Prefer SSO OAuth PKCE for CPA minting and sync latest accounts.

Switch CPA export to SSO→Authorization Code with referrer=grok-build, keep device-code as optional fallback, and capture new register/auth artifacts.
This commit is contained in:
chaos committed 2026-07-12 15:54:24 +08:00
1 parent 8b3664a2d5
commit ee151343e0
455 files changed
+9051 -59

No files matched your search

+16 -10
View File
@@ -1,4 +1,4 @@
#!/usr/bin/env python
#!/usr/bin/env python
# -*- coding: utf-8 -*-
"""
Grok 注册机 - TTK GUI 版本
@@ -40,10 +40,10 @@ DEFAULT_CONFIG = {
"enable_nsfw": True,
"register_count": 1,
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36",
# ===== CPA (CLIProxyAPI) 导出 / 免费 Grok 4.5(OIDC,非 Web SSO)=====
# 注册成功后走设备码 OIDC 铸造 token,写出 CLIProxyAPI 的 xai-<email>.json,并可
# 推送到远端 CLIProxyAPI 导入。免费号用 cli-chat-proxy,CLIProxyAPI 请求 grok 时
# 自带 x-grok-client-version 头,不会 426。SSO cookie 不能替代 OIDC。
# ===== CPA (CLIProxyAPI) 导出 / 免费 Grok 4.5(OIDC)=====
# 注册成功后用 SSO cookie 走 Authorization Code + PKCE,强制 referrer=grok-build,
# 写出 CLIProxyAPI 的 xai-<email>.json,并可推送到远端。免费号用 cli-chat-proxy。
# 旧设备码铸造的 token 缺 referrer,cli-chat-proxy 已不可用。
"cpa_export_enabled": True, # 注册成功后是否铸造 OIDC 并写 CPA 认证文件
"cpa_auth_dir": "./cpa_auths", # 本地写盘目录(xai-<email>.json)
"cpa_base_url": "https://cli-chat-proxy.grok.com/v1", # 写进 auth 的 base_url;付费用 https://api.x.ai/v1
@@ -54,7 +54,11 @@ DEFAULT_CONFIG = {
"cpa_remote_verify_tls": True, # https 远端是否校验证书
"cpa_push_proxy": "", # 推送用代理;空=直连(不走 mint 代理)
"cpa_push_required": False, # True=推送失败则整次注册算失败
# OIDC 设备码铸造(独立 Chromium)
# OIDC:优先 SSO→Authorization Code + referrer=grok-build
"cpa_prefer_sso_oauth": True, # True=用 sso cookie 走 PKCE(必须带 referrer)
"cpa_require_referrer": True, # True=access_token 无 referrer=grok-build 则失败
"cpa_allow_device_fallback": False, # True=SSO 失败时回退设备码(通常不可用)
# OIDC 铸造代理/超时
"mint_proxy": "", # 铸造专用代理;空=复用 proxy
"mint_timeout_sec": 300, # 单账号铸造超时(秒)
"mint_required": False, # True=铸造失败则整次注册算失败
@@ -338,9 +342,9 @@ def export_cpa_after_register(email, password, session=None, sso="", log_callbac
"""注册成功后铸造 Grok Build OIDC,写出 CPA (CLIProxyAPI) 的 xai-<email>.json,
并按配置推送到远端 CLIProxyAPI 导入。
走独立 Chromium 完成设备码确认,再轮询 token;本地写到 config['cpa_auth_dir'],
默认优先用 SSO cookie 走 Authorization Code + PKCE(referrer=grok-build),
不再依赖设备码浏览器确认。本地写到 config['cpa_auth_dir'],
远端推送到 config['cpa_remote_base'] 的 /v0/management/auth-files。
SSO cookie 只用于尽量跳过二次登录,不能替代 OIDC。
"""
log = log_callback or cli_log
if not config.get("cpa_export_enabled", True):
@@ -355,13 +359,13 @@ def export_cpa_after_register(email, password, session=None, sso="", log_callbac
raise
return {"ok": False, "error": f"import: {exc}"}
# 铸造用独立浏览器,只借注册页导出 cookie 以尽量跳过二次登录
page = getattr(session, "page", None) if session is not None else None
try:
result = cpa_export.export_cpa_for_account(
email,
password,
page=page,
sso=sso or "",
config=config,
log_callback=log,
)
@@ -373,7 +377,9 @@ def export_cpa_after_register(email, password, session=None, sso="", log_callbac
if result.get("ok"):
tail = " 并已推送远端" if result.get("pushed") else ""
log(f"[+] CPA 认证已写出: {result.get('path')}{tail}")
ref = result.get("referrer") or ""
ref_s = f" referrer={ref}" if ref else ""
log(f"[+] CPA 认证已写出: {result.get('path')}{ref_s}{tail}")
elif result.get("skipped"):
log(f"[cpa] 跳过: {result.get('reason')}")
else: