Revert mint path to pre-browser PKCE baseline (2e833f2).

Restore HTTP-only SSO OAuth with curl_cffi then std requests fallback;
remove browser PKCE prefer/fallback knobs and mint_from_sso_browser.
This commit is contained in:
chaos committed 2026-07-14 14:06:13 +08:00
1 parent d74d14d3f4
commit 4abdc8aa4a
5 files changed
+51 -751

No files matched your search

+12 -17
View File
@@ -85,9 +85,6 @@ DEFAULT_CONFIG = {
# OIDC:优先 SSO→Authorization Code + referrer=grok-build
"cpa_prefer_sso_oauth": True, # True=用 sso cookie 走 PKCE(必须带 referrer)
"cpa_require_referrer": True, # True=access_token 无 referrer=grok-build 则失败
"cpa_prefer_browser_mint": False, # True=有 page 时先浏览器(慢);默认关
"cpa_allow_browser_fallback": False, # True=HTTP 失败再用浏览器 PKCE;默认关(不要网页铸造)
"cpa_browser_mint_timeout_sec": 90, # 浏览器 PKCE 最长等待(仅 fallback 开启时)
"cpa_allow_device_fallback": False, # True=SSO 失败时回退设备码(通常不可用)
# OIDC 铸造代理/超时
"mint_proxy": "", # 铸造专用代理;空=复用 proxy
@@ -2098,7 +2095,6 @@ def update_nsfw_settings(session, log_callback=None):
def _is_curl_tls_error(exc) -> bool:
"""curl_cffi 库损坏 / TLS / 连接超时:可尝试换后端或记失败,勿当业务错误。"""
text = str(exc or "").lower()
return any(
n in text
@@ -2106,16 +2102,9 @@ def _is_curl_tls_error(exc) -> bool:
"openssl_internal:invalid library",
"tls connect error",
"curl: (35)",
"curl: (28)",
"failed to perform, curl: (35)",
"failed to perform, curl: (28)",
"connection timed out",
"ssl_error_syscall",
"ssl connect error",
"readtimeout",
"connecttimeout",
"timed out",
"timeout",
)
)
@@ -2176,18 +2165,24 @@ def enable_nsfw_for_token(token, cf_clearance="", log_callback=None):
except Exception:
pass
# 仅用 curl_cffi:本机实测 std requests 对 accounts.x.ai/auth.x.ai 更易 ReadTimeout
try:
session = _make_post_reg_session(proxies, prefer="curl")
try:
return _run(session)
except Exception as exc:
if _is_curl_tls_error(exc):
log(f"[Debug] set_tos/nsfw 网络/TLS 失败(不回退 requests): {exc}")
return False, f"网络/TLS: {exc}"
return False, f"异常: {exc}"
finally:
if not _is_curl_tls_error(exc):
return False, f"异常: {exc}"
log(f"[Debug] curl TLS 异常,set_tos/nsfw 回退 requests: {exc}")
_close(session)
session = _make_post_reg_session(proxies, prefer="requests")
try:
return _run(session)
finally:
_close(session)
session = None
finally:
if session is not None:
_close(session)
except Exception as e:
return False, f"异常: {str(e)}"