Revert mint path to pre-browser PKCE baseline (2e833f2).

Restore HTTP-only SSO OAuth with curl_cffi then std requests fallback;
remove browser PKCE prefer/fallback knobs and mint_from_sso_browser.
This commit is contained in:
chaos committed 2026-07-14 14:06:13 +08:00
1 parent d74d14d3f4
commit 4abdc8aa4a
5 files changed
+51 -751

No files matched your search

+9 -59
View File
@@ -72,49 +72,13 @@ def _mint_tokens(
log: Callable[[str], None],
proxy: str | None,
) -> dict[str, Any]:
"""铸造策略(仅 HTTP;浏览器/设备码默认关):
1. 仅当 cpa_prefer_browser_mint=true 且有 page:先浏览器 PKCE
2. HTTP SSO→OAuth(curl_cffi,短超时)— 默认唯一主路径
3. 仅当 cpa_allow_browser_fallback=true 且 HTTP 失败:浏览器 PKCE
4. 可选设备码(通常无 referrer,默认关)
"""
from oidc_mint.oauth_code import (
OAuthCodeError,
_is_http_tls_failure,
mint_from_sso,
mint_from_sso_browser,
normalize_sso_cookie,
)
"""优先 SSO 授权码;可选回退设备码。"""
from oidc_mint.oauth_code import OAuthCodeError, mint_from_sso, normalize_sso_cookie
sso_token = normalize_sso_cookie(sso or "")
prefer_sso = bool(cfg.get("cpa_prefer_sso_oauth", True))
allow_browser = bool(cfg.get("cpa_allow_browser_fallback", False))
# 默认 False:不走浏览器优先
prefer_browser = bool(cfg.get("cpa_prefer_browser_mint", False))
allow_device = bool(cfg.get("cpa_allow_device_fallback", False))
timeout = float(cfg.get("mint_timeout_sec", 300) or 300)
require_ref = bool(cfg.get("cpa_require_referrer", True))
http_err: Exception | None = None
browser_timeout = min(timeout, float(cfg.get("cpa_browser_mint_timeout_sec", 90) or 90))
def _browser_mint(reason: str) -> dict[str, Any]:
log(f"[cpa] 浏览器 PKCE 铸造({reason})")
return mint_from_sso_browser(
sso_token,
page,
log=lambda m: log(f"[Debug] {m}"),
require_referrer=require_ref,
timeout_sec=browser_timeout,
)
# 路径 A:有 page 时优先浏览器(最稳,不依赖 Python→auth.x.ai 直连)
if prefer_sso and sso_token and allow_browser and page is not None and prefer_browser:
try:
return _browser_mint("优先浏览器,绕开 Python 直连 auth.x.ai")
except Exception as exc: # noqa: BLE001
log(f"[!] 浏览器 PKCE 优先路径失败: {exc}")
log("[cpa] 继续尝试 HTTP SSO→OAuth")
if prefer_sso and sso_token:
log("[cpa] 使用 SSO→OAuth(PKCE, referrer=grok-build)")
@@ -123,35 +87,21 @@ def _mint_tokens(
sso_token,
proxy=proxy,
log=lambda m: log(f"[Debug] {m}"),
require_referrer=require_ref,
require_referrer=bool(cfg.get("cpa_require_referrer", True)),
)
except OAuthCodeError as exc:
http_err = exc
log(f"[!] SSO→OAuth 失败: {exc}")
if not allow_device:
raise
log("[cpa] 回退设备码铸造(可能缺 referrer)")
except Exception as exc: # noqa: BLE001
http_err = exc
log(f"[!] SSO→OAuth 异常: {exc}")
# HTTP 失败后:有 page+sso 再试浏览器(若优先路径没走过或当时失败)
if allow_browser and page is not None and sso_token and http_err is not None:
why = "TLS/连接/超时" if _is_http_tls_failure(http_err) else "HTTP"
try:
return _browser_mint(f"{why}失败后回退")
except Exception as exc: # noqa: BLE001
log(f"[!] 浏览器 PKCE 失败: {exc}")
if not allow_device:
raise
log("[cpa] 继续回退设备码铸造(可能缺 referrer)")
elif http_err is not None and not allow_device:
raise http_err
if not allow_device:
raise
log("[cpa] 回退设备码铸造(可能缺 referrer)")
if not allow_device and not sso_token:
raise RuntimeError("无 sso cookie,且已禁用设备码回退;无法铸造带 referrer 的 token")
if not allow_device:
# 有 sso 但 browser 也没开/没 page
if http_err is not None:
raise http_err
raise RuntimeError("SSO 铸造失败,且未启用任何回退")
# 设备码回退(旧路径,通常无 referrer)
from oidc_mint import mint_with_browser