Commit Graph
9 Commits
Author SHA1 Message Date
chaos bc5ad63755 fix(oidc): 恢复 grok-cli:access 并支持批量重铸
补回 mint scope 中的 grok-cli:access,铸造后校验 JWT scope,
避免 cli-chat-proxy 返回 grok-cli-token-auth-required。
新增 remint_cli_scope.py,基于已有 sso 覆盖写回缺 scope 的 CPA auth;
同步更新 cpa/schema 文档说明 referrer 与 scope 双重要求。
2026-07-15 10:12:17 +08:00
chaos 7d6d52ac5d Detect Cloudflare 403 on mint and retry alternate proxies.
- Clear CF block errors with egress label and config hint
- Log mint exit (direct/proxy); probe local proxy ports on 403
- Retry mint_proxy/proxy/pool candidates without browser mint
2026-07-14 14:41:52 +08:00
chaos cc0aa6a433 Align OAuth mint with official Grok Build 0.2.101.
- UA xai-grok-build/0.2.101 + x-grok-client-version/surface
- Ephemeral loopback redirect_uri for authorize/consent/token
- Drop grok-cli:access from scope to match discovery
2026-07-14 14:30:38 +08:00
chaos 4abdc8aa4a Revert mint path to pre-browser PKCE baseline (2e833f2).
Restore HTTP-only SSO OAuth with curl_cffi then std requests fallback;
remove browser PKCE prefer/fallback knobs and mint_from_sso_browser.
2026-07-14 14:06:13 +08:00
chaos bf30d40c8b Fix browser PKCE stuck on consent without code.
Use real Allow clicks (JS click breaks React action), then browser-side
Next.js Server Action POST as fallback; harden SSO cookie injection.
2026-07-14 10:23:24 +08:00
chaos 96061cbd78 Prefer browser PKCE mint over flaky direct HTTP to auth.x.ai.
Logs show curl(28)/ReadTimeout on direct mint while registration browser
still works; skip slow requests fallback, shorten HTTP step timeout, and
mint via page first when available.
2026-07-14 10:19:25 +08:00
chaos 8b399277e7 Fallback SSO OAuth mint to browser PKCE when Python TLS fails.
HTTP mint often dies on auth.x.ai (curl OpenSSL / SSLEOFError); reuse the
registration browser to set SSO, complete authorize+consent, and fetch tokens
so CPA export/push to cpa.nopj.cn can continue.
2026-07-14 10:04:55 +08:00
chaos 2e833f2af3 Fallback mint/TOS HTTP from broken curl_cffi TLS to std requests.
Windows hosts hitting OPENSSL_internal:invalid library (curl 35) now retry SSO OAuth and post-reg TOS/NSFW via standard requests so CPA export can proceed.
2026-07-14 09:56:11 +08:00
chaos ee151343e0 Prefer SSO OAuth PKCE for CPA minting and sync latest accounts.
Switch CPA export to SSO→Authorization Code with referrer=grok-build, keep device-code as optional fallback, and capture new register/auth artifacts.
2026-07-12 15:54:24 +08:00