream billing cost scheduling
DR-lin-eng Jul 16, 2026
f13c16c
Bound async image task Redis pressure
DR-lin-eng Jul 16, 2026
a30081f
Fix admin batch query handler setup
DR-lin-eng Jul 16, 2026
ddd2296
Fix Images pseudo-stream header timeout
DR-lin-eng Jul 16, 2026
d13b789
Fix unit test admin service wiring
DR-lin-eng Jul 16, 2026
4e444ab
Fix non-transactional migration splitting
DR-lin-eng Jul 16, 2026
02eecae
Optimize upstream request hot paths
DR-lin-eng Jul 16, 2026
881096b
Add TTFT filtering and sorting to ops request details
DR-lin-eng Jul 16, 2026
91a3a34
Exclude image requests from TTFT metrics and add ops stats endpoint
DR-lin-eng Jul 17, 2026
f566a32
Support independent image rate multipliers for token billing
DR-lin-eng Jul 17, 2026
a8e2c0d
feat(frontend): 展示使用记录 Token 输出速度
BenjaminAaron196 Jul 16, 2026
36177bf
fix account last-used sorting
CRAZYShimakaze Jul 15, 2026
3e37ece
fix(apicompat): prevent Claude Code "Content block not found" on SSE …
Jul 14, 2026
cc6df42
Harden reviewed upstream PR integrations
DR-lin-eng Jul 17, 2026
15f4018
Fix post-sync lint regressions
DR-lin-eng Jul 17, 2026
983c584
Harden security audit request ownership and queue accounting
DR-lin-eng Jul 17, 2026
f8a2963
Fix settings tab sizing and label truncation
DR-lin-eng Jul 17, 2026
f1b26ac
Add hourly usage stats to admin account list
DR-lin-eng Jul 17, 2026
3d4e15b
fix: 完善上游 Sub2API 计费倍率探测与账号展示
yardbirds0 Jul 17, 2026
d67f022
fix: harden upstream billing sorting and bulk updates
yardbirds0 Jul 17, 2026
f94c126
Optimize upstream billing rate sorting
DR-lin-eng Jul 17, 2026
6783a9b
Fix upstream billing metadata validation lint
DR-lin-eng Jul 17, 2026
8598af1
feat(gateway): 归一化 thinking 参数使思考摘要对客户端可见
Eyre921 Jul 17, 2026
7604470
Optimize thinking display normalization hot path
DR-lin-eng Jul 17, 2026
6daf217
Separate Codex manifest routes from local models endpoints
DR-lin-eng Jul 17, 2026
90446fe
修复 GPT-5.6 Responses 显式缓存参数错误
dftian478 Jul 15, 2026
3d852aa
fix(openai): allow disabling PAT web search routing
SatellaPoi Jul 16, 2026
a5c9a5b
[verified] feat: add API key usage table to user dashboard
wucm667 Jul 15, 2026
45ce7eb
fix(auth): avoid binding sessions to untrusted proxy IPs
aomsir Jul 17, 2026
b917230
feat(api-key): add per-key concurrency limits
adamglin0 Jul 13, 2026
e6cbb5c
test(api-key): update concurrency response contracts
adamglin0 Jul 13, 2026
2562596
fix(migrations): renumber api key concurrency migration
adamglin0 Jul 17, 2026
5ce9c6e
fix: retry transient OpenAI failures before failover
Jul 15, 2026
9f3ed22
fix: retry passthrough body failures before failover
Jul 15, 2026
c4d43b4
fix: pin passthrough response retries to original account
Jul 15, 2026
e5dc956
fix: harden OpenAI passthrough failover boundaries
Jul 15, 2026
e9f2ef2
fix: preserve final passthrough refusal response
Jul 15, 2026
1b657be
test: align failover integration expectations
Jul 15, 2026
1de113d
fix: preserve v0.1.156 failover sanitization
Jul 15, 2026
c417c20
fix: harden OpenAI failover retry state
Jul 15, 2026
11c4a88
fix: ignore build suffix in update checks
Jul 15, 2026
a5e51d0
fix: 过滤入口拒绝日志并强化鉴权边界
BenjaminAaron196 Jul 17, 2026
af9d2bc
fix: 修复CI检查问题
BenjaminAaron196 Jul 17, 2026
21c1751
perf: harden merged PR hot paths
DR-lin-eng Jul 17, 2026
a2fc8f3
fix(ops): use adaptive byte units for memory usage display
feitianbubu Jul 10, 2026
8df8e13
fix(frontend): default Codex/CC Switch key templates to gpt-5.6
DylanChiang-Dev Jul 11, 2026
155429c
fix(dashboard): include cache tokens in token card breakdown
feitianbubu Jul 11, 2026
b1135c1
fix(dashboard): render full-card empty state for model distribution c…
feitianbubu Jul 11, 2026
8475d0e
fix(announcements): use proper empty-state copy instead of error message
feitianbubu Jul 11, 2026
4190030
fix(ops): show neutral SLA card when window has no requests
feitianbubu Jul 11, 2026
b69829d
Fix upstream audit findings
Jul 11, 2026
b751f33
fix(usage): make last-24-hours preset a true rolling window
feitianbubu Jul 11, 2026
0620dab
fix(billing): apply service tier multipliers to channel pricing
AixLau Jul 11, 2026
f05b8e7
feat: expose API key monitoring metadata (#4092)
DR-lin-eng Jul 18, 2026
bca1041
fix(openai): harden messages failover and compact recovery (#3808)
DR-lin-eng Jul 18, 2026
88fa72e
feat(scheduler): merge bounded candidate index engine (#4112)
DR-lin-eng Jul 18, 2026
1868475
fix(subscription): enforce progress ownership in query (#4027)
DR-lin-eng Jul 18, 2026
7262b14
fix(usage): preserve calendar boundaries across DST (#4034)
DR-lin-eng Jul 18, 2026
b2fa6a4
fix(billing): apply service tier after channel pricing (#4040)
DR-lin-eng Jul 18, 2026
6c74bc2
test: align merged PR regression fixtures
DR-lin-eng Jul 18, 2026
689cc55
Add composite group routing
heathermhuang Jun 30, 2026
c8b0c89
Harden composite group product surfaces
heathermhuang Jul 1, 2026
5c4e815
Add composite group route registry
heathermhuang Jul 1, 2026
75ef638
Fix composite route lint issues
heathermhuang Jul 1, 2026
b84319f
Fix composite route alias attribution
heathermhuang Jul 1, 2026
a463619
Build composite subscription bucket two
heathermhuang Jul 1, 2026
70bffa6
Align Grok composite example with live model
heathermhuang Jul 1, 2026
a7b1f1c
Fix composite model defaults for linked platforms
heathermhuang Jul 6, 2026
3a94b5b
Fix composite Grok video status routing
heathermhuang Jul 6, 2026
5707dbf
fix: allow composite grok messages routing
heathermhuang Jul 7, 2026
0c10788
fix: allow composite grok chat completions
heathermhuang Jul 7, 2026
b7fa40e
test: align composite route contracts after rebase
heathermhuang Jul 16, 2026
6bfc9d4
perf: cache composite route snapshots
DR-lin-eng Jul 18, 2026
03d37b8
perf(openai): reduce merged recovery overhead
DR-lin-eng Jul 18, 2026
f5120d2
fix: align post-merge generated code and lint
DR-lin-eng Jul 18, 2026
7b65f3e
Add local captcha support to auth and settings
DR-lin-eng Jul 18, 2026
aa69ca9
Add credential-key browser flow for auth requests
DR-lin-eng Jul 18, 2026
362b393
Remove sponsor section from README
DR-lin-eng Jul 18, 2026
d3a2417
Refine admin metrics and workflow handling across the app
DR-lin-eng Jul 18, 2026
2849836
test(perf): benchmark ingress reject hot paths
DR-lin-eng Jul 18, 2026
eb229c1
fix(monitor): extract anthropic text blocks
mark-ly-wang Apr 25, 2026
53f5ea1
perf(monitor): avoid anthropic response copies
DR-lin-eng Jul 18, 2026
17c892f
Support forced OpenAI image API routing for Responses
DR-lin-eng Jul 18, 2026
0d752a8
fix(gateway): enforce SSE response content types
DR-lin-eng Jul 18, 2026
211f774
feat: bridge Responses image_generation to Images API
DR-lin-eng Jul 18, 2026
d0b0bca
Merge upstream/main with performance safeguards
DR-lin-eng Jul 18, 2026
303b1e4
Refine image studio workflow and auth handling
DR-lin-eng Jul 19, 2026
7b84865
Add group ID support to channel monitors
DR-lin-eng Jul 19, 2026
eec802e
Refactor workflow handling and image pipeline updates
DR-lin-eng Jul 19, 2026
86b5c36
Add configurable client IP resolution settings
DR-lin-eng Jul 19, 2026
5ccfbd0
Limit and evict local captcha challenges with Redis scripts
DR-lin-eng Jul 19, 2026
a78c94a
Fix Cap endpoint lint errors
DR-lin-eng Jul 19, 2026
e7fa852
Add redeem code usage tracking for OAuth redemption
DR-lin-eng Jul 19, 2026
e855573
Stabilize global limiter test
DR-lin-eng Jul 19, 2026
3622eea
Add scoped admin API keys and refresh token cookies
DR-lin-eng Jul 19, 2026
9554b49
Fallback OpenAI Responses WebSocket 426s to HTTP SSE
DR-lin-eng Jul 19, 2026
7b7fe15
Support composite groups for forced OpenAI image tool routing
DR-lin-eng Jul 19, 2026
cebfda3
Add explicit OpenAI test modes and custom prompts
DR-lin-eng Jul 20, 2026
0c38338
Refine OAuth claim formatting and update callback token tests
DR-lin-eng Jul 20, 2026
b50c75f
Add usage detail modal and video billing fields
DR-lin-eng Jul 20, 2026
96b6220
Enforce seven-day browser session minimum for refresh tokens
DR-lin-eng Jul 20, 2026
da84660
Add user usage detail visibility setting
DR-lin-eng Jul 20, 2026
8debd43
Use TTFT for passive channel monitor latency
DR-lin-eng Jul 20, 2026
deabcc1
Merge upstream main with compatibility and performance safeguards
DR-lin-eng Jul 20, 2026
aa879f6
Merge latest upstream fixes and harden build path
DR-lin-eng Jul 20, 2026
3bc8c75
Merge upstream version 0.1.162
DR-lin-eng Jul 20, 2026
9132fe7
Sanitize OpenAI Responses input IDs across the gateway
DR-lin-eng Jul 20, 2026
1647d25
Handle concurrent index classification for notx migrations
DR-lin-eng Jul 20, 2026
e0f562d
Compact overlong OpenAI call IDs in gateway sanitization
DR-lin-eng Jul 20, 2026
39dbf59
Handle overlong Responses item IDs by dropping or compacting them
DR-lin-eng Jul 20, 2026
905b8a9
Add auto-disable on upstream insufficient balance
DR-lin-eng Jul 20, 2026
08eabe5
Refactor failover helpers and batch api key last-used updates
DR-lin-eng Jul 21, 2026
3be0016
Merge upstream main with compatibility and performance safeguards
DR-lin-eng Jul 21, 2026
cca5a75
Merge upstream main with compatibility and performance safeguards
DR-lin-eng Jul 22, 2026
30525bc
Remove obsolete tracked artifacts
DR-lin-eng Jul 22, 2026
0926ca6
Preserve load factor clears and refine OpenAI scheduling
DR-lin-eng Jul 22, 2026
33f1749
Implement upstream provider routing and admin configuration updates
DR-lin-eng Jul 22, 2026
8ea57c3
Fix integration test migration paths
DR-lin-eng Jul 22, 2026
10b4070
Merge upstream main with Grok compatibility and performance safeguards
DR-lin-eng Jul 22, 2026
153e1de
Optimize ops dashboard metrics queries
DR-lin-eng Jul 22, 2026
36b94df
Refactor backend modules and update frontend integrations
DR-lin-eng Jul 22, 2026
b23353b
修正ci错误
DR-lin-eng Jul 22, 2026
436a957
Handle Agent Identity authentication failures and quarantine accounts
DR-lin-eng Jul 23, 2026
34a49ee
Merge upstream main through v0.1.164
DR-lin-eng Jul 23, 2026
e266a2b
Limit Redis idle connections and correct pool usage metrics
DR-lin-eng Jul 23, 2026
92d4e3c
Raise goroutine alert thresholds and add coverage
DR-lin-eng Jul 23, 2026
c216cfd
Balance concurrent OpenAI content session requests
DR-lin-eng Jul 23, 2026
785b63a
Add type assertion check for account scheduler test
DR-lin-eng Jul 23, 2026
4cdbd36
Preserve Redis health accuracy in ops dashboard
DR-lin-eng Jul 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
10 changes: 10 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,16 @@ node_modules/

# Go build cache (will be built in container)
backend/vendor/
.gocache/
backend/.cache/
backend/.gocache/
backend/backend/
backend/internal/web/dist/

# Local frontend compiler artifacts
frontend/*.tsbuildinfo
frontend/vite.config.js
frontend/vite.config.d.ts

# Test files
*_test.go
Expand Down
85 changes: 85 additions & 0 deletions .github/workflows/docker-image.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
name: Docker Image

on:
push:
branches:
- main
pull_request:
branches:
- main
workflow_dispatch:

permissions:
contents: read
packages: write

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:
name: Build and publish image
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Normalize GHCR image name
id: image
run: echo "name=ghcr.io/${GITHUB_REPOSITORY,,}" >> "$GITHUB_OUTPUT"

- name: Set up QEMU
if: github.event_name != 'pull_request'
uses: docker/setup-qemu-action@v3

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ steps.image.outputs.name }}
tags: |
type=ref,event=branch
type=ref,event=pr
type=sha,prefix=sha-
type=raw,value=latest,enable={{is_default_branch}}

- name: Log in to GitHub Container Registry
if: github.event_name != 'pull_request'
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Build Docker image
if: github.event_name == 'pull_request'
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
platforms: linux/amd64
push: false
build-args: |
COMMIT=${{ github.sha }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha,scope=docker-image

- name: Build and push Docker image
if: github.event_name != 'pull_request'
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
platforms: linux/amd64,linux/arm64
push: true
build-args: |
COMMIT=${{ github.sha }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha,scope=docker-image
cache-to: type=gha,mode=max,scope=docker-image
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -135,7 +135,9 @@ docs/*
!docs/PAYMENT.md
!docs/PAYMENT_CN.md
!docs/ADMIN_PAYMENT_INTEGRATION_API.md
!docs/ADMIN_API.md
!docs/ASYNC_IMAGE_TASKS.md
!docs/SCHEDULER_CANDIDATE_INDEX_OPTIMIZATION_CN.md
!docs/legal/
!docs/legal/*.md
.serena/
Expand Down
2 changes: 2 additions & 0 deletions .goreleaser.simple.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,8 @@ dockers:
use: buildx
extra_files:
- deploy/docker-entrypoint.sh
- backend/resources/model-pricing/README.md
- backend/resources/model-pricing/model_prices_and_context_window.json
build_flag_templates:
- "--platform=linux/amd64"
- "--label=org.opencontainers.image.version={{ .Version }}"
Expand Down
8 changes: 8 additions & 0 deletions .goreleaser.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,8 @@ dockers:
use: buildx
extra_files:
- deploy/docker-entrypoint.sh
- backend/resources/model-pricing/README.md
- backend/resources/model-pricing/model_prices_and_context_window.json
build_flag_templates:
- "--platform=linux/amd64"
- "--label=org.opencontainers.image.version={{ .Version }}"
Expand All @@ -80,6 +82,8 @@ dockers:
use: buildx
extra_files:
- deploy/docker-entrypoint.sh
- backend/resources/model-pricing/README.md
- backend/resources/model-pricing/model_prices_and_context_window.json
build_flag_templates:
- "--platform=linux/arm64"
- "--label=org.opencontainers.image.version={{ .Version }}"
Expand All @@ -95,6 +99,8 @@ dockers:
use: buildx
extra_files:
- deploy/docker-entrypoint.sh
- backend/resources/model-pricing/README.md
- backend/resources/model-pricing/model_prices_and_context_window.json
build_flag_templates:
- "--platform=linux/amd64"
- "--label=org.opencontainers.image.version={{ .Version }}"
Expand All @@ -110,6 +116,8 @@ dockers:
use: buildx
extra_files:
- deploy/docker-entrypoint.sh
- backend/resources/model-pricing/README.md
- backend/resources/model-pricing/model_prices_and_context_window.json
build_flag_templates:
- "--platform=linux/arm64"
- "--label=org.opencontainers.image.version={{ .Version }}"
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ RUN --mount=type=cache,id=sub2api-gomod,target=/go/pkg/mod \
COPY backend/ ./

# Copy frontend dist from previous stage (must be after backend copy to avoid being overwritten)
COPY --from=frontend-builder /app/backend/internal/web/dist ./internal/web/dist
COPY --from=frontend-builder /app/backend/internal/transport/webassets/dist ./internal/transport/webassets/dist

# Build the binary (BuildType=release for CI builds, embed frontend)
# Version precedence: build arg VERSION > exact git tag > cmd/server/VERSION
Expand Down
1 change: 1 addition & 0 deletions Dockerfile.goreleaser
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ WORKDIR /app

# Copy pre-built binary from GoReleaser
COPY sub2api /app/sub2api
COPY backend/resources/model-pricing /app/resources/model-pricing

# Create data directory
RUN mkdir -p /app/data && chown -R sub2api:sub2api /app
Expand Down
23 changes: 5 additions & 18 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -183,11 +183,6 @@ Model authenticity: no content intervention or secondary filtering — experienc
</td>
</tr>

<tr>
<td width="180"><a href="https://nagora.ai/"><img src="assets/partners/logos/nagora.png" alt="Nagora" width="150"></a></td>
<td><a href="https://nagora.ai/">Nagora</a> is a multi-model AI API gateway built for developers and teams. With a single account and API key, you can access more than 26 leading text and image models through one unified interface. It is compatible with OpenAI, Anthropic, and Gemini protocols and integrates seamlessly with development tools such as Claude Code, Codex, and Gemini CLI. The platform provides intelligent routing, automatic failover, transparent pricing, and consolidated billing, along with budget management, rate limiting, and concurrency controls. This makes AI usage more reliable and manageable across individual development, team collaboration, and production environments. No changes to your existing application are required. Simply replace the Base URL and API key to complete the integration in as little as one minute.</td>
</tr>

</table>

## Overview
Expand Down Expand Up @@ -395,7 +390,7 @@ openssl rand -hex 32

```bash
# 4. Create data directories (for local version)
mkdir -p data postgres_data redis_data
mkdir -p data postgres_data

# 5. Start all services
# Option A: Local directory version (recommended - easy migration)
Expand Down Expand Up @@ -470,7 +465,7 @@ docker compose -f docker-compose.local.yml logs -f

# Remove all data (caution!)
docker compose -f docker-compose.local.yml down
rm -rf data/ postgres_data/ redis_data/
rm -rf data/ postgres_data/
```

---
Expand Down Expand Up @@ -516,7 +511,7 @@ npm install -g pnpm
cd frontend
pnpm install
pnpm run build
# Output will be in ../backend/internal/web/dist/
# Output will be in ../backend/internal/transport/webassets/dist/

# 4. Build backend with embedded frontend
cd ../backend
Expand Down Expand Up @@ -580,18 +575,10 @@ Additional security-related options are available in `config.yaml`:
- `security.response_headers.enabled` to enable configurable response header filtering (disabled uses default allowlist)
- `security.csp` to control Content-Security-Policy headers
- `billing.circuit_breaker` to fail closed on billing errors
- `security.trust_forwarded_ip_for_api_key_acl` enables legacy raw forwarded-header takeover (enabled by default for upgrade compatibility); disable it to enforce `server.trusted_proxies`, which should contain only the exact proxy CIDRs that connect directly to Sub2API
- `security.forwarded_client_ip_headers` configures up to 16 third-party CDN client-IP header names; they are checked in order before the built-in headers only while legacy takeover is enabled
- Client IP resolution modes in admin settings for automatic reverse-proxy compatibility, strict proxy trust, or direct-peer-only operation
- `server.trusted_proxies` for optional additional trusted proxy CIDRs/IPs
- `turnstile.required` to require Turnstile in release mode

Custom client-IP headers can be set in YAML or as a comma-separated environment variable:

```bash
SECURITY_FORWARDED_CLIENT_IP_HEADERS=True-Client-IP,X-CDN-Client-IP
```

Header names are validated, canonicalized, and de-duplicated. The admin security settings can update the list without a restart; new installations persist YAML/environment defaults and existing installations backfill a missing database value. When legacy takeover is disabled, all custom and built-in raw forwarding headers are ignored and Gin uses only `server.trusted_proxies`. While takeover is enabled, firewall the origin to CDN/proxy addresses and make the edge overwrite every trusted client-IP header. See [`deploy/EDGE_SECURITY.md`](deploy/EDGE_SECURITY.md) for the complete migration and trust-boundary rules.

**⚠️ Security Warning: HTTP URL Configuration**

When `security.url_allowlist.enabled=false`, the system performs minimal URL validation and **allows HTTP URLs by default** (dev-friendly mode; Docker Compose deployments use the same default). For production, explicitly tighten this to HTTPS-only:
Expand Down
24 changes: 6 additions & 18 deletions README_CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -186,11 +186,6 @@
</td>
</tr>

<tr>
<td width="180"><a href="https://nagora.ai/"><img src="assets/partners/logos/nagora.png" alt="Nagora" width="150"></a></td>
<td><a href="https://nagora.ai/">Nagora</a> 是专为开发者和团队打造的多模型 AI API 网关。通过一个账户和一枚 API Key,即可统一调用 26+ 款主流文本与图像模型,兼容 OpenAI、Anthropic 与 Gemini 协议,并可无缝接入 Claude Code、Codex、Gemini CLI 等开发工具。平台提供智能路由、自动故障转移、透明计费与统一账单,同时支持预算、限速、并发控制,让个人开发、团队协作和生产环境中的 AI 调用更稳定、更可控。无需改造现有应用,只需替换 Base URL 与 API Key,最快 1 分钟即可完成接入。</td>
</tr>

</table>

## 项目概述
Expand All @@ -207,6 +202,7 @@ Sub2API 是一个 AI API 网关平台,用于分发和管理 AI 产品订阅的
- **速率限制** - 可配置的请求和 Token 速率限制
- **内置支付系统** - 支持 EasyPay 易支付、支付宝官方、微信官方、Stripe,用户自助充值,无需独立部署支付服务([配置指南](docs/PAYMENT_CN.md))
- **管理后台** - Web 界面进行监控和管理
- **管理员 API 集成** - 支持细粒度 scoped Admin API Key、有效期、轮换和撤销([调用文档](docs/ADMIN_API.md))
- **外部系统集成** - 支持通过 iframe 嵌入外部系统(如工单等),扩展管理后台功能

## 生态项目
Expand Down Expand Up @@ -397,7 +393,7 @@ openssl rand -hex 32

```bash
# 4. 创建数据目录(本地版)
mkdir -p data postgres_data redis_data
mkdir -p data postgres_data

# 5. 启动所有服务
# 选项 A:本地目录版(推荐 - 易于迁移)
Expand Down Expand Up @@ -484,7 +480,7 @@ docker compose -f docker-compose.local.yml logs -f

# 删除所有数据(谨慎!)
docker compose -f docker-compose.local.yml down
rm -rf data/ postgres_data/ redis_data/
rm -rf data/ postgres_data/
```

---
Expand Down Expand Up @@ -530,7 +526,7 @@ npm install -g pnpm
cd frontend
pnpm install
pnpm run build
# 构建产物输出到 ../backend/internal/web/dist/
# 构建产物输出到 ../backend/internal/transport/webassets/dist/

# 4. 编译后端(嵌入前端)
cd ../backend
Expand Down Expand Up @@ -614,18 +610,10 @@ gateway:
- `security.response_headers.enabled` 可启用可配置响应头过滤(关闭时使用默认白名单)
- `security.csp` 配置 Content-Security-Policy
- `billing.circuit_breaker` 计费异常时 fail-closed
- `security.trust_forwarded_ip_for_api_key_acl` 控制旧版原始转发头接管(为升级兼容默认开启);关闭后严格使用 `server.trusted_proxies`,其中只应填写直接连接 Sub2API 的精确代理 CIDR
- `security.forwarded_client_ip_headers` 最多配置 16 个第三方 CDN 客户端 IP 请求头;仅在旧版接管开启时按顺序优先于内置请求头解析
- 管理后台提供客户端 IP 自动兼容、严格可信代理和仅直连三种解析模式
- `server.trusted_proxies` 可配置额外可信代理 CIDR/IP
- `turnstile.required` 在 release 模式强制启用 Turnstile

自定义客户端 IP 请求头可通过 YAML 配置,也可使用逗号分隔的环境变量:

```bash
SECURITY_FORWARDED_CLIENT_IP_HEADERS=True-Client-IP,X-CDN-Client-IP
```

请求头名称会经过合法性校验、规范化和大小写无关去重。管理员可在安全设置中动态更新列表,无需重启;新安装会持久化 YAML/环境变量默认值,旧安装缺少数据库字段时会自动回填。关闭旧版接管后,自定义头和内置原始转发头均被忽略,只使用 `server.trusted_proxies`。开启接管时必须限制源站仅允许 CDN/代理访问,并确保边缘代理覆盖所有受信客户端 IP 请求头。完整迁移规则和信任边界见 [`deploy/EDGE_SECURITY.md`](deploy/EDGE_SECURITY.md)。

**网关防御纵深建议(重点)**

- `gateway.upstream_response_read_max_bytes`:限制非流式上游响应读取大小(默认 `8MB`),用于防止异常响应导致内存放大。
Expand Down
23 changes: 5 additions & 18 deletions README_JA.md
Original file line number Diff line number Diff line change
Expand Up @@ -181,11 +181,6 @@
</td>
</tr>

<tr>
<td width="180"><a href="https://nagora.ai/"><img src="assets/partners/logos/nagora.png" alt="Nagora" width="150"></a></td>
<td><a href="https://nagora.ai/">Nagora</a>は、開発者やチーム向けに設計されたマルチモデルAI APIゲートウェイです。1つのアカウントと1つのAPIキーだけで、26種類以上の主要なテキストモデルおよび画像モデルを一元的に利用できます。OpenAI、Anthropic、Geminiの各プロトコルに対応し、Claude Code、Codex、Gemini CLIなどの開発ツールにもシームレスに接続できます。 プラットフォームには、インテリジェントルーティング、自動フェイルオーバー、透明性の高い料金体系、請求の一元管理に加え、予算管理、レート制限、同時実行数の制御機能が備わっています。これにより、個人開発、チームでの共同作業、本番環境におけるAI APIの利用を、より安定的かつ柔軟に管理できます。 既存のアプリケーションを改修する必要はありません。Base URLとAPIキーを置き換えるだけで、最短1分で導入を完了できます。</td>
</tr>

</table>

## 概要
Expand Down Expand Up @@ -392,7 +387,7 @@ openssl rand -hex 32

```bash
# 4. データディレクトリを作成(ローカルバージョンの場合)
mkdir -p data postgres_data redis_data
mkdir -p data postgres_data

# 5. すべてのサービスを起動
# オプション A: ローカルディレクトリバージョン(推奨 - 移行が容易)
Expand Down Expand Up @@ -467,7 +462,7 @@ docker compose -f docker-compose.local.yml logs -f

# すべてのデータを削除(注意!)
docker compose -f docker-compose.local.yml down
rm -rf data/ postgres_data/ redis_data/
rm -rf data/ postgres_data/
```

---
Expand Down Expand Up @@ -513,7 +508,7 @@ npm install -g pnpm
cd frontend
pnpm install
pnpm run build
# 出力先: ../backend/internal/web/dist/
# 出力先: ../backend/internal/transport/webassets/dist/

# 4. フロントエンドを組み込んだバックエンドをビルド
cd ../backend
Expand Down Expand Up @@ -576,18 +571,10 @@ default:
- `security.response_headers.enabled` - 設定可能なレスポンスヘッダーフィルタリングを有効化(無効時はデフォルトの許可リストを使用)
- `security.csp` - Content-Security-Policy ヘッダーの制御
- `billing.circuit_breaker` - 課金エラー時にフェイルクローズ
- `security.trust_forwarded_ip_for_api_key_acl` - 従来の生転送ヘッダーによる上書きを制御(アップグレード互換性のため既定で有効)。無効にすると `server.trusted_proxies` を厳格に使用し、Sub2API に直接接続するプロキシの正確な CIDR のみを指定
- `security.forwarded_client_ip_headers` - サードパーティ CDN のクライアント IP ヘッダーを最大 16 個指定。従来モードが有効な場合のみ、設定順で組み込みヘッダーより先に評価
- 管理画面でクライアント IP の自動互換、厳格な信頼済みプロキシ、直接接続のみの各モードを設定
- `server.trusted_proxies` - 追加の信頼済みプロキシ CIDR/IP
- `turnstile.required` - リリースモードでの Turnstile 必須化

カスタムクライアント IP ヘッダーは YAML またはカンマ区切りの環境変数で設定できます:

```bash
SECURITY_FORWARDED_CLIENT_IP_HEADERS=True-Client-IP,X-CDN-Client-IP
```

ヘッダー名は検証、正規化、大小文字を区別しない重複排除が行われます。管理画面のセキュリティ設定から再起動せずに更新でき、新規インストールでは YAML/環境変数の既定値を保存し、既存環境ではデータベース値がない場合に補完します。従来モードを無効にするとカスタムおよび組み込みの生転送ヘッダーはすべて無視され、`server.trusted_proxies` のみを使用します。有効にする場合はオリジンへの接続元を CDN/プロキシに制限し、エッジで信頼する全クライアント IP ヘッダーを上書きしてください。移行規則と信頼境界の詳細は [`deploy/EDGE_SECURITY.md`](deploy/EDGE_SECURITY.md) を参照してください。

**⚠️ セキュリティ警告: HTTP URL 設定**

`security.url_allowlist.enabled=false` の場合、システムは最小限の URL バリデーションのみを行い、**デフォルトで HTTP URL を許可**します(開発フレンドリーモード。Docker Compose デプロイのデフォルトも同じです)。本番環境では、以下のように明示的に HTTPS のみに制限することを推奨します:
Expand Down
Binary file removed assets/partners/logos/nagora.png
Binary file not shown.
Loading
Loading