Fallback SSO OAuth mint to browser PKCE when Python TLS fails.

HTTP mint often dies on auth.x.ai (curl OpenSSL / SSLEOFError); reuse the
registration browser to set SSO, complete authorize+consent, and fetch tokens
so CPA export/push to cpa.nopj.cn can continue.
This commit is contained in:
chaos committed 2026-07-14 10:04:55 +08:00
1 parent 2e833f2af3
commit 8b399277e7
4 files changed
+443 -9

No files matched your search

+1
View File
@@ -85,6 +85,7 @@ DEFAULT_CONFIG = {
# OIDC:优先 SSO→Authorization Code + referrer=grok-build
"cpa_prefer_sso_oauth": True, # True=用 sso cookie 走 PKCE(必须带 referrer)
"cpa_require_referrer": True, # True=access_token 无 referrer=grok-build 则失败
"cpa_allow_browser_fallback": True, # True=HTTP 铸造失败时用注册浏览器走 PKCE(绕 Python TLS)
"cpa_allow_device_fallback": False, # True=SSO 失败时回退设备码(通常不可用)
# OIDC 铸造代理/超时
"mint_proxy": "", # 铸造专用代理;空=复用 proxy