Prefer browser PKCE mint over flaky direct HTTP to auth.x.ai.

Logs show curl(28)/ReadTimeout on direct mint while registration browser
still works; skip slow requests fallback, shorten HTTP step timeout, and
mint via page first when available.
This commit is contained in:
chaos committed 2026-07-14 10:19:25 +08:00
1 parent 8b399277e7
commit 96061cbd78
3 files changed
+68 -55

No files matched your search

+17 -13
View File
@@ -85,7 +85,9 @@ DEFAULT_CONFIG = {
# OIDC:优先 SSO→Authorization Code + referrer=grok-build
"cpa_prefer_sso_oauth": True, # True=用 sso cookie 走 PKCE(必须带 referrer)
"cpa_require_referrer": True, # True=access_token 无 referrer=grok-build 则失败
"cpa_allow_browser_fallback": True, # True=HTTP 铸造失败时用注册浏览器走 PKCE(绕 Python TLS)
"cpa_prefer_browser_mint": True, # True=有注册浏览器时优先浏览器 PKCE(避开 Python 直连超时)
"cpa_allow_browser_fallback": True, # True=HTTP 铸造失败时用注册浏览器走 PKCE
"cpa_browser_mint_timeout_sec": 120, # 浏览器 PKCE 最长等待
"cpa_allow_device_fallback": False, # True=SSO 失败时回退设备码(通常不可用)
# OIDC 铸造代理/超时
"mint_proxy": "", # 铸造专用代理;空=复用 proxy
@@ -2096,6 +2098,7 @@ def update_nsfw_settings(session, log_callback=None):
def _is_curl_tls_error(exc) -> bool:
"""curl_cffi 库损坏 / TLS / 连接超时:可尝试换后端或记失败,勿当业务错误。"""
text = str(exc or "").lower()
return any(
n in text
@@ -2103,9 +2106,16 @@ def _is_curl_tls_error(exc) -> bool:
"openssl_internal:invalid library",
"tls connect error",
"curl: (35)",
"curl: (28)",
"failed to perform, curl: (35)",
"failed to perform, curl: (28)",
"connection timed out",
"ssl_error_syscall",
"ssl connect error",
"readtimeout",
"connecttimeout",
"timed out",
"timeout",
)
)
@@ -2166,24 +2176,18 @@ def enable_nsfw_for_token(token, cf_clearance="", log_callback=None):
except Exception:
pass
# 仅用 curl_cffi:本机实测 std requests 对 accounts.x.ai/auth.x.ai 更易 ReadTimeout
try:
session = _make_post_reg_session(proxies, prefer="curl")
try:
return _run(session)
except Exception as exc:
if not _is_curl_tls_error(exc):
return False, f"异常: {exc}"
log(f"[Debug] curl TLS 异常,set_tos/nsfw 回退 requests: {exc}")
_close(session)
session = _make_post_reg_session(proxies, prefer="requests")
try:
return _run(session)
finally:
_close(session)
session = None
if _is_curl_tls_error(exc):
log(f"[Debug] set_tos/nsfw 网络/TLS 失败(不回退 requests): {exc}")
return False, f"网络/TLS: {exc}"
return False, f"异常: {exc}"
finally:
if session is not None:
_close(session)
_close(session)
except Exception as e:
return False, f"异常: {str(e)}"