v0.0.8
🔒 Security
- Fixed privilege escalation via URL-parameter channel pinning (one-api#2410): any authenticated user could previously call
/v1/oneapi/proxy/:channelid/*targetto pin an arbitrary upstream channel, bypassing group isolation and per-channel model allowlists while triggering upstream-credential forwarding. The URL-parameter path now requires an admin, matching the token-suffix path. - Re-validate group / model allowlist on pinned channels (one-api#2410): even when an admin pins a channel, the distributor now re-checks that the channel actually serves the caller's user group and requested model before forwarding — defense in depth.
- Stopped leaking
access_tokenin admin user APIs (one-api#2425): the admin batch endpoints (GET /api/user/,GET /api/user/search) no longer return users' access_tokens, preventing token replay that could escalate to root (consistent with the existing single-user read path). - Added
Channel.ContainsGroup/Channel.ContainsModelmodel helpers and regression tests covering all of the above.
✨ New Features
- Reworked all four auth pages — Login, Register, Password Reset, and Password Reset Confirm — around a new
AuthLayout(decorative gradient-orb background + branded logo slot), unified semantic headings (h1+ subtitle) and formaria-labels; tidied upforgot-link/form-alertstyles so all four pages look and behave consistently. - Added Terms of Service (
/terms) and Privacy Policy (/privacy) pages rendered via a newLegalLayout(top nav + legal document layout). Both routes are whitelisted in the router so visitors can reach them without first logging in. - Registration now requires checking "I agree to the Terms of Service and Privacy Policy" (with
aria-label) before submitting, and the copy includes direct/terms//privacylinks. - Added an empty state to the Plans page so users see a friendly illustration + hint ("暂无可用套餐 / 请联系管理员配置套餐后再来查看") instead of a blank grid when no plans are configured.
- Added
Channel.ContainsGroup/Channel.ContainsModelallowlist helpers (comma-split, exact match; empty config allows all), providing the reusable building block for downstream auth and re-validation logic. - Embedded-theme check at startup: added
common.ValidateEmbeddedTheme(buildFS, themesRoot, theme)andcommon.ListEmbeddedThemes(buildFS, themesRoot)helpers.main.goinvokes the validator right after loggingusing theme <name>; if the configured theme is not embedded in the binary, it emits a loud[ERROR]that names the missingweb/build/<theme>/index.html, lists every theme that IS embedded, and points at three fixes (updateoptions.theme/ adjust theTHEMEenv / add the theme toweb/THEMESand rebuild). The check is non-fatal — the server still starts so the operator can fix the misconfiguration — but it puts the "blank admin page" failure mode straight into the log.
🐛 Bug Fixes
- Removed an extra
page-containerpadding in the Orders page so its margins match the other pages. - Fixed the security issue where ordinary users could bypass group isolation / model allowlists by pinning an upstream channel (see Security).
- Fixed the security issue where admin user list / search responses could expose
access_token(see Security). router/web.gono longer silently swallows the error from readingweb/build/<theme>/index.html; it now logstheme %q is not embedded ...vialogger.SysErroras a safety net, so the failure is still visible even ifSetWebRouteris ever reached before the startup check (tests, future refactors).
📚 Documentation
- README i18n now covers 8 languages: added German, Arabic, Korean, Russian, Japanese and Traditional Chinese READMEs, and updated the language navigation in both the main and English READMEs.
🔧 Tooling / CI
- Added three groups of regression tests: middleware channel-pinning auth (
middleware/auth_test.go), user-listaccess_tokenredaction (controller/user_test.go), and model allowlist helpers (model/channel_contains_test.go). - Added 5 unit tests for the embedded-theme validator (
common/embed_theme_test.go, with synthetic fixtures incommon/embed_theme_testdata/): list themes, theme present, theme missing, empty theme, and trailing-slash tolerance on the themes root.
⚠️ Upgrade Notes
- Code/frontend-only release — no database migration; safe to upgrade in place.
- Login / register / password-reset pages have been redesigned; please clear the browser cache or verify in an incognito window after upgrading.
- If you relied on anonymous "pin channel by URL parameter" proxying in open-registration deployments, note that this is no longer allowed: only admins can pin a channel (via URL parameter or token suffix).
- Stale
options.themefrom older releases will now be caught: when upgrading from an older one-api / one-api-pro that shipped the legacydefaulttheme, you may see[ERROR] theme "default" is not embedded in this binary ...at startup — that means the MySQLoptionstable still holds the oldtheme=defaultrow, which overrides the env default. RunUPDATE options SET value='default-pro' WHERE \key`='theme';` (or delete the row) and restart.