You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit b2935dd
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: README.en.md
+11-2Lines changed: 11 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,6 +17,7 @@ upstream channels, with a shared credential pool, unified scheduling, and per-us
17
17
-**Cached-token accounting**: TRAE's `cache_read_input_tokens` / `cache_creation_input_tokens` are mapped to per-request `cached_tokens` and surfaced in stats
18
18
-**Three-state health + tiered cooldowns**: quota exhausted 12h, rate-limited 60s, consecutive errors 10m, dead session disabled; model-scoped limits sideline only that model
19
19
-**Shared credential pool**: admins maintain credentials, everyone shares them; usage tracked per user
20
+
-**Three-role accounts**: `admin` / `operator` / `viewer` stored in SQLite. New users get a one-time activation link to set their own password (no shared initial secret) and must change an admin-reset password on first login; changing a role or disabling an account revokes its sessions immediately. Logins and write operations are audited
-**Per-credential pause**: "Pause" removes one credential from *chat traffic only* — probing, refresh, check-in, growth and activity tasks keep running (they honor only the system hard-disable `disabled`). Distinct from "Disabled", which means the upstream rejected the session and needs re-login + "Restore"
22
23
-**Activity reporting** (CodeBuddy only, **off by default**): `ACTIVITY_REPORT_ENABLED=true` posts one chat-activity event per account per day to keep the growth-center streak alive. The upstream needs a `userId` and silently drops reports without one (HTTP 200 `{"code":0}`, streak unchanged); when the credential has no `user_id`, the gateway falls back to the bearer JWT `sub`. Upstream-internal and may break without notice — not a reliability feature (terms forbid scripted tampering: disqualification + clawback)
@@ -34,10 +35,11 @@ upstream channels, with a shared credential pool, unified scheduling, and per-us
34
35
35
36
```bash
36
37
uv sync
37
-
uv run python scripts/hash_password.py admin # prompts for a password
38
+
# Create the first admin (add the rest from the "Users" page later)
39
+
uv run python scripts/create_user.py admin --role admin
Point any OpenAI-compatible client at `http://127.0.0.1:8000/v1`.
54
56
57
+
> `scripts/create_user.py` writes directly to SQLite (`--db`, or `DATA_DIR`; default
58
+
> `data/coding2api.sqlite3`). On startup, an existing `secrets/users.txt` is imported
59
+
> once (existing usernames are never overwritten), and `ADMIN_USERNAMES` promotes the
60
+
> named users to `admin`. Both are **bootstrap-only** afterwards — day-to-day user and
61
+
> role management happens on the *Users* page. See [`README.md`](README.md) (Chinese)
62
+
> for the role matrix, activation flow, and the audit log.
63
+
55
64
### Responses API (Codex CLI)
56
65
57
66
`POST /v1/responses` serves a Responses subset for clients that only speak the Responses API, such as the [Codex CLI](https://github.com/openai/codex). It shares the same credential selection, cooldown, rotation, accounting, and session affinity as `/v1/chat/completions`; only the inbound mapping and outbound translation differ (see [`TECHNICAL.md` §3.7](TECHNICAL.md), in Chinese):
0 commit comments