chaos
bc5ad63755
fix(oidc): 恢复 grok-cli:access 并支持批量重铸
...
补回 mint scope 中的 grok-cli:access,铸造后校验 JWT scope,
避免 cli-chat-proxy 返回 grok-cli-token-auth-required。
新增 remint_cli_scope.py,基于已有 sso 覆盖写回缺 scope 的 CPA auth;
同步更新 cpa/schema 文档说明 referrer 与 scope 双重要求。
2026-07-15 10:12:17 +08:00
chaos
7d6d52ac5d
Detect Cloudflare 403 on mint and retry alternate proxies.
...
- Clear CF block errors with egress label and config hint
- Log mint exit (direct/proxy); probe local proxy ports on 403
- Retry mint_proxy/proxy/pool candidates without browser mint
2026-07-14 14:41:52 +08:00
chaos
cc0aa6a433
Align OAuth mint with official Grok Build 0.2.101.
...
- UA xai-grok-build/0.2.101 + x-grok-client-version/surface
- Ephemeral loopback redirect_uri for authorize/consent/token
- Drop grok-cli:access from scope to match discovery
2026-07-14 14:30:38 +08:00
chaos
4abdc8aa4a
Revert mint path to pre-browser PKCE baseline ( 2e833f2).
...
Restore HTTP-only SSO OAuth with curl_cffi then std requests fallback;
remove browser PKCE prefer/fallback knobs and mint_from_sso_browser.
2026-07-14 14:06:13 +08:00
chaos
d74d14d3f4
Disable browser PKCE mint by default.
...
User does not want web/browser casting; HTTP-only unless
cpa_allow_browser_fallback is explicitly re-enabled.
2026-07-14 13:48:53 +08:00
chaos
0417fa3218
Lower browser PKCE mint priority; HTTP-first by default.
...
Browser path is slow; only use it as fallback after HTTP mint fails unless
cpa_prefer_browser_mint is explicitly enabled.
2026-07-14 10:36:20 +08:00
chaos
bf30d40c8b
Fix browser PKCE stuck on consent without code.
...
Use real Allow clicks (JS click breaks React action), then browser-side
Next.js Server Action POST as fallback; harden SSO cookie injection.
2026-07-14 10:23:24 +08:00
chaos
96061cbd78
Prefer browser PKCE mint over flaky direct HTTP to auth.x.ai.
...
Logs show curl(28)/ReadTimeout on direct mint while registration browser
still works; skip slow requests fallback, shorten HTTP step timeout, and
mint via page first when available.
2026-07-14 10:19:25 +08:00
chaos
8b399277e7
Fallback SSO OAuth mint to browser PKCE when Python TLS fails.
...
HTTP mint often dies on auth.x.ai (curl OpenSSL / SSLEOFError); reuse the
registration browser to set SSO, complete authorize+consent, and fetch tokens
so CPA export/push to cpa.nopj.cn can continue.
2026-07-14 10:04:55 +08:00
chaos
2e833f2af3
Fallback mint/TOS HTTP from broken curl_cffi TLS to std requests.
...
Windows hosts hitting OPENSSL_internal:invalid library (curl 35) now retry SSO OAuth and post-reg TOS/NSFW via standard requests so CPA export can proceed.
2026-07-14 09:56:11 +08:00
chaos
fc879c09ea
Generate natural English-style email local-parts with digit suffixes.
...
Replace random alnum usernames with first/last name patterns ending in 2-4 digits across all email providers.
2026-07-14 09:32:20 +08:00
chaos
001dc014ea
Point default CPA push target to https://cpa.nopj.cn .
...
Enable push by default with the new management secret so hosts inherit the nopj CPA endpoint.
2026-07-14 09:27:26 +08:00
chaos
a0fb249dff
Default email provider and domains to mail.bblbb.com.
...
Clarify that existing config.json overrides code defaults so other hosts must update provider settings after pull.
2026-07-14 09:19:12 +08:00
chaos
df9213463d
Add bblbb mail provider and CPA push queue; sync runtime artifacts.
...
Switch default email provider to mail.bblbb.com, queue failed CPA auth pushes for retry, and refresh local auth/account outputs.
2026-07-14 09:14:06 +08:00
chaos
a4dbe948b2
Disable proxy pool by default; add managed proxy lifecycle and Turnstile fixes.
...
Keep proxy_pool_enabled/managed off for direct registration, while shipping
SSO OAuth CPA export, visible Turnstile click handling, and proxy harvest tooling.
2026-07-13 07:16:11 +08:00
chaos
1ed18236b9
Sync remaining CPA auth JSON and latest register outputs.
...
Add newly generated cpa_auths xai-*.json files and related accounts/mail credential increments after the previous push.
2026-07-12 16:35:34 +08:00
chaos
ee151343e0
Prefer SSO OAuth PKCE for CPA minting and sync latest accounts.
...
Switch CPA export to SSO→Authorization Code with referrer=grok-build, keep device-code as optional fallback, and capture new register/auth artifacts.
2026-07-12 15:54:24 +08:00
chaos
8b3664a2d5
Capture latest register runtime outputs.
2026-07-12 08:11:16 +08:00
chaos
90d09db27a
Sync latest mail_credentials.txt after register run.
2026-07-12 08:11:00 +08:00
chaos
33f966ccea
Initial commit: grok-register with private config and auth artifacts.
...
Include local config, CPA auth files, account dumps, and temp-mail deploy helpers for the private Gitea repo.
2026-07-12 08:10:44 +08:00