Skip to content

v0.0.8 ​

🔒 Security ​

  • Fixed privilege escalation via URL-parameter channel pinning (one-api#2410): any authenticated user could previously call /v1/oneapi/proxy/:channelid/*target to pin an arbitrary upstream channel, bypassing group isolation and per-channel model allowlists while triggering upstream-credential forwarding. The URL-parameter path now requires an admin, matching the token-suffix path.
  • Re-validate group / model allowlist on pinned channels (one-api#2410): even when an admin pins a channel, the distributor now re-checks that the channel actually serves the caller's user group and requested model before forwarding — defense in depth.
  • Stopped leaking access_token in admin user APIs (one-api#2425): the admin batch endpoints (GET /api/user/, GET /api/user/search) no longer return users' access_tokens, preventing token replay that could escalate to root (consistent with the existing single-user read path).
  • Added Channel.ContainsGroup / Channel.ContainsModel model helpers and regression tests covering all of the above.

✨ New Features ​

  • Reworked all four auth pages — Login, Register, Password Reset, and Password Reset Confirm — around a new AuthLayout (decorative gradient-orb background + branded logo slot), unified semantic headings (h1 + subtitle) and form aria-labels; tidied up forgot-link / form-alert styles so all four pages look and behave consistently.
  • Added Terms of Service (/terms) and Privacy Policy (/privacy) pages rendered via a new LegalLayout (top nav + legal document layout). Both routes are whitelisted in the router so visitors can reach them without first logging in.
  • Registration now requires checking "I agree to the Terms of Service and Privacy Policy" (with aria-label) before submitting, and the copy includes direct /terms / /privacy links.
  • Added an empty state to the Plans page so users see a friendly illustration + hint ("暂无可用套餐 / 请联系管理员配置套餐后再来查看") instead of a blank grid when no plans are configured.
  • Added Channel.ContainsGroup / Channel.ContainsModel allowlist helpers (comma-split, exact match; empty config allows all), providing the reusable building block for downstream auth and re-validation logic.
  • Embedded-theme check at startup: added common.ValidateEmbeddedTheme(buildFS, themesRoot, theme) and common.ListEmbeddedThemes(buildFS, themesRoot) helpers. main.go invokes the validator right after logging using theme <name>; if the configured theme is not embedded in the binary, it emits a loud [ERROR] that names the missing web/build/<theme>/index.html, lists every theme that IS embedded, and points at three fixes (update options.theme / adjust the THEME env / add the theme to web/THEMES and rebuild). The check is non-fatal — the server still starts so the operator can fix the misconfiguration — but it puts the "blank admin page" failure mode straight into the log.

🐛 Bug Fixes ​

  • Removed an extra page-container padding in the Orders page so its margins match the other pages.
  • Fixed the security issue where ordinary users could bypass group isolation / model allowlists by pinning an upstream channel (see Security).
  • Fixed the security issue where admin user list / search responses could expose access_token (see Security).
  • router/web.go no longer silently swallows the error from reading web/build/<theme>/index.html; it now logs theme %q is not embedded ... via logger.SysError as a safety net, so the failure is still visible even if SetWebRouter is ever reached before the startup check (tests, future refactors).

📚 Documentation ​

  • README i18n now covers 8 languages: added German, Arabic, Korean, Russian, Japanese and Traditional Chinese READMEs, and updated the language navigation in both the main and English READMEs.

🔧 Tooling / CI ​

  • Added three groups of regression tests: middleware channel-pinning auth (middleware/auth_test.go), user-list access_token redaction (controller/user_test.go), and model allowlist helpers (model/channel_contains_test.go).
  • Added 5 unit tests for the embedded-theme validator (common/embed_theme_test.go, with synthetic fixtures in common/embed_theme_testdata/): list themes, theme present, theme missing, empty theme, and trailing-slash tolerance on the themes root.

⚠️ Upgrade Notes ​

  • Code/frontend-only release — no database migration; safe to upgrade in place.
  • Login / register / password-reset pages have been redesigned; please clear the browser cache or verify in an incognito window after upgrading.
  • If you relied on anonymous "pin channel by URL parameter" proxying in open-registration deployments, note that this is no longer allowed: only admins can pin a channel (via URL parameter or token suffix).
  • Stale options.theme from older releases will now be caught: when upgrading from an older one-api / one-api-pro that shipped the legacy default theme, you may see [ERROR] theme "default" is not embedded in this binary ... at startup — that means the MySQL options table still holds the old theme=default row, which overrides the env default. Run UPDATE options SET value='default-pro' WHERE \key`='theme';` (or delete the row) and restart.