Compare commits

...
29 Commits
Author SHA1 Message Date
公明andGitHub a6b3773f00 Add files via upload 2026-07-28 18:35:32 +08:00
公明andGitHub c2b950ad53 Add files via upload 2026-07-28 18:32:15 +08:00
公明andGitHub 0283fff743 Add files via upload 2026-07-28 18:30:28 +08:00
公明andGitHub 018835d6b8 Add files via upload 2026-07-28 18:28:41 +08:00
公明andGitHub 4b7df4e0f3 Add files via upload 2026-07-28 18:26:33 +08:00
公明andGitHub 0324b41a01 Add files via upload 2026-07-28 18:25:11 +08:00
公明andGitHub 4a19620137 Add files via upload 2026-07-28 18:22:30 +08:00
公明andGitHub f8110413c0 Add files via upload 2026-07-28 18:20:17 +08:00
公明andGitHub 59dc7cf858 Add files via upload 2026-07-28 18:17:47 +08:00
公明andGitHub 52595e07e5 Add files via upload 2026-07-28 18:15:54 +08:00
公明andGitHub e0965594bb Add files via upload 2026-07-28 18:14:06 +08:00
公明andGitHub 9ef8263eaf Update config.example.yaml 2026-07-28 17:50:02 +08:00
3c54a67416 fix(project): 允许 fact_key 驼峰命名并澄清未绑定项目授权报错 (#200) (#217)
- fact_key 校验放开大写字母,支持驼峰命名(如 finding/info-disclosure-messageBundle):
  - internal/database/project.go: 正则 ^[a-z0-9]... 改为 ^[a-zA-Z0-9]...,并更新错误提示
  - internal/project/fact_body_links.go: body 解析正则(依赖事实/相关 fact_key)同步放开大写
- authorizeProjectTool 区分「未绑定项目 / 查询出错 / 真实无权限」三种情况:
  未绑定项目时返回明确可执行提示,替代误导性的 no access to project
  - internal/app/mcp_authorization.go

Co-authored-by: sycmacmini <sycmacmini@sycmacminis-Mac-mini.local>
2026-07-28 11:18:58 +08:00
公明andGitHub 98ca395edd Add files via upload 2026-07-28 11:01:17 +08:00
公明andGitHub c616822cd6 Add files via upload 2026-07-28 10:37:49 +08:00
公明andGitHub ba1796d7ce Add files via upload 2026-07-27 17:27:55 +08:00
公明andGitHub dad14c55c1 Add files via upload 2026-07-24 18:10:52 +08:00
公明andGitHub cc0233d7b4 Add files via upload 2026-07-24 17:05:44 +08:00
公明andGitHub 7b6f56e476 Add files via upload 2026-07-24 16:43:01 +08:00
公明andGitHub 2522fc6ae2 Add files via upload 2026-07-24 16:06:30 +08:00
公明andGitHub 99d7380450 Add files via upload 2026-07-24 16:03:46 +08:00
公明andGitHub 837e41459a Add files via upload 2026-07-24 15:58:55 +08:00
公明andGitHub 5cbd828cad Add files via upload 2026-07-24 15:52:16 +08:00
公明andGitHub 8cb317cbd6 Add files via upload 2026-07-24 15:50:11 +08:00
公明andGitHub 94a2ba0406 Add files via upload 2026-07-24 15:19:01 +08:00
公明andGitHub 4ee7204509 Add files via upload 2026-07-24 14:55:59 +08:00
公明andGitHub c326adbb66 Add files via upload 2026-07-24 14:53:44 +08:00
公明andGitHub 7d1e9bdac4 Add files via upload 2026-07-24 14:08:19 +08:00
公明andGitHub 151b445c74 Add files via upload 2026-07-24 11:44:35 +08:00
54 changed files with 3435 additions and 559 deletions
+91 -8
View File
@@ -4,7 +4,9 @@ import (
"context"
"cyberstrike-ai/internal/app"
"cyberstrike-ai/internal/config"
"cyberstrike-ai/internal/database"
"cyberstrike-ai/internal/logger"
"cyberstrike-ai/internal/security"
"cyberstrike-ai/internal/termout"
"flag"
"fmt"
@@ -12,17 +14,21 @@ import (
"os/signal"
"strings"
"syscall"
"go.uber.org/zap"
"golang.org/x/term"
)
func main() {
var configPath = flag.String("config", "config.yaml", "配置文件路径")
var httpsBootstrap = flag.Bool("https", false, "启用主站 HTTPS:未配置 tls_cert_path/tls_key_path 时使用内存自签证书(本地测试);与 run.sh 默认行为一致")
var httpBootstrap = flag.Bool("http", false, "强制主站使用明文 HTTP:覆盖配置文件中的 tls_enabled/tls_auto_self_sign/tls_cert_path/tls_key_path")
var configPath = flag.String("config", "config.yaml", "Path to the configuration file")
var httpsBootstrap = flag.Bool("https", false, "Enable HTTPS for the main site; uses an in-memory self-signed certificate when no cert/key is configured")
var httpBootstrap = flag.Bool("http", false, "Force plain HTTP for the main site, overriding TLS settings in the configuration file")
var resetAdminPassword = flag.Bool("reset-admin-password", false, "Interactively reset the built-in admin password and exit")
flag.Parse()
// 环境变量兼容(便于 systemd/docker 等不传参场景)
if *httpsBootstrap && *httpBootstrap {
fmt.Fprintln(os.Stderr, "--http --https 不能同时使用")
fmt.Fprintln(os.Stderr, "--http and --https cannot be used together")
os.Exit(2)
}
if !*httpsBootstrap && !*httpBootstrap {
@@ -38,24 +44,32 @@ func main() {
cp = "config.yaml"
}
if strings.HasPrefix(cp, "-") {
fmt.Fprintf(os.Stderr, "无效的 -config 路径 %q\n若同时需要 HTTPS,请写成: ./cyberstrike-ai --https -config config.yaml-config 后必须是 yaml 文件路径)。\n", cp)
fmt.Fprintf(os.Stderr, "Invalid -config path %q.\nIf HTTPS is also needed, use: ./cyberstrike-ai --https -config config.yaml (-config must be followed by a yaml file path).\n", cp)
os.Exit(2)
}
localConfig, err := config.EnsureLocalConfig(cp)
if err != nil {
fmt.Printf("加载配置失败: %v\n", err)
fmt.Printf("Failed to load config: %v\n", err)
return
}
cfg, err := config.Load(cp)
if err != nil {
fmt.Printf("加载配置失败: %v\n", err)
fmt.Printf("Failed to load config: %v\n", err)
return
}
if localConfig.Created {
termout.PrintConfigCreated()
}
if *resetAdminPassword {
if err := runResetAdminPassword(cfg); err != nil {
fmt.Fprintf(os.Stderr, "Failed to reset admin password: %v\n", err)
os.Exit(1)
}
return
}
if *httpBootstrap {
config.ApplyPlainHTTPBootstrap(cfg)
} else if *httpsBootstrap {
@@ -79,7 +93,7 @@ func main() {
// MCP 启用且 auth_header_value 为空时,自动生成随机密钥并写回配置
if err := config.EnsureMCPAuth(cp, cfg); err != nil {
fmt.Printf("MCP 鉴权配置失败: %v\n", err)
fmt.Printf("Failed to configure MCP authentication: %v\n", err)
return
}
if cfg.MCP.Enabled {
@@ -121,3 +135,72 @@ func main() {
}
}
}
func runResetAdminPassword(cfg *config.Config) error {
dbPath := strings.TrimSpace(cfg.Database.Path)
if dbPath == "" {
dbPath = "data/conversations.db"
}
if _, err := os.Stat(dbPath); err != nil {
if os.IsNotExist(err) {
return fmt.Errorf("database does not exist: %s; start the service once to initialize it first", dbPath)
}
return err
}
fmt.Println("Reset built-in admin password")
fmt.Println()
password, err := readHiddenPassword("New admin password: ")
if err != nil {
return err
}
password = strings.TrimSpace(password)
if len(password) < 8 {
return fmt.Errorf("new password must be at least 8 characters")
}
confirm, err := readHiddenPassword("Confirm new password: ")
if err != nil {
return err
}
if password != strings.TrimSpace(confirm) {
return fmt.Errorf("passwords do not match")
}
hash, err := security.HashPassword(password)
if err != nil {
return err
}
db, err := database.NewDB(dbPath, zap.NewNop())
if err != nil {
return err
}
defer func() { _ = db.Close() }()
admin, err := db.GetRBACUserByUsername("admin")
if err != nil {
return fmt.Errorf("built-in admin account was not found; start the service once to initialize it first: %w", err)
}
if !admin.IsBuiltin {
return fmt.Errorf("admin account is not built in; refusing to reset it")
}
if err := db.UpdateRBACAdminPassword(hash); err != nil {
return err
}
fmt.Println()
fmt.Println("Admin password has been reset.")
fmt.Println("If the service is running, existing login sessions remain valid until the service restarts or the sessions expire.")
return nil
}
func readHiddenPassword(prompt string) (string, error) {
fmt.Fprint(os.Stderr, prompt)
password, err := term.ReadPassword(int(os.Stdin.Fd()))
fmt.Fprintln(os.Stderr)
if err != nil {
return "", err
}
return string(password), nil
}
+1 -1
View File
@@ -68,7 +68,7 @@ ai:
api_key: sk-xxxxxxx
model: qwen3-max
max_total_tokens: 120000
max_completion_tokens: 16384
max_completion_tokens: 32768
# Eino 路径模型推理:DeepSeek/OpenAI 为 thinking / reasoning_effortClaude 4.6+ 为 adaptive + output_config.effort(仅显式配置 effort 时下发);3.7 为 enabled+budget_tokens:10000(文档示例),effort 不映射,自定义预算用 extra_request_fields
reasoning:
mode: on # auto | on | offoffOpenAI/Claude 不附加推理字段,DeepSeek 发送 thinking.type=disabled(其默认开启思考)
+10 -2
View File
@@ -46,13 +46,21 @@ Login fails:
If another administrator with `rbac:write` is available, reset the password under **Platform permissions → User management**.
If no administrator session is available, the built-in `admin` account can be recovered on the server. Stop CyberStrikeAI, back up the database, change to the project root, and run the command below. Enter and confirm the new password when prompted:
If no administrator session is available, the built-in `admin` account can be recovered on the server. Change to the project root and run:
```bash
./run.sh --reset-admin-password
```
Enter and confirm the new password when prompted. The script hides input and stores a bcrypt hash. If the service is running, restart it afterward to invalidate existing login sessions.
If `run.sh` is not available, run the command below manually. Enter and confirm the new password when prompted:
```bash
HASH=$(htpasswd -nBC 10 '' | cut -d: -f2 | tr -d '\n') && sqlite3 data/conversations.db "UPDATE rbac_users SET password_hash='$HASH', updated_at=CURRENT_TIMESTAMP WHERE id='admin' AND username='admin' AND is_builtin=1; SELECT changes();"
```
Output `1` means that the row was updated. The command requires `sqlite3` and `htpasswd`. If `database.path` in `config.yaml` is not the default, replace `data/conversations.db`. Password input is hidden, is not written to shell history, and is stored as a bcrypt hash. Restart the service afterward to invalidate existing login sessions.
Output `1` means that the row was updated. The command requires `sqlite3` and `htpasswd`. If `database.path` in `config.yaml` is not the default, replace `data/conversations.db`. Password input is hidden and is not written to shell history.
Model fails:
+1 -1
View File
@@ -12,7 +12,7 @@
## 核心概念与编排
- [架构说明](architecture.md) · [安全模型](security-model.md) · [RBAC](rbac.md)
- [Agent 与角色](agent-and-role-guide.md) · [Skills](skills-guide.md) · [Eino 多代理](MULTI_AGENT_EINO.md)
- [Agent 与角色](agent-and-role-guide.md) · [Skills](skills-guide.md) · [Eino 多代理](MULTI_AGENT_EINO.md) · [Agent 最终回复治理](agent-finalization-best-practices.md)
- [工作流](workflow-graph.md) · [工具执行治理](tool-execution-governance.md) · [人机协同最佳实践](hitl-best-practices.md)
## 功能指南
@@ -0,0 +1,333 @@
# Agent 最终回复治理最佳实践
[返回中文文档](README.md)
调研日期:2026-07-28
本文聚焦一个具体问题:Agent 在工具调用、推理、计划或子代理协作尚未真正完成时,输出了一段“像结论”的自然语言,前端或编排层把它当作最终回复展示。结论先说清楚:成熟 Agent 系统不会用“最近一段 assistant 文本”判断任务完成,而是用运行时状态、工具状态、验证结果和显式终态事件共同决定是否 final。
## 一、核心结论
1. **最终回复是运行时事件,不是自然语言内容。**
“已拿到”“下一步”“Huge breakthrough”这类文本只能作为候选观察或进展,不能作为完成信号。
2. **过程面和交付面必须隔离。**
`thinking``reasoning_chain``planning``response_delta`、子代理回复、工具输出都属于过程面;只有通过 final gate 的 `response` / `final` 事件才能写入主消息气泡和 `messages.content`
3. **复杂任务需要 verifier,而不是更长 prompt。**
Prompt 可以提醒模型谨慎,但最终完成必须由代码层判断:是否仍有待执行工具、后台 execution、未完成计划步骤、未验证证据、未记录事实/漏洞、未清理或未说明不可清理。
4. **不同 agent 模式不同,但 final 治理原则一致。**
单代理、Deep、Plan-Execute、Supervisor 都需要 final gate。区别只是 gate 的证据来源不同:单代理看工具轨迹,Deep 还要看子代理结果,Plan-Execute 要看 Replanner 的终止判断,Supervisor 要看 `exit` 与 supervisor 汇总。
## 二、成熟 Agent 的公开做法
| 系统 | 公开做法 | 对 final 治理的启发 |
|---|---|---|
| Codex | OpenAI 的 Codex prompting guide 建议不要在 prompt 中强行要求 upfront plan、preamble 或 status updates,因为这可能导致 rollout 未完成就停止。 | 不要把“模型自己说的阶段性计划/状态”当完成依据;agent harness 应负责执行循环和收尾。 |
| Claude Code | Claude Code 提供 `PreToolUse``PostToolUse``Stop` 等 hooks`PostToolUse` 明确发生在工具成功执行之后。 | 生命周期事件比自然语言可靠。验证、审计、阻断应挂在确定的阶段边界上。 |
| Claude Code Subagents | 子代理有独立上下文、自定义系统提示、特定工具权限和独立权限;子代理适合隔离大量检索/日志/文件读取。 | 子代理输出是证据材料,不是主任务最终结论;主代理必须汇总、验收、再 final。 |
| Claude Code Plan Mode | Plan mode 先读文件并产出计划,获得批准前不编辑。 | 计划与执行是不同状态;计划完成不等于任务完成。 |
| Cursor Plan Mode | Cursor Plan Mode 会研究代码库、询问澄清问题、生成可审查计划,并等待用户确认后再构建。 | UI 层把 plan/review/build 拆开,用户不会把计划误认为最终交付。 |
| OpenCode | OpenCode 把 Build、Plan、Review、Debug、Docs 等 agent 分成不同工具权限与用途,Plan agent 只分析规划不做修改。 | 用 agent 能力边界降低误触发:能规划的 agent 不等于能执行完成。 |
| Eino ADK | Eino ADK 提供事件驱动输出、Runner 回调、中断、checkpoint,以及 Supervisor、Plan-Execute 等协作原语。Plan-Execute 由 Planner、Executor、Replanner 协作。 | 当前项目选型方向正确;需要把事件驱动能力进一步固化为 finalization contract。 |
主要参考:
- OpenAI Codex Prompting Guide: https://developers.openai.com/cookbook/examples/gpt-5/codex_prompting_guide
- Claude Code Hooks: https://docs.anthropic.com/en/docs/claude-code/hooks
- Claude Code Subagents: https://docs.anthropic.com/en/docs/claude-code/sub-agents
- Claude Code Common Workflows: https://docs.anthropic.com/en/docs/claude-code/common-workflows
- Cursor Agent Best Practices: https://cursor.com/blog/agent-best-practices
- OpenCode Agents: https://opencode.ai/docs/agents/
- CloudWeGo Eino ADK: https://www.cloudwego.io/docs/eino/core_modules/eino_adk/
- CloudWeGo Eino ADK Patterns: https://www.cloudwego.io/docs/eino/overview/eino_adk0_1/
## 三、通用最佳实践
### 1. 建立 Finalization Contract
所有执行入口统一产出一个结构化收尾对象,只有它允许触发最终回复。
```go
type FinalizationDecision struct {
Status string // in_progress | completed | blocked | failed | cancelled
Finalizable bool
CompletionReason string // verified | user_cancelled | timeout | blocked | failed
FinalText string
EvidenceVerified bool
EvidenceRefs []string
PendingToolRuns []string
PendingPlanSteps []string
PendingApprovals []string
MissingChecks []string
}
```
硬规则:
- `Finalizable=false` 时禁止发送 `response` 终态事件。
- `Status=in_progress` 时只能发 `progress``planning``tool_*``reasoning_chain` 等过程事件。
- `FinalText` 不能为空,但非空不代表可以 final。
- `PendingToolRuns``PendingPlanSteps``PendingApprovals` 任一非空时不能 `completed`
- `EvidenceVerified=false` 时不能把候选输出写成已验证结论。
### 2. 固定 SSE 事件语义
推荐事件分层:
| 事件 | 展示位置 | 可否写 `messages.content` | 说明 |
|---|---|---:|---|
| `progress` | 任务状态/时间线 | 否 | 简短进度 |
| `planning` | 执行详情 | 否 | 主代理计划、阶段性判断 |
| `reasoning_chain` / `thinking` | 执行详情 | 否 | 推理/思考摘要 |
| `tool_call` / `tool_result` | 执行详情 | 否 | 工具事件 |
| `eino_agent_reply` | 执行详情 | 否 | 子代理返回材料 |
| `finalization_check` | 执行详情 | 否 | verifier 结果 |
| `finalization_auto_continue` | 执行详情 | 否 | verifier 触发的工程续跑,`contextInjection=false` |
| `response` | 主消息气泡 | 是 | 只能在 `data.finalized=true` 时使用 |
| `done` | 关闭流 | 否 | 仅表示流结束,不表示任务成功 |
| `error` / `cancelled` | 主消息气泡或系统提示 | 是,终态失败类 | 必须带原因 |
### 3. 把“最终候选”与“最终回复”分开
模型可以输出候选结论,但候选结论必须先进入 `final_candidate``planning`,再由 verifier 决定是否提升:
```text
assistant text
-> candidate
-> finalization gate
-> response(finalized=true)
```
不要这样做:
```text
assistant text
-> response
```
### 4. Stop-time Verification
借鉴 Claude Code hook 思路,在 agent run 停止时做一次确定性检查:
- 所有工具调用都有对应 tool result。
- 后台 execution 都处于 terminal 状态,或被明确登记为仍在运行且任务状态为 `in_progress` / `blocked`
- Plan-Execute 没有未执行的 required step。
- Supervisor 没有未汇总的子代理结果。
- 在 evidence-required 策略下,至少存在可查询到的 completed 工具执行证据。
### 5. 子代理输出只作证据
子代理返回不能直接成为用户最终回复。主代理必须完成:
- 去重和冲突合并。
- 证据强度排序。
- 不确定性标注。
- 范围边界确认。
- 用户可读交付。
### 6. Prompt 只做软约束,代码做硬约束
Prompt 中可以写:
```text
Interim observations must be marked as progress, not final.
Do not produce a final answer until verification is complete.
```
但真正决定 final 的必须是后端字段和状态机。否则模型只要生成一段像最终结论的自然语言,UI 仍可能误判。
## 四、CyberStrikeAI 当前落地状态
当前项目已经具备一套显式 final gate:
- [internal/agentfinalizer/decision.go](../../internal/agentfinalizer/decision.go) 是唯一的最终回复决策契约。
- [internal/handler/finalization_helpers.go](../../internal/handler/finalization_helpers.go) 负责把决策结果写入 `process_details`,并且只有 `Finalizable=true` 时才调用 `UpdateAssistantMessageFinalize`
- [internal/handler/eino_single_agent.go](../../internal/handler/eino_single_agent.go)、[internal/handler/multi_agent.go](../../internal/handler/multi_agent.go)、[internal/handler/workflow_integration.go](../../internal/handler/workflow_integration.go)、[internal/handler/batch_queue_executor.go](../../internal/handler/batch_queue_executor.go) 均已在收尾处接入 finalizer。
- [web/static/js/monitor.js](../../web/static/js/monitor.js) 只把 `data.finalized === true``response` 当最终回复;未最终化文本会显示为最终回复检查未通过。
- [web/static/js/webshell.js](../../web/static/js/webshell.js) 将流式正文标记为候选输出,只有 `response(finalized=true)` 才切换为完成态。
- [internal/agentfinalizer/decision_test.go](../../internal/agentfinalizer/decision_test.go) 覆盖 pending tool、HITL、空输出、证据策略要求但缺执行证据、失败证据不能支撑最终化、完成态证据可 final 等回归场景。
- [internal/handler/finalization_auto_continue.go](../../internal/handler/finalization_auto_continue.go) 在缺 completed 执行证据时最多自动续跑 2 段;续跑只恢复已有模型轨迹,不向 agent 注入新的 user/system 文案。
当前契约的核心规则:
1. **模型自然语言只是 candidate。**
`RunResult.Response` 不能直接升级为最终回复,必须经过 `agentfinalizer.Decide`
2. **所有 `response` 事件必须携带终态字段。**
至少包含 `finalized``finalizable``status``completionReason``evidenceVerified``evidenceRefs``pendingExecutionIds``missingChecks`
3. **未完成工具会阻断 final。**
`queued/running` 工具执行仍存在时,决策结果为 `in_progress/pending_tool_executions`
4. **执行证据必须由结构化策略声明。**
后端不从用户自然语言、助手回复或 agent mode 名称中推断执行意图。聊天请求通过 `finalization.requireExecutionEvidence` 显式声明;WebShell、Workflow、批量、机器人等执行入口由调用点显式传入 policy。policy 要求证据时,至少需要一个可查询到的 `completed` 工具执行记录;只有 failed/cancelled 记录不能支撑最终化。
5. **缺执行证据先工程续跑,再阻断。**
Eino 单代理和 Eino 多代理主链路在 `missing_execution_evidence` 时会先通过已有 trace 自动续跑,不注入额外上下文;达到续跑上限后仍缺证据才写入 blocked。
6. **HITL 和空输出不会 final。**
workflow 等待人工确认、空 assistant 文本、Eino 空输出占位均会写入阻断文案,而不是成功总结。
## 五、贴合当前项目的推荐架构
当前采用的链路是:
```text
Agent / Eino ADK events
-> event normalizer
-> process_details
-> finalization verifier
-> response(finalized=true)
-> messages.content
```
### 1. 后端统一 Finalizer
职责:
- 接收 `RunResult` / 候选文本、`mcpExecutionIds`、会话与助手消息 ID、HITL 状态、编排模式。
- 通过数据库查询工具执行状态,识别 pending、completed、failed、cancelled 等证据状态。
- 返回 `FinalizationDecision`
- 不调用高风险工具,只做状态和证据检查。
### 2. RunResult 终态字段
[internal/multiagent/runner.go](../../internal/multiagent/runner.go) 已扩展终态字段:
```go
type RunResult struct {
Response string
MCPExecutionIDs []string
LastAgentTraceInput string
LastAgentTraceOutput string
Finalized bool
Status string
CompletionReason string
EvidenceVerified bool
EvidenceRefs []string
PendingExecutionIDs []string
MissingChecks []string
}
```
### 3. 发送 `response` 的条件
在单代理、多代理、工作流、批处理收尾处统一执行:
```go
decision := h.finalizeAgentRunForDelivery(...)
if !decision.Finalizable {
sendEvent("finalization_check", "任务尚未达到最终回复条件", decision)
sendEvent("response", finalizationBlockedMessage(decision), finalizationResponsePayload(decision, extra))
return
}
sendEvent("response", decision.FinalText, finalizationResponsePayload(decision, extra))
```
### 4. 前端只信 `finalized=true`
在 [web/static/js/monitor.js](../../web/static/js/monitor.js) 的 `case 'response'` 中执行硬判断:
```js
const responseFinalized = isFinalizedResponseData(responseData);
const bubbleText = responseFinalized
? resolvedResponseText
: (event.message || '任务尚未达到最终回复条件,暂不生成成功结论。');
markAssistantFinalizationState(assistantIdFinal, responseData);
```
WebShell 侧同理:`response_delta` 可以用于实时预览,但 UI 文案应标记为“执行中输出”,只有最终 `response(finalized=true)` 才显示为完成态。
### 5. 各模式 final gate
| 模式 | 谁可以产出最终候选 | 谁决定 final | 必须检查 |
|---|---|---|---|
| Eino 单代理 | 单代理最后助手文本 | Finalizer | 无 pending tool、证据引用完整、任务状态 terminal |
| Deep | 主代理汇总文本 | Finalizer | 子代理结果已汇总;子代理文本不能直接 final;工具状态 terminal |
| Plan-Execute | Replanner 结束后的汇总文本 | Replanner + Finalizer | Executor 单步输出不能 final;计划步骤完成或明确 blocked |
| Supervisor | Supervisor 的 `exit` / 汇总文本 | Supervisor + Finalizer | transfer 已返回;无未处理专家结果;最终由 supervisor 统一口径 |
### 6. 安全测试场景的证据 gate
安全测试、WebShell、批量验证、Workflow 和多代理执行等 evidence-required 场景,最终回复必须至少满足:
- 有明确目标和授权范围标识。
- 有可复核证据引用,例如工具 execution id、请求/响应摘要、截图路径、命令输出摘要、事实/漏洞记录 ID。
- 有身份或影响验证结果,而不是只凭 marker 文本判断。
- 已记录到项目黑板或漏洞库,或明确说明未绑定项目导致无法记录。
- 高风险动作已清理、回滚、取消,或明确说明未执行清理的原因。
- 仍在运行的扫描/命令/WebShell/C2 任务不能被隐式当作完成。
注意:这里的 gate 是治理规则,不要求最终报告暴露敏感利用细节;可以只给证据摘要和内部引用。
## 六、落地状态与后续增强
### P0:先修“误 final”(已落地)
1. 已引入 `FinalizationDecision`
2. 主要 agent SSE `response` 事件已携带 `data.finalized/finalizable/status/completionReason` 等字段。
3. 前端 `monitor.js``webshell.js` 已按 `finalized=true` 区分候选输出和最终回复。
4. `RunResult.Response` 仍保留兼容字段名,但语义已由 finalizer 统一提升;后续可再拆成 `CandidateResponse` / `FinalResponse`,减少误用空间。
5. Plan-Execute / Deep / Supervisor / Eino Single 等模式均通过统一 handler 收尾 gate。
### P1:补证据链(部分落地)
1. 已用 `mcp_execution:<id>` 作为基础 evidence refs。
2. `finalization_check` 事件已展示 pending execution 与 missing checks。
3. 执行入口已启用显式 execution evidence policyEino 主链路在 policy 要求证据且缺少 completed 工具证据时先无注入续跑,达到上限后才阻断 final。
4. 后续建议:为 `record_vulnerability``upsert_project_fact`、项目黑板记录建立更细粒度 evidence refs。
5. 后续建议:最终报告模板固定包含“结论、证据、风险/不确定性、后续动作”。
### P2:体验和观测(后续增强)
1. 在任务卡片展示 `in_progress / verifying / finalizing / completed / blocked`
2. 为 finalizer 加日志和指标:误拦截率、缺失证据类型、pending tool 数量。
3. 支持“继续验证”按钮,从 `FinalizationDecision.MissingChecks` 自动生成下一轮输入。
## 七、验收测试建议
至少加入这些回归测试:
1. **推理文本不 final**
模拟 `reasoning_chain` 里出现看似完成的候选结论,但本轮没有 completed 工具执行证据;预期主消息气泡不显示成功结论,只显示执行中或阻断态。
2. **主代理阶段性输出不 final**
模拟 `response_start/delta` 输出“下一步继续验证”;预期只进入 timeline `planning`
3. **未完成后台工具不 final**
工具返回 `execution_id` 且状态 `running`;即使模型给出总结,也只能 `in_progress`
4. **Plan-Execute Executor 输出不 final**
Executor 输出“突破成功”,但 Replanner 未结束;预期不触发 `messages.content` finalize。
5. **Supervisor 子代理输出不 final**
子代理返回确定结论,Supervisor 未 `exit`;预期只进入 `eino_agent_reply`
6. **最终事件必须带 finalized**
前端收到旧格式 `response``finalized=true`;预期候选内容只进入详情/警告,主消息显示阻断态,不创建成功最终气泡。
7. **失败和取消可终态**
`error` / `cancelled` 仍可更新助手消息,但 `completionReason` 必须是 `failed` / `user_cancelled`,不能伪装为成功完成。
## 八、推荐默认策略
对 CyberStrikeAI,建议默认策略是:
```text
eino_single:轻量任务可用,但 final gate 必须开启
deep:复杂安全测试默认推荐
plan_execute:目标明确、需要严格“规划-执行-重规划”的任务推荐
supervisor:多专家路由任务使用,不作为默认泛化模式
```
最终治理一句话:
```text
messages.content 只能来自 FinalizationDecision.FinalText
process_details 可以展示所有过程;
前端只能把 response(finalized=true) 当最终回复。
```
+10 -2
View File
@@ -32,13 +32,21 @@ https://127.0.0.1:8080/
如果仍有其他具备 `rbac:write` 权限的管理员账号,优先在 **平台权限 → 用户管理** 中重置密码。
如果没有可用的管理员会话,可在服务器上紧急重置内置 `admin` 账号。先停止 CyberStrikeAI 服务并备份数据库,然后在项目根目录执行以下命令,按提示输入并确认新密码
如果没有可用的管理员会话,可在服务器上紧急重置内置 `admin` 账号。在项目根目录执行
```bash
./run.sh --reset-admin-password
```
按提示输入并确认新密码。脚本会隐藏输入并写入 bcrypt 哈希。如果服务正在运行,完成后重新启动服务,使原有登录会话失效。
如果无法使用 `run.sh`,也可以手动执行以下命令,按提示输入并确认新密码:
```bash
HASH=$(htpasswd -nBC 10 '' | cut -d: -f2 | tr -d '\n') && sqlite3 data/conversations.db "UPDATE rbac_users SET password_hash='$HASH', updated_at=CURRENT_TIMESTAMP WHERE id='admin' AND username='admin' AND is_builtin=1; SELECT changes();"
```
输出 `1` 表示修改成功。该命令需要 `sqlite3``htpasswd`;如果 `config.yaml` 中的 `database.path` 不是默认值,请替换 `data/conversations.db`。密码输入不会显示,也不会写入 Shell 历史,并以 bcrypt 哈希保存。完成后重新启动服务,使原有登录会话失效
输出 `1` 表示修改成功。该命令需要 `sqlite3``htpasswd`;如果 `config.yaml` 中的 `database.path` 不是默认值,请替换 `data/conversations.db`。密码输入不会显示,也不会写入 Shell 历史。
## 模型无响应
+1
View File
@@ -37,6 +37,7 @@ require (
go.opentelemetry.io/otel/trace v1.34.0
go.uber.org/zap v1.26.0
golang.org/x/net v0.35.0
golang.org/x/term v0.32.0
golang.org/x/text v0.26.0
golang.org/x/time v0.14.0
gopkg.in/yaml.v3 v3.0.1
+14 -22
View File
@@ -514,6 +514,14 @@ type ToolExecutionResult struct {
IsError bool
}
func buildToolFailureMessage(toolName, detail string, err error) string {
var b strings.Builder
fmt.Fprintf(&b, "工具调用失败\n\n")
fmt.Fprintf(&b, "工具名称: %s\n", toolName)
fmt.Fprintf(&b, "错误详情: %s", detail)
return strings.TrimRight(b.String(), "\n")
}
// executeToolViaMCP 通过MCP执行工具
// 即使工具执行失败,也返回结果而不是错误,让AI能够处理错误情况
func (a *Agent) executeToolViaMCP(ctx context.Context, toolName string, args map[string]interface{}) (*ToolExecutionResult, error) {
@@ -573,32 +581,16 @@ func (a *Agent) executeToolViaMCP(ctx context.Context, toolName string, args map
// 如果调用失败(如工具不存在、超时),返回友好的错误信息而不是抛出异常
if err != nil {
detail := err.Error()
timeoutMinutes := 10
if a.agentConfig != nil && a.agentConfig.ToolTimeoutMinutes > 0 {
timeoutMinutes = a.agentConfig.ToolTimeoutMinutes
}
if errors.Is(err, context.Canceled) {
detail = "工具调用已被手动终止(MCP 监控页)。智能体将携带此结果继续后续步骤,整条任务不会因此被停止。"
} else if errors.Is(err, context.DeadlineExceeded) {
min := 10
if a.agentConfig != nil && a.agentConfig.ToolTimeoutMinutes > 0 {
min = a.agentConfig.ToolTimeoutMinutes
}
detail = fmt.Sprintf("工具执行超过 %d 分钟被自动终止(可在 config.yaml 的 agent.tool_timeout_minutes 中调整)", min)
detail = fmt.Sprintf("工具执行超过 %d 分钟被自动终止(可在 config.yaml 的 agent.tool_timeout_minutes 中调整)", timeoutMinutes)
}
errorMsg := fmt.Sprintf(`工具调用失败
工具名称: %s
错误类型: 系统错误
错误详情: %s
可能的原因:
- 工具 "%s" 不存在或未启用
- 单次执行超时(agent.tool_timeout_minutes
- 系统配置问题
- 网络或权限问题
建议:
- 检查工具名称是否正确
- 若需更长执行时间,可适当增大 agent.tool_timeout_minutes
- 尝试使用其他替代工具
- 如果这是必需的工具,请向用户说明情况`, toolName, detail, toolName)
errorMsg := buildToolFailureMessage(toolName, detail, err)
return &ToolExecutionResult{
Result: errorMsg,
+75
View File
@@ -2,6 +2,7 @@ package agent
import (
"context"
"errors"
"strings"
"sync"
"testing"
@@ -71,6 +72,80 @@ func TestAgent_NewAgent_CustomConfig(t *testing.T) {
}
}
func TestBuildToolFailureMessageAuthorizationDenied(t *testing.T) {
msg := buildToolFailureMessage(
"list_project_facts",
"tool authorization denied: no access to project",
errors.New("tool authorization denied: no access to project"),
)
for _, want := range []string{
"工具名称: list_project_facts",
"错误详情: tool authorization denied: no access to project",
} {
if !strings.Contains(msg, want) {
t.Fatalf("message missing %q:\n%s", want, msg)
}
}
for _, notWant := range []string{
"可能的原因",
"建议",
"错误类型",
"工具 \"list_project_facts\" 不存在或未启用",
"单次执行超时",
} {
if strings.Contains(msg, notWant) {
t.Fatalf("message should not include generic hint %q:\n%s", notWant, msg)
}
}
}
func TestBuildToolFailureMessageCanceled(t *testing.T) {
msg := buildToolFailureMessage(
"long_running_tool",
"工具调用已被手动终止(MCP 监控页)。智能体将携带此结果继续后续步骤,整条任务不会因此被停止。",
context.Canceled,
)
for _, want := range []string{
"工具名称: long_running_tool",
"错误详情: 工具调用已被手动终止",
} {
if !strings.Contains(msg, want) {
t.Fatalf("message missing %q:\n%s", want, msg)
}
}
}
func TestBuildToolFailureMessageDeadlineExceeded(t *testing.T) {
msg := buildToolFailureMessage(
"nmap",
"工具执行超过 15 分钟被自动终止(可在 config.yaml 的 agent.tool_timeout_minutes 中调整)",
context.DeadlineExceeded,
)
for _, want := range []string{
"工具名称: nmap",
"错误详情: 工具执行超过 15 分钟被自动终止",
} {
if !strings.Contains(msg, want) {
t.Fatalf("message missing %q:\n%s", want, msg)
}
}
}
func TestBuildToolFailureMessageUnknownKeepsGenericFallback(t *testing.T) {
msg := buildToolFailureMessage("custom_tool", "dial tcp: connection reset by peer", errors.New("dial tcp: connection reset by peer"))
for _, want := range []string{
"工具名称: custom_tool",
"错误详情: dial tcp: connection reset by peer",
} {
if !strings.Contains(msg, want) {
t.Fatalf("message missing %q:\n%s", want, msg)
}
}
}
func TestAgentCancelRunningMCPToolsForConversation(t *testing.T) {
ag := setupTestAgent(t)
ag.mcpServer.ConfigureToolWaitTimeoutSeconds(1)
+266
View File
@@ -0,0 +1,266 @@
package agentfinalizer
import (
"strings"
"cyberstrike-ai/internal/database"
"cyberstrike-ai/internal/mcp"
"cyberstrike-ai/internal/multiagent"
)
const (
StatusCompleted = "completed"
StatusInProgress = "in_progress"
StatusBlocked = "blocked"
StatusFailed = "failed"
StatusCancelled = "cancelled"
StatusAwaitingHITL = "awaiting_hitl"
ReasonVerified = "verified"
ReasonPendingTools = "pending_tool_executions"
ReasonEmptyResponse = "empty_response"
ReasonAwaitingHITL = "awaiting_hitl"
ReasonFailed = "failed"
ReasonCancelled = "cancelled"
ReasonMissingEvidence = "missing_execution_evidence"
)
// Decision is the single contract that may promote an agent run to a final
// user-facing answer. Natural-language assistant text is only a candidate until
// this object says Finalizable.
type Decision struct {
Status string `json:"status"`
Finalizable bool `json:"finalizable"`
Finalized bool `json:"finalized"`
CompletionReason string `json:"completionReason"`
FinalText string `json:"finalText,omitempty"`
EvidenceVerified bool `json:"evidenceVerified"`
EvidenceRefs []string `json:"evidenceRefs,omitempty"`
PendingExecutionIDs []string `json:"pendingExecutionIds,omitempty"`
PendingToolRuns []string `json:"pendingToolRuns,omitempty"`
MissingChecks []string `json:"missingChecks,omitempty"`
AgentMode string `json:"agentMode,omitempty"`
ConversationID string `json:"conversationId,omitempty"`
AssistantMessageID string `json:"messageId,omitempty"`
CandidateResponseLen int `json:"candidateResponseLen,omitempty"`
}
type Input struct {
Response string
MCPExecutionIDs []string
ConversationID string
AssistantMessageID string
AgentMode string
Status string
CompletionReason string
AwaitingHITL bool
RequireExecutionEvidence bool
}
func FromRunResult(db *database.DB, result *multiagent.RunResult, in Input) Decision {
if result != nil {
if strings.TrimSpace(in.Response) == "" {
in.Response = result.Response
}
if len(in.MCPExecutionIDs) == 0 {
in.MCPExecutionIDs = result.MCPExecutionIDs
}
if strings.TrimSpace(in.Status) == "" {
in.Status = result.Status
}
if strings.TrimSpace(in.CompletionReason) == "" {
in.CompletionReason = result.CompletionReason
}
}
d := Decide(db, in)
if result != nil {
result.Finalized = d.Finalized
result.Status = d.Status
result.CompletionReason = d.CompletionReason
result.EvidenceVerified = d.EvidenceVerified
result.EvidenceRefs = append([]string(nil), d.EvidenceRefs...)
result.PendingExecutionIDs = append([]string(nil), d.PendingExecutionIDs...)
result.MissingChecks = append([]string(nil), d.MissingChecks...)
}
return d
}
func Decide(db *database.DB, in Input) Decision {
text := strings.TrimSpace(in.Response)
status := strings.TrimSpace(in.Status)
if status == "" {
status = StatusCompleted
}
reason := strings.TrimSpace(in.CompletionReason)
if reason == "" {
reason = ReasonVerified
}
d := Decision{
Status: status,
CompletionReason: reason,
FinalText: text,
EvidenceVerified: true,
EvidenceRefs: evidenceRefs(in.MCPExecutionIDs),
AgentMode: strings.TrimSpace(in.AgentMode),
ConversationID: strings.TrimSpace(in.ConversationID),
AssistantMessageID: strings.TrimSpace(in.AssistantMessageID),
CandidateResponseLen: len([]rune(text)),
}
if in.AwaitingHITL {
d.Status = StatusAwaitingHITL
d.CompletionReason = ReasonAwaitingHITL
d.EvidenceVerified = false
d.MissingChecks = append(d.MissingChecks, "workflow is awaiting HITL approval")
return d
}
if isEmptyCandidate(text) {
d.Status = StatusBlocked
d.CompletionReason = ReasonEmptyResponse
d.EvidenceVerified = false
d.MissingChecks = append(d.MissingChecks, "assistant final text is empty or only an empty-response placeholder")
return d
}
switch status {
case StatusInProgress, StatusBlocked, StatusFailed, StatusCancelled, StatusAwaitingHITL:
d.Status = status
d.EvidenceVerified = false
if d.CompletionReason == ReasonVerified {
d.CompletionReason = status
}
d.MissingChecks = append(d.MissingChecks, "agent run status is "+status)
return d
}
pending := pendingExecutions(db, in.MCPExecutionIDs)
if len(pending) > 0 {
d.Status = StatusInProgress
d.CompletionReason = ReasonPendingTools
d.EvidenceVerified = false
d.PendingExecutionIDs = pending
d.PendingToolRuns = append([]string(nil), pending...)
d.MissingChecks = append(d.MissingChecks, "tool execution still queued or running")
return d
}
if in.RequireExecutionEvidence && !hasCompletedEvidence(db, in.MCPExecutionIDs) {
d.Status = StatusBlocked
d.CompletionReason = ReasonMissingEvidence
d.EvidenceVerified = false
d.MissingChecks = append(d.MissingChecks, "execution evidence is required but no completed tool execution was recorded")
return d
}
d.Finalizable = true
d.Finalized = true
d.Status = StatusCompleted
if d.CompletionReason == "" {
d.CompletionReason = ReasonVerified
}
return d
}
func ResponsePayload(d Decision, extra map[string]interface{}) map[string]interface{} {
out := map[string]interface{}{
"finalized": d.Finalized,
"finalizable": d.Finalizable,
"status": d.Status,
"completionReason": d.CompletionReason,
"evidenceVerified": d.EvidenceVerified,
"evidenceRefs": d.EvidenceRefs,
"pendingExecutionIds": d.PendingExecutionIDs,
"pendingToolRuns": d.PendingToolRuns,
"missingChecks": d.MissingChecks,
}
if d.ConversationID != "" {
out["conversationId"] = d.ConversationID
}
if d.AssistantMessageID != "" {
out["messageId"] = d.AssistantMessageID
}
if d.AgentMode != "" {
out["agentMode"] = d.AgentMode
}
for k, v := range extra {
out[k] = v
}
return out
}
func isEmptyCandidate(s string) bool {
s = strings.TrimSpace(s)
if s == "" {
return true
}
return strings.Contains(s, "no assistant text was captured") ||
strings.Contains(s, "未捕获到助手文本输出")
}
func evidenceRefs(ids []string) []string {
out := make([]string, 0, len(ids))
seen := make(map[string]struct{}, len(ids))
for _, id := range ids {
id = strings.TrimSpace(id)
if id == "" {
continue
}
if _, ok := seen[id]; ok {
continue
}
seen[id] = struct{}{}
out = append(out, "mcp_execution:"+id)
}
return out
}
func pendingExecutions(db *database.DB, ids []string) []string {
if db == nil || len(ids) == 0 {
return nil
}
out := make([]string, 0)
seen := make(map[string]struct{}, len(ids))
for _, id := range ids {
id = strings.TrimSpace(id)
if id == "" {
continue
}
if _, ok := seen[id]; ok {
continue
}
seen[id] = struct{}{}
exec, err := db.GetToolExecution(id)
if err != nil || exec == nil {
continue
}
switch strings.TrimSpace(exec.Status) {
case mcp.ToolExecutionStatusQueued, mcp.ToolExecutionStatusRunning:
out = append(out, id)
}
}
return out
}
func hasCompletedEvidence(db *database.DB, ids []string) bool {
if db == nil || len(ids) == 0 {
return false
}
seen := make(map[string]struct{}, len(ids))
for _, id := range ids {
id = strings.TrimSpace(id)
if id == "" {
continue
}
if _, ok := seen[id]; ok {
continue
}
seen[id] = struct{}{}
exec, err := db.GetToolExecution(id)
if err != nil || exec == nil {
continue
}
if strings.TrimSpace(exec.Status) == mcp.ToolExecutionStatusCompleted {
return true
}
}
return false
}
+132
View File
@@ -0,0 +1,132 @@
package agentfinalizer
import (
"path/filepath"
"testing"
"time"
"cyberstrike-ai/internal/database"
"cyberstrike-ai/internal/mcp"
"go.uber.org/zap"
)
func newDecisionTestDB(t *testing.T) *database.DB {
t.Helper()
db, err := database.NewDB(filepath.Join(t.TempDir(), "finalizer.db"), zap.NewNop())
if err != nil {
t.Fatalf("NewDB: %v", err)
}
t.Cleanup(func() { _ = db.Close() })
return db
}
func saveDecisionTestExecution(t *testing.T, db *database.DB, id, status string) {
t.Helper()
if err := db.SaveToolExecution(&mcp.ToolExecution{
ID: id,
ToolName: "test::tool",
Arguments: map[string]interface{}{"input": id},
Status: status,
StartTime: time.Now(),
}); err != nil {
t.Fatalf("SaveToolExecution(%s): %v", id, err)
}
}
func TestDecideBlocksPendingToolExecutions(t *testing.T) {
db := newDecisionTestDB(t)
saveDecisionTestExecution(t, db, "run-queued", mcp.ToolExecutionStatusQueued)
saveDecisionTestExecution(t, db, "run-running", mcp.ToolExecutionStatusRunning)
saveDecisionTestExecution(t, db, "run-completed", mcp.ToolExecutionStatusCompleted)
d := Decide(db, Input{
Response: "工具还没全部结束时,这只是一段候选输出。",
MCPExecutionIDs: []string{"run-queued", "run-running", "run-completed"},
})
if d.Finalizable || d.Finalized {
t.Fatalf("pending tools should not be finalizable: %+v", d)
}
if d.Status != StatusInProgress || d.CompletionReason != ReasonPendingTools {
t.Fatalf("status/reason = %s/%s, want %s/%s", d.Status, d.CompletionReason, StatusInProgress, ReasonPendingTools)
}
if got, want := len(d.PendingExecutionIDs), 2; got != want {
t.Fatalf("pending execution count = %d, want %d (%v)", got, want, d.PendingExecutionIDs)
}
}
func TestDecideBlocksAwaitingHITLAndEmptyCandidate(t *testing.T) {
hitl := Decide(nil, Input{Response: "等待人工审批", AwaitingHITL: true})
if hitl.Finalizable || hitl.Status != StatusAwaitingHITL || hitl.CompletionReason != ReasonAwaitingHITL {
t.Fatalf("HITL decision mismatch: %+v", hitl)
}
empty := Decide(nil, Input{Response: "⚠️ Eino 执行完成,但未捕获到助手文本输出。"})
if empty.Finalizable || empty.Status != StatusBlocked || empty.CompletionReason != ReasonEmptyResponse {
t.Fatalf("empty candidate decision mismatch: %+v", empty)
}
}
func TestDecideBlocksWhenExecutionEvidenceIsRequiredButMissing(t *testing.T) {
d := Decide(nil, Input{
Response: "任务已处理完成。",
RequireExecutionEvidence: true,
})
if d.Finalizable || d.Finalized {
t.Fatalf("missing required execution evidence should not finalize: %+v", d)
}
if d.Status != StatusBlocked || d.CompletionReason != ReasonMissingEvidence {
t.Fatalf("status/reason = %s/%s, want %s/%s", d.Status, d.CompletionReason, StatusBlocked, ReasonMissingEvidence)
}
if d.EvidenceVerified {
t.Fatalf("missing required execution evidence should be marked unverified: %+v", d)
}
if len(d.MissingChecks) == 0 {
t.Fatalf("missing checks should explain the evidence gap: %+v", d)
}
}
func TestDecideBlocksWhenOnlyFailedEvidenceIsRecorded(t *testing.T) {
db := newDecisionTestDB(t)
saveDecisionTestExecution(t, db, "run-failed", mcp.ToolExecutionStatusFailed)
saveDecisionTestExecution(t, db, "run-cancelled", mcp.ToolExecutionStatusCancelled)
d := Decide(db, Input{
Response: "任务已处理完成。",
MCPExecutionIDs: []string{"run-failed", "run-cancelled"},
RequireExecutionEvidence: true,
})
if d.Finalizable || d.Finalized {
t.Fatalf("failed evidence should not satisfy required execution evidence: %+v", d)
}
if d.Status != StatusBlocked || d.CompletionReason != ReasonMissingEvidence {
t.Fatalf("status/reason = %s/%s, want %s/%s", d.Status, d.CompletionReason, StatusBlocked, ReasonMissingEvidence)
}
}
func TestDecideFinalizesCompletedEvidence(t *testing.T) {
db := newDecisionTestDB(t)
saveDecisionTestExecution(t, db, "run-ok", mcp.ToolExecutionStatusCompleted)
d := Decide(db, Input{
Response: "任务已处理完成,见工具执行记录。",
MCPExecutionIDs: []string{"run-ok"},
RequireExecutionEvidence: true,
})
if !d.Finalizable || !d.Finalized || d.Status != StatusCompleted {
t.Fatalf("completed execution should finalize: %+v", d)
}
if !d.EvidenceVerified || len(d.EvidenceRefs) != 1 {
t.Fatalf("evidence refs mismatch: %+v", d)
}
}
func TestDecideAllowsInformationalAnswerWhenExecutionEvidenceIsNotRequired(t *testing.T) {
d := Decide(nil, Input{Response: "这是一个概念解释,不需要执行工具。"})
if !d.Finalizable || !d.Finalized || d.Status != StatusCompleted {
t.Fatalf("informational response should finalize when execution evidence is not required: %+v", d)
}
}
+7 -1
View File
@@ -382,7 +382,13 @@ func authorizeProjectTool(ctx context.Context, principal authctx.Principal, db *
return fmt.Errorf("no access to conversation %s", conversationID)
}
projectID, err := db.GetConversationProjectID(conversationID)
if err != nil || strings.TrimSpace(projectID) == "" || !db.UserCanAccessResource(principal.UserID, principal.ScopeFor(permission), "project", projectID) {
if err != nil {
return fmt.Errorf("no access to project: %w", err)
}
if strings.TrimSpace(projectID) == "" {
return fmt.Errorf("当前对话未绑定项目,无法使用项目黑板工具,请先在对话中选择项目或创建带项目的对话")
}
if !db.UserCanAccessResource(principal.UserID, principal.ScopeFor(permission), "project", projectID) {
return fmt.Errorf("no access to project %s", projectID)
}
return nil
+60 -21
View File
@@ -23,6 +23,7 @@ type Conversation struct {
Title string `json:"title"`
ProjectID string `json:"projectId,omitempty"`
RoleName string `json:"roleName,omitempty"`
AgentMode string `json:"agentMode,omitempty"`
Pinned bool `json:"pinned"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
@@ -59,29 +60,30 @@ func (db *DB) CreateConversationWithWebshell(webshellConnectionID, title string,
}
}
roleName := normalizeConversationRoleName(meta.RoleName)
agentMode := normalizeConversationAgentMode(meta.AgentMode)
var err error
wsID := strings.TrimSpace(webshellConnectionID)
switch {
case wsID != "" && projectID != "":
_, err = db.Exec(
"INSERT INTO conversations (id, title, created_at, updated_at, webshell_connection_id, project_id, role_name) VALUES (?, ?, ?, ?, ?, ?, ?)",
id, title, now, now, wsID, projectID, roleName,
"INSERT INTO conversations (id, title, created_at, updated_at, webshell_connection_id, project_id, role_name, agent_mode) VALUES (?, ?, ?, ?, ?, ?, ?, ?)",
id, title, now, now, wsID, projectID, roleName, agentMode,
)
case wsID != "":
_, err = db.Exec(
"INSERT INTO conversations (id, title, created_at, updated_at, webshell_connection_id, role_name) VALUES (?, ?, ?, ?, ?, ?)",
id, title, now, now, wsID, roleName,
"INSERT INTO conversations (id, title, created_at, updated_at, webshell_connection_id, role_name, agent_mode) VALUES (?, ?, ?, ?, ?, ?, ?)",
id, title, now, now, wsID, roleName, agentMode,
)
case projectID != "":
_, err = db.Exec(
"INSERT INTO conversations (id, title, created_at, updated_at, project_id, role_name) VALUES (?, ?, ?, ?, ?, ?)",
id, title, now, now, projectID, roleName,
"INSERT INTO conversations (id, title, created_at, updated_at, project_id, role_name, agent_mode) VALUES (?, ?, ?, ?, ?, ?, ?)",
id, title, now, now, projectID, roleName, agentMode,
)
default:
_, err = db.Exec(
"INSERT INTO conversations (id, title, created_at, updated_at, role_name) VALUES (?, ?, ?, ?, ?)",
id, title, now, now, roleName,
"INSERT INTO conversations (id, title, created_at, updated_at, role_name, agent_mode) VALUES (?, ?, ?, ?, ?, ?)",
id, title, now, now, roleName, agentMode,
)
}
if err != nil {
@@ -93,6 +95,7 @@ func (db *DB) CreateConversationWithWebshell(webshellConnectionID, title string,
Title: title,
ProjectID: projectID,
RoleName: roleName,
AgentMode: agentMode,
CreatedAt: now,
UpdatedAt: now,
}
@@ -240,10 +243,11 @@ func (db *DB) GetConversation(id string) (*Conversation, error) {
var projectID sql.NullString
var roleName sql.NullString
var agentMode sql.NullString
err := db.QueryRow(
"SELECT id, title, pinned, created_at, updated_at, project_id, role_name FROM conversations WHERE id = ?",
"SELECT id, title, pinned, created_at, updated_at, project_id, role_name, agent_mode FROM conversations WHERE id = ?",
id,
).Scan(&conv.ID, &conv.Title, &pinned, &createdAt, &updatedAt, &projectID, &roleName)
).Scan(&conv.ID, &conv.Title, &pinned, &createdAt, &updatedAt, &projectID, &roleName, &agentMode)
if err != nil {
if err == sql.ErrNoRows {
return nil, fmt.Errorf("对话不存在")
@@ -256,6 +260,9 @@ func (db *DB) GetConversation(id string) (*Conversation, error) {
if roleName.Valid {
conv.RoleName = normalizeConversationRoleName(roleName.String)
}
if agentMode.Valid {
conv.AgentMode = normalizeConversationAgentMode(agentMode.String)
}
// 尝试多种时间格式解析
var err1, err2 error
@@ -330,10 +337,11 @@ func (db *DB) GetConversationLite(id string) (*Conversation, error) {
var projectID sql.NullString
var roleName sql.NullString
var agentMode sql.NullString
err := db.QueryRow(
"SELECT id, title, pinned, created_at, updated_at, project_id, role_name FROM conversations WHERE id = ?",
"SELECT id, title, pinned, created_at, updated_at, project_id, role_name, agent_mode FROM conversations WHERE id = ?",
id,
).Scan(&conv.ID, &conv.Title, &pinned, &createdAt, &updatedAt, &projectID, &roleName)
).Scan(&conv.ID, &conv.Title, &pinned, &createdAt, &updatedAt, &projectID, &roleName, &agentMode)
if err != nil {
if err == sql.ErrNoRows {
return nil, fmt.Errorf("对话不存在")
@@ -346,6 +354,9 @@ func (db *DB) GetConversationLite(id string) (*Conversation, error) {
if roleName.Valid {
conv.RoleName = normalizeConversationRoleName(roleName.String)
}
if agentMode.Valid {
conv.AgentMode = normalizeConversationAgentMode(agentMode.String)
}
// 尝试多种时间格式解析
var err1, err2 error
@@ -384,6 +395,17 @@ func normalizeConversationRoleName(roleName string) string {
return roleName
}
func normalizeConversationAgentMode(agentMode string) string {
agentMode = strings.ToLower(strings.TrimSpace(agentMode))
agentMode = strings.ReplaceAll(agentMode, "-", "_")
switch agentMode {
case "deep", "plan_execute", "supervisor":
return agentMode
default:
return "eino_single"
}
}
func (db *DB) SetConversationRoleName(id, roleName string) error {
roleName = normalizeConversationRoleName(roleName)
_, err := db.Exec(
@@ -396,6 +418,18 @@ func (db *DB) SetConversationRoleName(id, roleName string) error {
return nil
}
func (db *DB) SetConversationAgentMode(id, agentMode string) error {
agentMode = normalizeConversationAgentMode(agentMode)
_, err := db.Exec(
"UPDATE conversations SET agent_mode = ? WHERE id = ?",
agentMode, id,
)
if err != nil {
return fmt.Errorf("更新对话模式失败: %w", err)
}
return nil
}
func conversationProjectIDColumn(alias string) string {
if alias != "" {
return alias + ".project_id"
@@ -520,7 +554,7 @@ func (db *DB) ListConversations(limit, offset int, search, sortBy, projectID str
where, args = appendConversationProjectFilter(where, args, projectID, "c")
args = append(args, limit, offset)
rows, err = db.Query(
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name, c.agent_mode
FROM conversations c`+where+`
`+orderClause+`
LIMIT ? OFFSET ?`,
@@ -536,7 +570,7 @@ func (db *DB) ListConversations(limit, offset int, search, sortBy, projectID str
}
args = append(args, limit, offset)
rows, err = db.Query(
"SELECT id, title, COALESCE(pinned, 0), created_at, updated_at, project_id, role_name FROM conversations"+where+" "+orderClause+" LIMIT ? OFFSET ?",
"SELECT id, title, COALESCE(pinned, 0), created_at, updated_at, project_id, role_name, agent_mode FROM conversations"+where+" "+orderClause+" LIMIT ? OFFSET ?",
args...,
)
}
@@ -564,7 +598,7 @@ func (db *DB) ListConversationsForAccess(limit, offset int, search, sortBy, proj
where, args = appendConversationAccessFilter(where, args, userID, scope, "c")
args = append(args, limit, offset)
rows, err = db.Query(
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name, c.agent_mode
FROM conversations c`+where+`
`+orderClause+`
LIMIT ? OFFSET ?`, args...)
@@ -579,7 +613,7 @@ func (db *DB) ListConversationsForAccess(limit, offset int, search, sortBy, proj
}
args = append(args, limit, offset)
rows, err = db.Query(
"SELECT id, title, COALESCE(pinned, 0), created_at, updated_at, project_id, role_name FROM conversations"+where+" "+orderClause+" LIMIT ? OFFSET ?",
"SELECT id, title, COALESCE(pinned, 0), created_at, updated_at, project_id, role_name, agent_mode FROM conversations"+where+" "+orderClause+" LIMIT ? OFFSET ?",
args...)
}
if err != nil {
@@ -597,7 +631,8 @@ func scanConversationRows(rows *sql.Rows) ([]*Conversation, error) {
var pinned int
var projectID sql.NullString
var roleName sql.NullString
if err := rows.Scan(&conv.ID, &conv.Title, &pinned, &createdAt, &updatedAt, &projectID, &roleName); err != nil {
var agentMode sql.NullString
if err := rows.Scan(&conv.ID, &conv.Title, &pinned, &createdAt, &updatedAt, &projectID, &roleName, &agentMode); err != nil {
return nil, fmt.Errorf("扫描对话失败: %w", err)
}
if projectID.Valid {
@@ -606,6 +641,9 @@ func scanConversationRows(rows *sql.Rows) ([]*Conversation, error) {
if roleName.Valid {
conv.RoleName = normalizeConversationRoleName(roleName.String)
}
if agentMode.Valid {
conv.AgentMode = normalizeConversationAgentMode(agentMode.String)
}
var err1, err2 error
conv.CreatedAt, err1 = time.Parse("2006-01-02 15:04:05.999999999-07:00", createdAt)
if err1 != nil {
@@ -665,7 +703,7 @@ func (db *DB) ListUngroupedConversations(limit, offset int, sortBy, projectID st
where, args = appendConversationProjectFilter(where, args, projectID, "c")
args = append(args, limit, offset)
rows, err := db.Query(
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name `+
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name, c.agent_mode `+
where+`
`+orderClause+`
LIMIT ? OFFSET ?`,
@@ -689,7 +727,7 @@ func (db *DB) ListUngroupedConversationsForAccess(limit, offset int, sortBy, pro
where, args = appendConversationAccessFilter(where, args, userID, scope, "c")
args = append(args, limit, offset)
rows, err := db.Query(
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name `+
`SELECT c.id, c.title, COALESCE(c.pinned, 0), c.created_at, c.updated_at, c.project_id, c.role_name, c.agent_mode `+
where+`
`+orderClause+`
LIMIT ? OFFSET ?`,
@@ -1424,7 +1462,8 @@ func (db *DB) GetProcessDetailsSummary(messageID string) (*ProcessDetailsSummary
seenExecIDs := make(map[string]bool)
// A provider may reuse a fallback toolCallId across streaming rounds. Keep a
// FIFO per ID instead of a single index so every persisted call gets at most
// one result. Results without an ID fall back to the oldest unmatched call.
// one result. Results without a stable ID are kept separate instead of being
// guessed by order; showing no link is safer than linking to the wrong tool.
toolIndexesByCallID := make(map[string][]int)
lastMatchedToolIndexByCallID := make(map[string]int)
matchedToolIndexes := make([]bool, 0)
@@ -1499,7 +1538,7 @@ func (db *DB) GetProcessDetailsSummary(messageID string) (*ProcessDetailsSummary
}
}
}
if idx < 0 {
if idx < 0 && toolCallID != "" {
for nextUnmatchedToolIdx < len(matchedToolIndexes) && matchedToolIndexes[nextUnmatchedToolIdx] {
nextUnmatchedToolIdx++
}
@@ -6,6 +6,7 @@ type ConversationCreateMeta struct {
WebShellConnectionID string
ProjectID string
RoleName string
AgentMode string
ClientIP string
SessionHint string
}
+16
View File
@@ -184,6 +184,7 @@ func (db *DB) initTables() error {
created_at DATETIME NOT NULL,
updated_at DATETIME NOT NULL,
role_name TEXT NOT NULL DEFAULT '默认',
agent_mode TEXT NOT NULL DEFAULT 'eino_single',
last_react_input TEXT,
last_react_output TEXT
);`
@@ -1174,6 +1175,21 @@ func (db *DB) migrateConversationsTable() error {
}
}
// 检查 agent_mode 字段是否存在(对话绑定的执行模式,用于历史任务切换时恢复对话模式)
err = db.QueryRow("SELECT COUNT(*) FROM pragma_table_info('conversations') WHERE name='agent_mode'").Scan(&count)
if err != nil {
if _, addErr := db.Exec("ALTER TABLE conversations ADD COLUMN agent_mode TEXT NOT NULL DEFAULT 'eino_single'"); addErr != nil {
errMsg := strings.ToLower(addErr.Error())
if !strings.Contains(errMsg, "duplicate column") && !strings.Contains(errMsg, "already exists") {
db.logger.Warn("添加agent_mode字段失败", zap.Error(addErr))
}
}
} else if count == 0 {
if _, err := db.Exec("ALTER TABLE conversations ADD COLUMN agent_mode TEXT NOT NULL DEFAULT 'eino_single'"); err != nil {
db.logger.Warn("添加agent_mode字段失败", zap.Error(err))
}
}
return nil
}
@@ -7,7 +7,7 @@ import (
"go.uber.org/zap"
)
func TestProcessDetailsSummaryPairsMixedIdentifiedAndIDLessResults(t *testing.T) {
func TestProcessDetailsSummaryDoesNotGuessIDLessResultsByOrder(t *testing.T) {
db, conversationID, messageID := setupProcessDetailsSummaryTest(t)
for _, id := range []string{"call-1", "call-2", "call-3", "call-4"} {
if err := db.AddProcessDetail(messageID, conversationID, "tool_call", "call", map[string]interface{}{
@@ -32,14 +32,24 @@ func TestProcessDetailsSummaryPairsMixedIdentifiedAndIDLessResults(t *testing.T)
if err != nil {
t.Fatalf("GetProcessDetailsSummary: %v", err)
}
if len(summary.ToolExecutions) != 4 {
t.Fatalf("tool executions = %d, want 4", len(summary.ToolExecutions))
if len(summary.ToolExecutions) != 6 {
t.Fatalf("tool executions = %d, want 6", len(summary.ToolExecutions))
}
for i, execution := range summary.ToolExecutions {
for i, execution := range summary.ToolExecutions[:2] {
if execution.Status != "completed" {
t.Fatalf("execution %d status = %q, want completed", i, execution.Status)
}
}
for i, execution := range summary.ToolExecutions[2:4] {
if execution.Status != "result_missing" {
t.Fatalf("unmatched call %d status = %q, want result_missing", i, execution.Status)
}
}
for i, execution := range summary.ToolExecutions[4:] {
if execution.Status != "completed" || execution.ToolCallID != "" {
t.Fatalf("idless result %d = %#v, want separate completed result without toolCallId", i, execution)
}
}
}
func TestProcessDetailsSummaryPairsRepeatedToolCallIDsFIFO(t *testing.T) {
+2 -2
View File
@@ -10,7 +10,7 @@ import (
"github.com/google/uuid"
)
var factKeyPattern = regexp.MustCompile(`^[a-z0-9][a-z0-9._/-]*$`)
var factKeyPattern = regexp.MustCompile(`^[a-zA-Z0-9][a-zA-Z0-9._/-]*$`)
// ValidateFactKey 校验事实 key(项目内唯一标识)。
func ValidateFactKey(key string) error {
@@ -22,7 +22,7 @@ func ValidateFactKey(key string) error {
return fmt.Errorf("fact_key 过长(最多 128 字符)")
}
if !factKeyPattern.MatchString(key) {
return fmt.Errorf("fact_key 格式无效,仅允许小写字母、数字及 . _ / -,且须以小写字母或数字开头")
return fmt.Errorf("fact_key 格式无效,仅允许字母、数字及 . _ / -,且须以字母或数字开头(支持驼峰命名)")
}
return nil
}
+39 -20
View File
@@ -333,17 +333,24 @@ type ChatReasoningRequest struct {
Effort string `json:"effort,omitempty"`
}
// ChatFinalizationRequest is a caller-provided delivery policy. The server does
// not infer execution intent from natural-language user text.
type ChatFinalizationRequest struct {
RequireExecutionEvidence *bool `json:"requireExecutionEvidence,omitempty"`
}
// ChatRequest 聊天请求
type ChatRequest struct {
Message string `json:"message" binding:"required"`
ConversationID string `json:"conversationId,omitempty"`
ProjectID string `json:"projectId,omitempty"` // 新对话绑定的项目(可选;未指定时可用 config.project.default_project_id
Role string `json:"role,omitempty"` // 角色名称
Attachments []ChatAttachment `json:"attachments,omitempty"`
WebShellConnectionID string `json:"webshellConnectionId,omitempty"` // WebShell 管理 - AI 助手:当前选中的连接 ID,仅使用 webshell_* 工具
AIChannelID string `json:"aiChannelId,omitempty"` // 会话级 AI 通道;空则使用 ai.default_channel
Hitl *HITLRequest `json:"hitl,omitempty"`
Reasoning *ChatReasoningRequest `json:"reasoning,omitempty"`
Message string `json:"message" binding:"required"`
ConversationID string `json:"conversationId,omitempty"`
ProjectID string `json:"projectId,omitempty"` // 新对话绑定的项目(可选;未指定时可用 config.project.default_project_id
Role string `json:"role,omitempty"` // 角色名称
Attachments []ChatAttachment `json:"attachments,omitempty"`
WebShellConnectionID string `json:"webshellConnectionId,omitempty"` // WebShell 管理 - AI 助手:当前选中的连接 ID,仅使用 webshell_* 工具
AIChannelID string `json:"aiChannelId,omitempty"` // 会话级 AI 通道;空则使用 ai.default_channel
Hitl *HITLRequest `json:"hitl,omitempty"`
Reasoning *ChatReasoningRequest `json:"reasoning,omitempty"`
Finalization ChatFinalizationRequest `json:"finalization,omitempty"`
// Orchestration 仅对 /api/multi-agent、/api/multi-agent/streamdeep | plan_execute | supervisor;空则等同 deep。机器人/批量等无请求体时由服务端默认 deep。/api/eino-agent* 不使用此字段。
Orchestration string `json:"orchestration,omitempty"`
}
@@ -668,10 +675,18 @@ func (h *AgentHandler) mergeAssistantMessagePartialOnCancel(messageID, partial s
// ChatResponse 聊天响应
type ChatResponse struct {
Response string `json:"response"`
MCPExecutionIDs []string `json:"mcpExecutionIds,omitempty"` // 本次对话中执行的MCP调用ID列表
ConversationID string `json:"conversationId"` // 对话ID
Time time.Time `json:"time"`
Response string `json:"response"`
MCPExecutionIDs []string `json:"mcpExecutionIds,omitempty"` // 本次对话中执行的MCP调用ID列表
ConversationID string `json:"conversationId"` // 对话ID
Time time.Time `json:"time"`
Finalizable bool `json:"finalizable"`
Finalized bool `json:"finalized"`
Status string `json:"status,omitempty"`
CompletionReason string `json:"completionReason,omitempty"`
EvidenceVerified bool `json:"evidenceVerified"`
EvidenceRefs []string `json:"evidenceRefs,omitempty"`
PendingExecutionIDs []string `json:"pendingExecutionIds,omitempty"`
MissingChecks []string `json:"missingChecks,omitempty"`
}
func (h *AgentHandler) finalizeRobotAgentError(ctx context.Context, assistantMessageID, conversationID string, resultMA *multiagent.RunResult, errMA error) (string, string, error) {
@@ -687,19 +702,20 @@ func (h *AgentHandler) finalizeRobotAgentError(ctx context.Context, assistantMes
}
func (h *AgentHandler) finalizeRobotAgentSuccess(assistantMessageID, conversationID string, resultMA *multiagent.RunResult) (string, string, error) {
if assistantMessageID != "" {
if errU := h.db.UpdateAssistantMessageFinalize(assistantMessageID, resultMA.Response, resultMA.MCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(resultMA.LastAgentTraceInput)); errU != nil {
h.logger.Warn("机器人:更新助手消息失败", zap.Error(errU))
}
} else {
if _, err := h.db.AddMessage(conversationID, "assistant", resultMA.Response, resultMA.MCPExecutionIDs); err != nil {
decision := h.finalizeAgentRunForDeliveryWithPolicy(conversationID, assistantMessageID, "robot", resultMA, resultMA.MCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(resultMA.LastAgentTraceInput), true)
responseText := decision.FinalText
if !decision.Finalizable {
responseText = finalizationBlockedMessage(decision)
}
if assistantMessageID == "" {
if _, err := h.db.AddMessage(conversationID, "assistant", responseText, resultMA.MCPExecutionIDs); err != nil {
h.logger.Warn("机器人:保存助手消息失败", zap.Error(err))
}
}
if resultMA.LastAgentTraceInput != "" || resultMA.LastAgentTraceOutput != "" {
_ = h.db.SaveAgentTrace(conversationID, resultMA.LastAgentTraceInput, resultMA.LastAgentTraceOutput)
}
return resultMA.Response, conversationID, nil
return responseText, conversationID, nil
}
func (h *AgentHandler) runRobotEinoSingleWithRetry(
@@ -830,6 +846,9 @@ func (h *AgentHandler) ProcessMessageForRobot(ctx context.Context, platform stri
progressCallback := h.createProgressCallback(taskCtx, cancelWithCause, conversationID, assistantMessageID, nil)
robotMode := config.NormalizeAgentMode(agentMode)
if err := h.db.SetConversationAgentMode(conversationID, robotMode); err != nil {
h.logger.Warn("机器人:更新对话模式失败", zap.String("conversationId", conversationID), zap.String("agentMode", robotMode), zap.Error(err))
}
switch robotMode {
case "eino_single":
return h.runRobotEinoSingleWithRetry(taskCtx, conversationID, finalMessage, agentHistoryMessages, roleTools, progressCallback, assistantMessageID, &taskStatus)
+37 -9
View File
@@ -238,6 +238,11 @@ func (h *AgentHandler) executeOneBatchSubTask(queueID string, queue *BatchTaskQu
useBatchMulti = true
batchOrch = "deep"
}
if useBatchMulti {
_ = h.db.SetConversationAgentMode(conversationID, batchOrch)
} else {
_ = h.db.SetConversationAgentMode(conversationID, "eino_single")
}
var resultMA *multiagent.RunResult
var runErr error
@@ -268,19 +273,38 @@ func (h *AgentHandler) executeOneBatchSubTask(queueID string, queue *BatchTaskQu
h.logger.Info("批量任务执行成功", zap.String("queueId", queueID), zap.String("taskId", task.ID), zap.String("conversationId", conversationID))
resText := resultMA.Response
mcpIDs := resultMA.MCPExecutionIDs
lastIn := resultMA.LastAgentTraceInput
lastOut := resultMA.LastAgentTraceOutput
reasoningContent := multiagent.AggregatedReasoningFromTraceJSON(lastIn)
agentMode := "batch_eino_single"
if useBatchMulti {
agentMode = "batch_eino_" + batchOrch
}
decision := h.finalizeAgentRunForDeliveryWithPolicy(conversationID, assistantMessageID, agentMode, resultMA, mcpIDs, reasoningContent, true)
resText := decision.FinalText
if !decision.Finalizable {
resText = finalizationBlockedMessage(decision)
finishStatus = decision.Status
sendEvent("finalization_check", resText, decision)
}
sendEvent("response", resText, finalizationResponsePayload(decision, map[string]interface{}{
"conversationId": conversationID,
"messageId": assistantMessageID,
"agentMode": agentMode,
"mcpExecutionIds": mcpIDs,
"batchQueueId": queueID,
"batchTaskId": task.ID,
"batchTaskStatus": map[bool]string{true: string(BatchTaskStatusCompleted), false: string(BatchTaskStatusFailed)}[decision.Finalizable],
"candidatePreview": safeTruncateString(resultMA.Response, 500),
}))
if assistantMessageID != "" {
if updateErr := h.db.UpdateAssistantMessageFinalize(assistantMessageID, resText, mcpIDs, multiagent.AggregatedReasoningFromTraceJSON(lastIn)); updateErr != nil {
h.logger.Warn("更新助手消息失败", zap.String("queueId", queueID), zap.String("taskId", task.ID), zap.Error(updateErr))
if _, err = h.db.AddMessage(conversationID, "assistant", resText, mcpIDs); err != nil {
h.logger.Error("保存助手消息失败", zap.String("queueId", queueID), zap.String("taskId", task.ID), zap.String("conversationId", conversationID), zap.Error(err))
}
}
} else if _, err = h.db.AddMessage(conversationID, "assistant", resText, mcpIDs); err != nil {
if assistantMessageID == "" {
_, err = h.db.AddMessage(conversationID, "assistant", resText, mcpIDs)
} else if !decision.Finalizable {
err = nil
}
if err != nil {
h.logger.Error("保存助手消息失败", zap.String("queueId", queueID), zap.String("taskId", task.ID), zap.String("conversationId", conversationID), zap.Error(err))
}
@@ -290,6 +314,10 @@ func (h *AgentHandler) executeOneBatchSubTask(queueID string, queue *BatchTaskQu
}
}
if !decision.Finalizable {
h.batchTaskManager.UpdateTaskStatusWithConversationID(queueID, task.ID, BatchTaskStatusFailed, resText, finalizationCheckMessage(decision), conversationID)
return
}
h.batchTaskManager.UpdateTaskStatusWithConversationID(queueID, task.ID, BatchTaskStatusCompleted, resText, "", conversationID)
}
@@ -68,15 +68,15 @@ func (h *AgentHandler) tryContinueOnEinoEmptyResponse(
case <-time.After(backoff):
}
inject := multiagent.FormatEmptyResponseContinueUserMessage()
h.applyEinoTraceResumeSegment(conversationID, result, curHistory, curFinalMessage, inject)
h.applyEinoTraceResumeSegment(conversationID, result, curHistory, curFinalMessage, "")
if progressCallback != nil {
progressCallback("eino_empty_response_continue", "已恢复上下文,正在续跑…", map[string]interface{}{
"conversationId": conversationID,
"source": "eino",
"attempt": *attempt,
"maxAttempts": maxAttempts,
"contextSource": "empty_response_continue",
"conversationId": conversationID,
"source": "eino",
"attempt": *attempt,
"maxAttempts": maxAttempts,
"contextSource": "empty_response_continue",
"contextInjection": false,
})
}
return true
+57 -18
View File
@@ -10,6 +10,7 @@ import (
"sync"
"time"
"cyberstrike-ai/internal/agentfinalizer"
"cyberstrike-ai/internal/mcp"
"cyberstrike-ai/internal/multiagent"
@@ -189,6 +190,8 @@ func (h *AgentHandler) EinoSingleAgentLoopStream(c *gin.Context) {
// 同一请求内分段续跑时,主代理 iteration 事件按偏移累计,避免 UI 出现「第3轮 → 第1轮」回跳。
var mainIterationOffset int
var emptyResponseContinueAttempt int
var finalizationAutoContinueAttempt int
var decision agentfinalizer.Decision
for {
segmentMainIterationMax := 0
@@ -258,6 +261,13 @@ func (h *AgentHandler) EinoSingleAgentLoopStream(c *gin.Context) {
baseCtx, cancelWithCause, taskCtx, timeoutCancel = h.rebindEinoRunningTask(taskCtx, conversationID, timeoutCancel)
continue
}
decision = h.decideAgentRunForDeliveryWithPolicy(conversationID, assistantMessageID, "eino_single", result, cumulativeMCPExecutionIDs, requestRequiresExecutionEvidence(&req))
if h.tryAutoContinueAfterFinalization(taskCtx, conversationID, result, decision, &finalizationAutoContinueAttempt, &curHistory, &curFinalMessage, progressCallback) {
mainIterationOffset += segmentMainIterationMax
timeoutCancel()
baseCtx, cancelWithCause, taskCtx, timeoutCancel = h.rebindEinoRunningTask(taskCtx, conversationID, timeoutCancel)
continue
}
timeoutCancel()
break
}
@@ -358,9 +368,10 @@ func (h *AgentHandler) EinoSingleAgentLoopStream(c *gin.Context) {
timeoutCancel()
if assistantMessageID != "" {
_ = h.db.UpdateAssistantMessageFinalize(assistantMessageID, result.Response, cumulativeMCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput))
if decision.CompletionReason == "" {
decision = h.decideAgentRunForDeliveryWithPolicy(conversationID, assistantMessageID, "eino_single", result, cumulativeMCPExecutionIDs, requestRequiresExecutionEvidence(&req))
}
h.persistFinalizationDecision(conversationID, assistantMessageID, "eino_single", cumulativeMCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput), decision)
if result.LastAgentTraceInput != "" || result.LastAgentTraceOutput != "" {
if err := h.db.SaveAgentTrace(conversationID, result.LastAgentTraceInput, result.LastAgentTraceOutput); err != nil {
@@ -368,12 +379,19 @@ func (h *AgentHandler) EinoSingleAgentLoopStream(c *gin.Context) {
}
}
sendEvent("response", result.Response, map[string]interface{}{
responseText := decision.FinalText
if !decision.Finalizable {
responseText = finalizationBlockedMessage(decision)
sendEvent("finalization_check", responseText, decision)
taskStatus = decision.Status
h.tasks.UpdateTaskStatus(conversationID, taskStatus)
}
sendEvent("response", responseText, finalizationResponsePayload(decision, map[string]interface{}{
"mcpExecutionIds": cumulativeMCPExecutionIDs,
"conversationId": conversationID,
"messageId": assistantMessageID,
"agentMode": "eino_single",
})
}))
sendEvent("done", "", map[string]interface{}{"conversationId": conversationID})
}
@@ -429,6 +447,9 @@ func (h *AgentHandler) EinoSingleAgentLoop(c *gin.Context) {
curMsg := prep.FinalMessage
var result *multiagent.RunResult
var runErr error
var emptyResponseContinueAttempt int
var finalizationAutoContinueAttempt int
var decision agentfinalizer.Decision
for {
result, runErr = multiagent.RunEinoSingleChatModelAgent(
taskCtx,
@@ -446,28 +467,46 @@ func (h *AgentHandler) EinoSingleAgentLoop(c *gin.Context) {
chatReasoningToClientIntent(req.Reasoning),
h.agentSessionContextBlock(prep.ConversationID),
)
if runErr == nil {
break
if runErr != nil {
if shouldPersistEinoAgentTraceAfterRunError(baseCtx) {
h.persistEinoAgentTraceForResume(prep.ConversationID, result)
}
c.JSON(http.StatusInternalServerError, gin.H{"error": runErr.Error()})
return
}
if shouldPersistEinoAgentTraceAfterRunError(baseCtx) {
h.persistEinoAgentTraceForResume(prep.ConversationID, result)
mw := &h.config.MultiAgent.EinoMiddleware
if h.tryContinueOnEinoEmptyResponse(taskCtx, mw, prep.ConversationID, result, &emptyResponseContinueAttempt, &curHist, &curMsg, progressCallback) {
continue
}
c.JSON(http.StatusInternalServerError, gin.H{"error": runErr.Error()})
return
decision = h.decideAgentRunForDeliveryWithPolicy(prep.ConversationID, prep.AssistantMessageID, "eino_single", result, result.MCPExecutionIDs, requestRequiresExecutionEvidence(&req))
if h.tryAutoContinueAfterFinalization(taskCtx, prep.ConversationID, result, decision, &finalizationAutoContinueAttempt, &curHist, &curMsg, progressCallback) {
continue
}
break
}
if prep.AssistantMessageID != "" {
_ = h.db.UpdateAssistantMessageFinalize(prep.AssistantMessageID, result.Response, result.MCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput))
}
h.persistFinalizationDecision(prep.ConversationID, prep.AssistantMessageID, "eino_single", result.MCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput), decision)
if result.LastAgentTraceInput != "" || result.LastAgentTraceOutput != "" {
_ = h.db.SaveAgentTrace(prep.ConversationID, result.LastAgentTraceInput, result.LastAgentTraceOutput)
}
responseText := decision.FinalText
if !decision.Finalizable {
responseText = finalizationBlockedMessage(decision)
}
c.JSON(http.StatusOK, gin.H{
"response": result.Response,
"conversationId": prep.ConversationID,
"mcpExecutionIds": result.MCPExecutionIDs,
"assistantMessageId": prep.AssistantMessageID,
"agentMode": "eino_single",
"response": responseText,
"conversationId": prep.ConversationID,
"mcpExecutionIds": result.MCPExecutionIDs,
"assistantMessageId": prep.AssistantMessageID,
"agentMode": "eino_single",
"finalized": decision.Finalized,
"finalizable": decision.Finalizable,
"status": decision.Status,
"completionReason": decision.CompletionReason,
"evidenceVerified": decision.EvidenceVerified,
"evidenceRefs": decision.EvidenceRefs,
"pendingExecutionIds": decision.PendingExecutionIDs,
"missingChecks": decision.MissingChecks,
})
}
@@ -0,0 +1,77 @@
package handler
import (
"context"
"time"
"cyberstrike-ai/internal/agent"
"cyberstrike-ai/internal/agentfinalizer"
"cyberstrike-ai/internal/multiagent"
"go.uber.org/zap"
)
const finalizationAutoContinueMaxAttempts = 2
func shouldAutoContinueAfterFinalization(d agentfinalizer.Decision, attempt int) bool {
if d.Finalizable || d.Finalized {
return false
}
if attempt >= finalizationAutoContinueMaxAttempts {
return false
}
return d.CompletionReason == agentfinalizer.ReasonMissingEvidence
}
func (h *AgentHandler) tryAutoContinueAfterFinalization(
taskCtx context.Context,
conversationID string,
result *multiagent.RunResult,
decision agentfinalizer.Decision,
attempt *int,
curHistory *[]agent.ChatMessage,
curFinalMessage *string,
progressCallback func(eventType, message string, data interface{}),
) bool {
if !shouldAutoContinueAfterFinalization(decision, *attempt) || result == nil || !multiagent.HasEinoResumeTrace(result) {
return false
}
*attempt++
h.persistEinoAgentTraceForResume(conversationID, result)
if hist, err := h.loadHistoryFromAgentTrace(conversationID); err == nil && len(hist) > 0 {
*curHistory = hist
} else if h.logger != nil {
h.logger.Warn("finalization auto-continue could not restore trace",
zap.String("conversationId", conversationID),
zap.Error(err))
return false
}
// Agent 无感续跑:不追加新的 user/system 文案,只使用上一段模型可见轨迹继续 Runner。
*curFinalMessage = ""
if progressCallback != nil {
progressCallback("finalization_auto_continue", "最终回复检查尚未收敛,正在基于已有轨迹继续执行…", map[string]interface{}{
"conversationId": conversationID,
"source": "finalizer",
"attempt": *attempt,
"maxAttempts": finalizationAutoContinueMaxAttempts,
"status": decision.Status,
"completionReason": decision.CompletionReason,
"missingChecks": decision.MissingChecks,
"pendingExecutionIds": decision.PendingExecutionIDs,
"contextInjection": false,
})
}
select {
case <-taskCtx.Done():
return false
case <-time.After(finalizationAutoContinueBackoff(*attempt)):
return true
}
}
func finalizationAutoContinueBackoff(attempt int) time.Duration {
if attempt <= 1 {
return 500 * time.Millisecond
}
return time.Duration(attempt) * time.Second
}
@@ -0,0 +1,59 @@
package handler
import (
"testing"
"cyberstrike-ai/internal/agentfinalizer"
)
func TestShouldAutoContinueAfterFinalization(t *testing.T) {
missingEvidence := agentfinalizer.Decision{
Status: agentfinalizer.StatusBlocked,
CompletionReason: agentfinalizer.ReasonMissingEvidence,
}
if !shouldAutoContinueAfterFinalization(missingEvidence, 0) {
t.Fatal("missing execution evidence should trigger auto-continue")
}
if shouldAutoContinueAfterFinalization(missingEvidence, finalizationAutoContinueMaxAttempts) {
t.Fatal("auto-continue should stop at max attempts")
}
finalized := agentfinalizer.Decision{
Status: agentfinalizer.StatusCompleted,
CompletionReason: agentfinalizer.ReasonVerified,
Finalizable: true,
Finalized: true,
}
if shouldAutoContinueAfterFinalization(finalized, 0) {
t.Fatal("finalized decision should not auto-continue")
}
awaitingHITL := agentfinalizer.Decision{
Status: agentfinalizer.StatusAwaitingHITL,
CompletionReason: agentfinalizer.ReasonAwaitingHITL,
}
if shouldAutoContinueAfterFinalization(awaitingHITL, 0) {
t.Fatal("awaiting HITL should not auto-continue without approval")
}
}
func TestRequestRequiresExecutionEvidenceUsesExplicitPolicyOnly(t *testing.T) {
if requestRequiresExecutionEvidence(nil) {
t.Fatal("nil request should not require execution evidence")
}
if requestRequiresExecutionEvidence(&ChatRequest{}) {
t.Fatal("missing finalization policy should not require execution evidence")
}
require := true
if !requestRequiresExecutionEvidence(&ChatRequest{
Finalization: ChatFinalizationRequest{RequireExecutionEvidence: &require},
}) {
t.Fatal("explicit true policy should require execution evidence")
}
require = false
if requestRequiresExecutionEvidence(&ChatRequest{
Finalization: ChatFinalizationRequest{RequireExecutionEvidence: &require},
}) {
t.Fatal("explicit false policy should not require execution evidence")
}
}
+171
View File
@@ -0,0 +1,171 @@
package handler
import (
"fmt"
"strings"
"time"
"cyberstrike-ai/internal/agentfinalizer"
"cyberstrike-ai/internal/multiagent"
"go.uber.org/zap"
)
func (h *AgentHandler) finalizeAgentRunForDelivery(
conversationID string,
assistantMessageID string,
agentMode string,
result *multiagent.RunResult,
mcpExecutionIDs []string,
reasoningContent string,
) agentfinalizer.Decision {
return h.finalizeAgentRunForDeliveryWithPolicy(conversationID, assistantMessageID, agentMode, result, mcpExecutionIDs, reasoningContent, false)
}
func (h *AgentHandler) finalizeAgentRunForDeliveryWithPolicy(
conversationID string,
assistantMessageID string,
agentMode string,
result *multiagent.RunResult,
mcpExecutionIDs []string,
reasoningContent string,
requireExecutionEvidence bool,
) agentfinalizer.Decision {
decision := agentfinalizer.FromRunResult(h.db, result, agentfinalizer.Input{
ConversationID: conversationID,
AssistantMessageID: assistantMessageID,
AgentMode: agentMode,
MCPExecutionIDs: mcpExecutionIDs,
RequireExecutionEvidence: requireExecutionEvidence,
})
h.persistFinalizationDecision(conversationID, assistantMessageID, agentMode, mcpExecutionIDs, reasoningContent, decision)
return decision
}
func (h *AgentHandler) decideAgentRunForDeliveryWithPolicy(
conversationID string,
assistantMessageID string,
agentMode string,
result *multiagent.RunResult,
mcpExecutionIDs []string,
requireExecutionEvidence bool,
) agentfinalizer.Decision {
return agentfinalizer.FromRunResult(h.db, result, agentfinalizer.Input{
ConversationID: conversationID,
AssistantMessageID: assistantMessageID,
AgentMode: agentMode,
MCPExecutionIDs: mcpExecutionIDs,
RequireExecutionEvidence: requireExecutionEvidence,
})
}
func (h *AgentHandler) decideAgentRunForDelivery(
conversationID string,
assistantMessageID string,
agentMode string,
result *multiagent.RunResult,
mcpExecutionIDs []string,
) agentfinalizer.Decision {
return agentfinalizer.FromRunResult(h.db, result, agentfinalizer.Input{
ConversationID: conversationID,
AssistantMessageID: assistantMessageID,
AgentMode: agentMode,
MCPExecutionIDs: mcpExecutionIDs,
RequireExecutionEvidence: false,
})
}
func (h *AgentHandler) persistFinalizationDecision(
conversationID string,
assistantMessageID string,
agentMode string,
mcpExecutionIDs []string,
reasoningContent string,
decision agentfinalizer.Decision,
) {
if assistantMessageID == "" || h.db == nil {
return
}
_ = h.db.AddProcessDetail(assistantMessageID, conversationID, "finalization_check", finalizationCheckMessage(decision), decision)
if decision.Finalizable {
if err := h.db.UpdateAssistantMessageFinalize(assistantMessageID, decision.FinalText, mcpExecutionIDs, reasoningContent); err != nil && h.logger != nil {
h.logger.Warn("更新最终助手消息失败", zap.Error(err), zap.String("conversationId", conversationID), zap.String("agentMode", agentMode))
}
return
}
_, _ = h.db.Exec("UPDATE messages SET content = ?, updated_at = ? WHERE id = ?", finalizationBlockedMessage(decision), time.Now(), assistantMessageID)
}
func (h *AgentHandler) finalizeCandidateForDelivery(
conversationID string,
assistantMessageID string,
agentMode string,
response string,
mcpExecutionIDs []string,
awaitingHITL bool,
reasoningContent string,
) agentfinalizer.Decision {
return h.finalizeCandidateForDeliveryWithPolicy(conversationID, assistantMessageID, agentMode, response, mcpExecutionIDs, awaitingHITL, reasoningContent, false)
}
func (h *AgentHandler) finalizeCandidateForDeliveryWithPolicy(
conversationID string,
assistantMessageID string,
agentMode string,
response string,
mcpExecutionIDs []string,
awaitingHITL bool,
reasoningContent string,
requireExecutionEvidence bool,
) agentfinalizer.Decision {
decision := agentfinalizer.Decide(h.db, agentfinalizer.Input{
Response: response,
ConversationID: conversationID,
AssistantMessageID: assistantMessageID,
AgentMode: agentMode,
MCPExecutionIDs: mcpExecutionIDs,
AwaitingHITL: awaitingHITL,
RequireExecutionEvidence: requireExecutionEvidence,
})
if assistantMessageID == "" || h.db == nil {
return decision
}
_ = h.db.AddProcessDetail(assistantMessageID, conversationID, "finalization_check", finalizationCheckMessage(decision), decision)
if decision.Finalizable {
if err := h.db.UpdateAssistantMessageFinalize(assistantMessageID, decision.FinalText, mcpExecutionIDs, reasoningContent); err != nil && h.logger != nil {
h.logger.Warn("更新最终助手消息失败", zap.Error(err), zap.String("conversationId", conversationID), zap.String("agentMode", agentMode))
}
return decision
}
_, _ = h.db.Exec("UPDATE messages SET content = ?, updated_at = ? WHERE id = ?", finalizationBlockedMessage(decision), time.Now(), assistantMessageID)
return decision
}
func finalizationCheckMessage(d agentfinalizer.Decision) string {
if d.Finalizable {
return "最终回复检查通过。"
}
return finalizationBlockedMessage(d)
}
func finalizationBlockedMessage(d agentfinalizer.Decision) string {
parts := []string{"任务尚未达到最终回复条件,暂不生成成功结论。"}
if d.CompletionReason != "" {
parts = append(parts, "原因: "+d.CompletionReason)
}
if len(d.PendingExecutionIDs) > 0 {
parts = append(parts, fmt.Sprintf("仍有 %d 个工具执行未结束: %s", len(d.PendingExecutionIDs), strings.Join(d.PendingExecutionIDs, ", ")))
}
if len(d.MissingChecks) > 0 {
parts = append(parts, "缺失检查: "+strings.Join(d.MissingChecks, "; "))
}
return strings.Join(parts, "\n")
}
func finalizationResponsePayload(d agentfinalizer.Decision, extra map[string]interface{}) map[string]interface{} {
return agentfinalizer.ResponsePayload(d, extra)
}
func requestRequiresExecutionEvidence(req *ChatRequest) bool {
return req != nil && req.Finalization.RequireExecutionEvidence != nil && *req.Finalization.RequireExecutionEvidence
}
+70 -25
View File
@@ -10,6 +10,7 @@ import (
"sync"
"time"
"cyberstrike-ai/internal/agentfinalizer"
"cyberstrike-ai/internal/config"
"cyberstrike-ai/internal/mcp"
"cyberstrike-ai/internal/multiagent"
@@ -197,6 +198,13 @@ func (h *AgentHandler) MultiAgentLoopStream(c *gin.Context) {
// 同一请求内分段续跑时,主代理 iteration 事件按偏移累计,避免 UI 出现「第3轮 → 第1轮」回跳。
var mainIterationOffset int
var emptyResponseContinueAttempt int
var finalizationAutoContinueAttempt int
effectiveOrch := config.NormalizeMultiAgentOrchestration(h.config.MultiAgent.Orchestration)
if o := strings.TrimSpace(req.Orchestration); o != "" {
effectiveOrch = config.NormalizeMultiAgentOrchestration(o)
}
agentMode := "eino_" + effectiveOrch
var decision agentfinalizer.Decision
for {
segmentMainIterationMax := 0
@@ -267,6 +275,13 @@ func (h *AgentHandler) MultiAgentLoopStream(c *gin.Context) {
baseCtx, cancelWithCause, taskCtx, timeoutCancel = h.rebindEinoRunningTask(taskCtx, conversationID, timeoutCancel)
continue
}
decision = h.decideAgentRunForDeliveryWithPolicy(conversationID, assistantMessageID, agentMode, result, cumulativeMCPExecutionIDs, requestRequiresExecutionEvidence(&req))
if h.tryAutoContinueAfterFinalization(taskCtx, conversationID, result, decision, &finalizationAutoContinueAttempt, &curHistory, &curFinalMessage, progressCallback) {
mainIterationOffset += segmentMainIterationMax
timeoutCancel()
baseCtx, cancelWithCause, taskCtx, timeoutCancel = h.rebindEinoRunningTask(taskCtx, conversationID, timeoutCancel)
continue
}
timeoutCancel()
break
}
@@ -367,9 +382,10 @@ func (h *AgentHandler) MultiAgentLoopStream(c *gin.Context) {
timeoutCancel()
if assistantMessageID != "" {
_ = h.db.UpdateAssistantMessageFinalize(assistantMessageID, result.Response, cumulativeMCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput))
if decision.CompletionReason == "" {
decision = h.decideAgentRunForDeliveryWithPolicy(conversationID, assistantMessageID, agentMode, result, cumulativeMCPExecutionIDs, requestRequiresExecutionEvidence(&req))
}
h.persistFinalizationDecision(conversationID, assistantMessageID, agentMode, cumulativeMCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput), decision)
if result.LastAgentTraceInput != "" || result.LastAgentTraceOutput != "" {
if err := h.db.SaveAgentTrace(conversationID, result.LastAgentTraceInput, result.LastAgentTraceOutput); err != nil {
@@ -377,16 +393,19 @@ func (h *AgentHandler) MultiAgentLoopStream(c *gin.Context) {
}
}
effectiveOrch := config.NormalizeMultiAgentOrchestration(h.config.MultiAgent.Orchestration)
if o := strings.TrimSpace(req.Orchestration); o != "" {
effectiveOrch = config.NormalizeMultiAgentOrchestration(o)
responseText := decision.FinalText
if !decision.Finalizable {
responseText = finalizationBlockedMessage(decision)
sendEvent("finalization_check", responseText, decision)
taskStatus = decision.Status
h.tasks.UpdateTaskStatus(conversationID, taskStatus)
}
sendEvent("response", result.Response, map[string]interface{}{
sendEvent("response", responseText, finalizationResponsePayload(decision, map[string]interface{}{
"mcpExecutionIds": cumulativeMCPExecutionIDs,
"conversationId": conversationID,
"messageId": assistantMessageID,
"agentMode": "eino_" + effectiveOrch,
})
"agentMode": agentMode,
}))
sendEvent("done", "", map[string]interface{}{"conversationId": conversationID})
}
@@ -437,6 +456,14 @@ func (h *AgentHandler) MultiAgentLoop(c *gin.Context) {
curMsg := prep.FinalMessage
var result *multiagent.RunResult
var runErr error
var emptyResponseContinueAttempt int
var finalizationAutoContinueAttempt int
effectiveOrch := config.NormalizeMultiAgentOrchestration(h.config.MultiAgent.Orchestration)
if o := strings.TrimSpace(req.Orchestration); o != "" {
effectiveOrch = config.NormalizeMultiAgentOrchestration(o)
}
agentMode := "eino_" + effectiveOrch
var decision agentfinalizer.Decision
for {
result, runErr = multiagent.RunDeepAgent(
taskCtx,
@@ -456,24 +483,30 @@ func (h *AgentHandler) MultiAgentLoop(c *gin.Context) {
chatReasoningToClientIntent(req.Reasoning),
h.agentSessionContextBlock(prep.ConversationID),
)
if runErr == nil {
break
if runErr != nil {
if shouldPersistEinoAgentTraceAfterRunError(baseCtx) {
h.persistEinoAgentTraceForResume(prep.ConversationID, result)
}
h.logger.Error("Eino DeepAgent 执行失败", zap.Error(runErr))
errMsg := "执行失败: " + runErr.Error()
if prep.AssistantMessageID != "" {
_, _ = h.db.Exec("UPDATE messages SET content = ?, updated_at = ? WHERE id = ?", errMsg, time.Now(), prep.AssistantMessageID)
}
c.JSON(http.StatusInternalServerError, gin.H{"error": errMsg})
return
}
if shouldPersistEinoAgentTraceAfterRunError(baseCtx) {
h.persistEinoAgentTraceForResume(prep.ConversationID, result)
mw := &h.config.MultiAgent.EinoMiddleware
if h.tryContinueOnEinoEmptyResponse(taskCtx, mw, prep.ConversationID, result, &emptyResponseContinueAttempt, &curHist, &curMsg, progressCallback) {
continue
}
h.logger.Error("Eino DeepAgent 执行失败", zap.Error(runErr))
errMsg := "执行失败: " + runErr.Error()
if prep.AssistantMessageID != "" {
_, _ = h.db.Exec("UPDATE messages SET content = ?, updated_at = ? WHERE id = ?", errMsg, time.Now(), prep.AssistantMessageID)
decision = h.decideAgentRunForDeliveryWithPolicy(prep.ConversationID, prep.AssistantMessageID, agentMode, result, result.MCPExecutionIDs, requestRequiresExecutionEvidence(&req))
if h.tryAutoContinueAfterFinalization(taskCtx, prep.ConversationID, result, decision, &finalizationAutoContinueAttempt, &curHist, &curMsg, progressCallback) {
continue
}
c.JSON(http.StatusInternalServerError, gin.H{"error": errMsg})
return
break
}
if prep.AssistantMessageID != "" {
_ = h.db.UpdateAssistantMessageFinalize(prep.AssistantMessageID, result.Response, result.MCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput))
}
h.persistFinalizationDecision(prep.ConversationID, prep.AssistantMessageID, agentMode, result.MCPExecutionIDs, multiagent.AggregatedReasoningFromTraceJSON(result.LastAgentTraceInput), decision)
if result.LastAgentTraceInput != "" || result.LastAgentTraceOutput != "" {
if err := h.db.SaveAgentTrace(prep.ConversationID, result.LastAgentTraceInput, result.LastAgentTraceOutput); err != nil {
@@ -481,11 +514,23 @@ func (h *AgentHandler) MultiAgentLoop(c *gin.Context) {
}
}
responseText := decision.FinalText
if !decision.Finalizable {
responseText = finalizationBlockedMessage(decision)
}
c.JSON(http.StatusOK, ChatResponse{
Response: result.Response,
MCPExecutionIDs: result.MCPExecutionIDs,
ConversationID: prep.ConversationID,
Time: time.Now(),
Response: responseText,
MCPExecutionIDs: result.MCPExecutionIDs,
ConversationID: prep.ConversationID,
Time: time.Now(),
Finalizable: decision.Finalizable,
Finalized: decision.Finalized,
Status: decision.Status,
CompletionReason: decision.CompletionReason,
EvidenceVerified: decision.EvidenceVerified,
EvidenceRefs: decision.EvidenceRefs,
PendingExecutionIDs: decision.PendingExecutionIDs,
MissingChecks: decision.MissingChecks,
})
}
+12
View File
@@ -6,6 +6,7 @@ import (
"cyberstrike-ai/internal/agent"
"cyberstrike-ai/internal/audit"
"cyberstrike-ai/internal/config"
"cyberstrike-ai/internal/database"
"cyberstrike-ai/internal/mcp/builtin"
"cyberstrike-ai/internal/security"
@@ -25,6 +26,13 @@ type multiAgentPrepared struct {
UserMessageID string
}
func chatRequestAgentMode(req *ChatRequest, source string) string {
if strings.HasPrefix(strings.TrimSpace(source), "multi_agent") {
return config.NormalizeMultiAgentOrchestration(req.Orchestration)
}
return "eino_single"
}
func (h *AgentHandler) prepareMultiAgentSession(req *ChatRequest, c *gin.Context, source string) (*multiAgentPrepared, error) {
if len(req.Attachments) > maxAttachments {
return nil, fmt.Errorf("附件最多 %d 个", maxAttachments)
@@ -57,6 +65,7 @@ func (h *AgentHandler) prepareMultiAgentSession(req *ChatRequest, c *gin.Context
meta := audit.ConversationCreateMetaFromGin(c, source)
meta.ProjectID = projectID
meta.RoleName = req.Role
meta.AgentMode = chatRequestAgentMode(req, source)
if webshellID != "" {
meta.Source = source + "_webshell"
meta.WebShellConnectionID = webshellID
@@ -84,6 +93,9 @@ func (h *AgentHandler) prepareMultiAgentSession(req *ChatRequest, c *gin.Context
if err := h.db.SetConversationRoleName(conversationID, req.Role); err != nil {
h.logger.Warn("更新对话角色失败", zap.String("conversationId", conversationID), zap.String("role", req.Role), zap.Error(err))
}
if err := h.db.SetConversationAgentMode(conversationID, chatRequestAgentMode(req, source)); err != nil {
h.logger.Warn("更新对话模式失败", zap.String("conversationId", conversationID), zap.String("source", source), zap.String("orchestration", req.Orchestration), zap.Error(err))
}
agentHistoryMessages, err := h.loadHistoryFromAgentTrace(conversationID)
if err != nil {
+97 -6
View File
@@ -35,6 +35,17 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
scheme = "https"
}
finalizationRequestSchema := map[string]interface{}{
"type": "object",
"description": "最终回复交付策略。后端不会从自然语言内容推断执行意图;执行入口应显式声明是否要求 completed 工具证据。",
"properties": map[string]interface{}{
"requireExecutionEvidence": map[string]interface{}{
"type": "boolean",
"description": "为 true 时,缺少 completed 工具执行记录会触发无注入续跑或最终阻断;普通聊天可省略或设为 false。",
},
},
}
spec := map[string]interface{}{
"openapi": "3.0.0",
"info": map[string]interface{}{
@@ -85,6 +96,70 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
},
"required": []string{"projectId"},
},
"AgentChatResponse": map[string]interface{}{
"type": "object",
"description": "Agent 非流式响应。response 只是交付文本;是否为成功最终回复必须以 finalized/finalizable/status 为准。",
"properties": map[string]interface{}{
"response": map[string]interface{}{
"type": "string",
"description": "交付给用户的文本。finalized=false 时为阻断/未完成说明,不是成功结论。",
},
"conversationId": map[string]interface{}{
"type": "string",
"description": "对话 ID",
},
"assistantMessageId": map[string]interface{}{
"type": "string",
"description": "助手消息 ID(部分接口返回)",
},
"mcpExecutionIds": map[string]interface{}{
"type": "array",
"description": "本轮关联的 MCP 工具执行 ID",
"items": map[string]interface{}{"type": "string"},
},
"agentMode": map[string]interface{}{
"type": "string",
"description": "agent 模式,例如 eino_single、eino_deep、workflow",
},
"finalized": map[string]interface{}{
"type": "boolean",
"description": "是否已经通过最终回复检查。只有 true 才能当成功最终回复。",
},
"finalizable": map[string]interface{}{
"type": "boolean",
"description": "候选输出是否可提升为最终回复。",
},
"status": map[string]interface{}{
"type": "string",
"description": "最终化状态",
"enum": []string{"completed", "in_progress", "blocked", "failed", "cancelled", "awaiting_hitl"},
},
"completionReason": map[string]interface{}{
"type": "string",
"description": "最终化或阻断原因,例如 verified、pending_tool_executions、missing_execution_evidence",
},
"evidenceVerified": map[string]interface{}{
"type": "boolean",
"description": "证据是否满足最终化要求",
},
"evidenceRefs": map[string]interface{}{
"type": "array",
"description": "证据引用,例如 mcp_execution:<id>",
"items": map[string]interface{}{"type": "string"},
},
"pendingExecutionIds": map[string]interface{}{
"type": "array",
"description": "仍处于 queued/running 的工具执行 ID",
"items": map[string]interface{}{"type": "string"},
},
"missingChecks": map[string]interface{}{
"type": "array",
"description": "未通过最终化检查的原因列表",
"items": map[string]interface{}{"type": "string"},
},
},
"required": []string{"response", "conversationId", "finalized", "finalizable", "status", "evidenceVerified"},
},
"Conversation": map[string]interface{}{
"type": "object",
"properties": map[string]interface{}{
@@ -1581,6 +1656,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"conversationId": map[string]interface{}{"type": "string"},
"role": map[string]interface{}{"type": "string"},
"webshellConnectionId": map[string]interface{}{"type": "string"},
"finalization": finalizationRequestSchema,
},
"required": []string{"message"},
},
@@ -1588,7 +1664,14 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
},
},
"responses": map[string]interface{}{
"200": map[string]interface{}{"description": "成功,响应格式同 /api/eino-agent"},
"200": map[string]interface{}{
"description": "成功。只有 finalized=true 表示成功最终回复;finalized=false 时 response 为未完成/阻断说明。",
"content": map[string]interface{}{
"application/json": map[string]interface{}{
"schema": map[string]interface{}{"$ref": "#/components/schemas/AgentChatResponse"},
},
},
},
"400": map[string]interface{}{"description": "参数错误"},
"401": map[string]interface{}{"description": "未授权"},
"500": map[string]interface{}{"description": "执行失败"},
@@ -1599,7 +1682,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"post": map[string]interface{}{
"tags": []string{"对话交互"},
"summary": "发送消息并获取 AI 回复(Eino ADK 单代理,SSE",
"description": "向 AI 发送消息并获取流式回复(SSE)。由 Eino **单代理** ADK 执行;事件类型与多代理流式一致(含 `tool_call` / `response_delta` / `thinking` 等)。**不依赖** `multi_agent.enabled`。",
"description": "向 AI 发送消息并获取流式回复(SSE)。由 Eino **单代理** ADK 执行;事件类型与多代理流式一致(含 `tool_call` / `response_delta` / `thinking` 等)。`response_start` / `response_delta` 仅为候选/过程输出;只有 `type: response` 且 `data.finalized=true` 才表示成功最终回复。缺 completed 执行证据时可能先发送 `finalization_auto_continue`,表示服务端基于已有 trace 无注入续跑。`data.finalized=false` 时 message 为未完成/阻断说明。**不依赖** `multi_agent.enabled`。",
"operationId": "sendMessageEinoSingleAgentStream",
"requestBody": map[string]interface{}{
"required": true,
@@ -1612,6 +1695,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"conversationId": map[string]interface{}{"type": "string"},
"role": map[string]interface{}{"type": "string"},
"webshellConnectionId": map[string]interface{}{"type": "string"},
"finalization": finalizationRequestSchema,
},
"required": []string{"message"},
},
@@ -1625,7 +1709,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"text/event-stream": map[string]interface{}{
"schema": map[string]interface{}{
"type": "string",
"description": "SSE 流",
"description": "SSE 流。终态 response 事件 data 包含 finalized、finalizable、status、completionReason、evidenceVerified、evidenceRefs、pendingExecutionIds、missingChecks;过程事件可能包含 finalization_auto_continue。",
},
},
},
@@ -1663,6 +1747,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"type": "string",
"description": "WebShell 连接 ID(可选,与 Eino 单/多代理流式行为一致)",
},
"finalization": finalizationRequestSchema,
"orchestration": map[string]interface{}{
"type": "string",
"description": "Eino 预置编排:deep | plan_execute | supervisor;缺省 deep",
@@ -1676,7 +1761,12 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
},
"responses": map[string]interface{}{
"200": map[string]interface{}{
"description": "成功,响应格式同 /api/eino-agent",
"description": "成功。只有 finalized=true 表示成功最终回复;finalized=false 时 response 为未完成/阻断说明。",
"content": map[string]interface{}{
"application/json": map[string]interface{}{
"schema": map[string]interface{}{"$ref": "#/components/schemas/AgentChatResponse"},
},
},
},
"400": map[string]interface{}{"description": "参数错误"},
"401": map[string]interface{}{"description": "未授权"},
@@ -1689,7 +1779,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"post": map[string]interface{}{
"tags": []string{"对话交互"},
"summary": "发送消息并获取 AI 回复(Eino 多代理,SSE",
"description": "与 `POST /api/eino-agent/stream` 类似;由 Eino 多代理执行。`orchestration` 指定 deep / plan_execute / supervisor,缺省 deep。**前提**`multi_agent.enabled: true`;未启用时 SSE 内首条为 `type: error` 后接 `done`。支持 `webshellConnectionId`。",
"description": "与 `POST /api/eino-agent/stream` 类似;由 Eino 多代理执行。`orchestration` 指定 deep / plan_execute / supervisor,缺省 deep。`response_start` / `response_delta` 仅为候选/过程输出;只有 `type: response` 且 `data.finalized=true` 才表示成功最终回复。缺 completed 执行证据时可能先发送 `finalization_auto_continue`,表示服务端基于已有 trace 无注入续跑。**前提**`multi_agent.enabled: true`;未启用时 SSE 内首条为 `type: error` 后接 `done`。支持 `webshellConnectionId`。",
"operationId": "sendMessageMultiAgentStream",
"requestBody": map[string]interface{}{
"required": true,
@@ -1702,6 +1792,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"conversationId": map[string]interface{}{"type": "string"},
"role": map[string]interface{}{"type": "string"},
"webshellConnectionId": map[string]interface{}{"type": "string"},
"finalization": finalizationRequestSchema,
"orchestration": map[string]interface{}{
"type": "string",
"description": "deep | plan_execute | supervisor;缺省 deep",
@@ -1720,7 +1811,7 @@ func (h *OpenAPIHandler) GetOpenAPISpec(c *gin.Context) {
"text/event-stream": map[string]interface{}{
"schema": map[string]interface{}{
"type": "string",
"description": "SSE 流",
"description": "SSE 流。终态 response 事件 data 包含 finalized、finalizable、status、completionReason、evidenceVerified、evidenceRefs、pendingExecutionIds、missingChecks;过程事件可能包含 finalization_auto_continue。",
},
},
},
+51 -14
View File
@@ -152,20 +152,37 @@ func (h *AgentHandler) runRoleWorkflowStreamIfBound(
sendEvent("done", "", map[string]interface{}{"conversationId": conversationID})
return true
}
if prep.AssistantMessageID != "" {
_ = h.db.UpdateAssistantMessageFinalize(prep.AssistantMessageID, result.Response, nil, "")
decision := h.finalizeCandidateForDeliveryWithPolicy(
prep.ConversationID,
prep.AssistantMessageID,
"workflow",
result.Response,
nil,
result.AwaitingHITL,
"",
true,
)
responseText := decision.FinalText
if !decision.Finalizable {
responseText = finalizationBlockedMessage(decision)
taskStatus = decision.Status
h.tasks.UpdateTaskStatus(conversationID, taskStatus)
sendEvent("finalization_check", responseText, decision)
}
payload := map[string]interface{}{
payload := finalizationResponsePayload(decision, map[string]interface{}{
"conversationId": prep.ConversationID,
"messageId": prep.AssistantMessageID,
"agentMode": "workflow",
"workflowRunId": result.RunID,
}
})
if result.AwaitingHITL {
payload["workflowStatus"] = "awaiting_hitl"
payload["awaitingHitl"] = true
} else {
payload["workflowStatus"] = result.Status
payload["awaitingHitl"] = false
}
sendEvent("response", result.Response, payload)
sendEvent("response", responseText, payload)
sendEvent("done", "", map[string]interface{}{"conversationId": prep.ConversationID})
return true
}
@@ -251,17 +268,37 @@ func (h *AgentHandler) runRoleWorkflowJSONIfBound(c *gin.Context, req *ChatReque
c.JSON(http.StatusInternalServerError, gin.H{"error": errMsg, "conversationId": conversationID})
return true
}
if prep.AssistantMessageID != "" {
_ = h.db.UpdateAssistantMessageFinalize(prep.AssistantMessageID, result.Response, nil, "")
decision := h.finalizeCandidateForDeliveryWithPolicy(
prep.ConversationID,
prep.AssistantMessageID,
"workflow",
result.Response,
nil,
result.AwaitingHITL,
"",
true,
)
responseText := decision.FinalText
if !decision.Finalizable {
responseText = finalizationBlockedMessage(decision)
taskStatus = decision.Status
}
c.JSON(http.StatusOK, gin.H{
"response": result.Response,
"conversationId": prep.ConversationID,
"assistantMessageId": prep.AssistantMessageID,
"agentMode": "workflow",
"workflowRunId": result.RunID,
"workflowStatus": result.Status,
"awaitingHitl": result.AwaitingHITL,
"response": responseText,
"conversationId": prep.ConversationID,
"assistantMessageId": prep.AssistantMessageID,
"agentMode": "workflow",
"workflowRunId": result.RunID,
"workflowStatus": result.Status,
"awaitingHitl": result.AwaitingHITL,
"finalized": decision.Finalized,
"finalizable": decision.Finalizable,
"status": decision.Status,
"completionReason": decision.CompletionReason,
"evidenceVerified": decision.EvidenceVerified,
"evidenceRefs": decision.EvidenceRefs,
"pendingExecutionIds": decision.PendingExecutionIDs,
"missingChecks": decision.MissingChecks,
})
return true
}
+48 -43
View File
@@ -674,48 +674,6 @@ func (m *ExternalMCPManager) updateToolCache(name string, tools []Tool) {
// CallTool 调用外部MCP工具(返回执行ID)
func (m *ExternalMCPManager) CallTool(ctx context.Context, toolName string, args map[string]interface{}) (*ToolResult, string, error) {
_, authenticated := authctx.PrincipalFromContext(ctx)
m.mu.RLock()
authorizer := m.toolAuthorizer
m.mu.RUnlock()
if authorizer != nil {
if err := authorizer(ctx, toolName, args); err != nil {
return nil, "", fmt.Errorf("external tool authorization denied: %w", err)
}
} else if authenticated {
return nil, "", fmt.Errorf("external tool authorization policy is not configured")
}
// 解析工具名称:name::toolName
var mcpName, actualToolName string
if idx := findSubstring(toolName, "::"); idx > 0 {
mcpName = toolName[:idx]
actualToolName = toolName[idx+2:]
} else {
return nil, "", fmt.Errorf("无效的工具名称格式: %s", toolName)
}
client, exists := m.GetClient(mcpName)
if !exists {
return nil, "", fmt.Errorf("外部MCP客户端不存在: %s", mcpName)
}
if err := m.checkExternalMCPCircuit(mcpName); err != nil {
return nil, "", err
}
// 检查连接状态,如果未连接或状态为error,不允许调用
if !client.IsConnected() {
status := client.GetStatus()
if status == "error" {
// 获取错误信息(如果有)
errorMsg := m.GetError(mcpName)
if errorMsg != "" {
return nil, "", fmt.Errorf("外部MCP连接失败: %s (错误: %s)", mcpName, errorMsg)
}
return nil, "", fmt.Errorf("外部MCP连接失败: %s", mcpName)
}
return nil, "", fmt.Errorf("外部MCP客户端未连接: %s (状态: %s)", mcpName, status)
}
if m.executionService == nil {
m.executionService = NewExecutionService(m.storage, m.logger)
m.executionService.ConfigureToolResultMaxBytes(m.toolResultMaxBytes)
@@ -725,12 +683,57 @@ func (m *ExternalMCPManager) CallTool(ctx context.Context, toolName string, args
if principal, ok := authctx.PrincipalFromContext(ctx); ok {
ownerUserID = principal.UserID
}
var mcpName, actualToolName string
var client ExternalMCPClient
handle, err := m.executionService.Submit(ctx, ExecutionRequest{
ToolName: toolName,
Arguments: args,
ConversationID: MCPConversationIDFromContext(ctx),
OwnerUserID: ownerUserID,
PreRun: func(runCtx context.Context, exec *ToolExecution) (func(), error) {
_, authenticated := authctx.PrincipalFromContext(runCtx)
m.mu.RLock()
authorizer := m.toolAuthorizer
m.mu.RUnlock()
if authorizer != nil {
if err := authorizer(runCtx, toolName, args); err != nil {
return nil, fmt.Errorf("external tool authorization denied: %w", err)
}
} else if authenticated {
return nil, fmt.Errorf("external tool authorization policy is not configured")
}
// 解析工具名称:name::toolName
if idx := findSubstring(toolName, "::"); idx > 0 {
mcpName = toolName[:idx]
actualToolName = toolName[idx+2:]
} else {
return nil, fmt.Errorf("无效的工具名称格式: %s", toolName)
}
var exists bool
client, exists = m.GetClient(mcpName)
if !exists {
return nil, fmt.Errorf("外部MCP客户端不存在: %s", mcpName)
}
if err := m.checkExternalMCPCircuit(mcpName); err != nil {
return nil, err
}
// 检查连接状态,如果未连接或状态为error,不允许调用
if !client.IsConnected() {
status := client.GetStatus()
if status == "error" {
// 获取错误信息(如果有)
errorMsg := m.GetError(mcpName)
if errorMsg != "" {
return nil, fmt.Errorf("外部MCP连接失败: %s (错误: %s)", mcpName, errorMsg)
}
return nil, fmt.Errorf("外部MCP连接失败: %s", mcpName)
}
return nil, fmt.Errorf("外部MCP客户端未连接: %s (状态: %s)", mcpName, status)
}
release, acquireErr := m.acquireExternalMCPCallSlot(runCtx, mcpName)
if acquireErr != nil {
return nil, acquireErr
@@ -746,7 +749,9 @@ func (m *ExternalMCPManager) CallTool(ctx context.Context, toolName string, args
},
OnDone: func(exec *ToolExecution) {
failed := exec != nil && exec.Status != ToolExecutionStatusCompleted && exec.Status != ToolExecutionStatusCancelled
m.recordExternalMCPResult(mcpName, failed)
if mcpName != "" {
m.recordExternalMCPResult(mcpName, failed)
}
m.updateStats(toolName, failed)
},
})
+11 -1
View File
@@ -20,10 +20,20 @@ func TestExternalManagerEnforcesConfiguredAuthorizer(t *testing.T) {
return errors.New("denied by policy")
})
ctx := authctx.WithPrincipal(context.Background(), authctx.NewPrincipal("u1", "user", "assigned", map[string]bool{"agent:execute": true}))
_, _, err := manager.CallTool(ctx, "server::tool", map[string]interface{}{})
_, executionID, err := manager.CallTool(ctx, "server::tool", map[string]interface{}{})
if err == nil || !strings.Contains(err.Error(), "authorization denied") {
t.Fatalf("external call bypassed authorizer: %v", err)
}
if executionID == "" {
t.Fatal("denied external call should still return an execution id")
}
execution, ok := manager.GetExecution(executionID)
if !ok || execution == nil {
t.Fatalf("missing denied external execution %q", executionID)
}
if execution.Status != ToolExecutionStatusFailed || !strings.Contains(execution.Error, "denied by policy") {
t.Fatalf("denied external execution = %#v, want failed with policy error", execution)
}
}
func TestExternalMCPManager_AddOrUpdateConfig(t *testing.T) {
+15 -19
View File
@@ -895,25 +895,6 @@ func (s *Server) GetAllTools() []Tool {
// CallTool 直接调用工具(用于内部调用)
func (s *Server) CallTool(ctx context.Context, toolName string, args map[string]interface{}) (*ToolResult, string, error) {
_, authenticated := authctx.PrincipalFromContext(ctx)
s.mu.RLock()
authorizer := s.toolAuthorizer
s.mu.RUnlock()
if authorizer != nil {
if err := authorizer(ctx, toolName, args); err != nil {
return nil, "", fmt.Errorf("tool authorization denied: %w", err)
}
} else if authenticated {
return nil, "", errors.New("tool authorization policy is not configured")
}
s.mu.RLock()
handler, exists := s.tools[toolName]
s.mu.RUnlock()
if !exists {
return nil, "", fmt.Errorf("工具 %s 未找到", toolName)
}
if s.executionService == nil {
s.executionService = NewExecutionService(s.storage, s.logger)
s.executionService.ConfigureToolResultMaxBytes(s.toolResultMaxBytes)
@@ -929,6 +910,21 @@ func (s *Server) CallTool(ctx context.Context, toolName string, args map[string]
ConversationID: MCPConversationIDFromContext(ctx),
OwnerUserID: ownerUserID,
Run: func(runCtx context.Context) (*ToolResult, error) {
_, authenticated := authctx.PrincipalFromContext(runCtx)
s.mu.RLock()
authorizer := s.toolAuthorizer
handler, exists := s.tools[toolName]
s.mu.RUnlock()
if authorizer != nil {
if err := authorizer(runCtx, toolName, args); err != nil {
return nil, fmt.Errorf("tool authorization denied: %w", err)
}
} else if authenticated {
return nil, errors.New("tool authorization policy is not configured")
}
if !exists {
return nil, fmt.Errorf("工具 %s 未找到", toolName)
}
return handler(runCtx, args)
},
OnDone: func(exec *ToolExecution) {
+12 -1
View File
@@ -23,9 +23,20 @@ func TestToolAuthorizerIsUniversalAndExecutionKeepsOwner(t *testing.T) {
}
return nil
})
if _, _, err := server.CallTool(context.Background(), "echo", nil); err == nil {
_, deniedExecutionID, err := server.CallTool(context.Background(), "echo", nil)
if err == nil {
t.Fatal("tool call without principal was allowed")
}
if deniedExecutionID == "" {
t.Fatal("denied tool call should still return an execution id")
}
deniedExecution, ok := server.GetExecution(deniedExecutionID)
if !ok || deniedExecution == nil {
t.Fatalf("missing denied execution %q", deniedExecutionID)
}
if deniedExecution.Status != ToolExecutionStatusFailed || !strings.Contains(deniedExecution.Error, "principal required") {
t.Fatalf("denied execution = %#v, want failed with authorization error", deniedExecution)
}
ctx := authctx.WithPrincipal(context.Background(), authctx.NewPrincipal("u1", "user", "assigned", map[string]bool{"mcp:execute": true}))
_, executionID, err := server.CallTool(ctx, "echo", nil)
if err != nil {
+5 -1
View File
@@ -60,6 +60,7 @@ func isEinoTransientRunError(err error) bool {
"bad gateway",
"gateway timeout",
"internal server error",
"unexpected internal error",
"connection reset",
"connection refused",
"connection closed",
@@ -72,6 +73,7 @@ func isEinoTransientRunError(err error) bool {
"dial tcp",
"tls handshake timeout",
"stream error",
"failed to receive stream chunk",
"goaway", // http2: server sent GOAWAY and closed the connection
"unexpected eof",
`": eof`, // net/http: Post "url": EOF (often wraps io.EOF)
@@ -136,7 +138,8 @@ func einoTransientRunErrorUserDetail(err error) (kind, summary string) {
case strings.Contains(lower, "overloaded") ||
strings.Contains(lower, "capacity") ||
strings.Contains(lower, "temporarily unavailable") ||
strings.Contains(lower, "service unavailable"):
strings.Contains(lower, "service unavailable") ||
strings.Contains(lower, "unexpected internal error"):
kind = "upstream_busy"
case strings.Contains(lower, "connection reset") ||
strings.Contains(lower, "connection refused") ||
@@ -153,6 +156,7 @@ func einoTransientRunErrorUserDetail(err error) (kind, summary string) {
strings.Contains(lower, "unexpected eof"):
kind = "network"
case strings.Contains(lower, "stream error") ||
strings.Contains(lower, "failed to receive stream chunk") ||
strings.Contains(lower, "unexpected end of json"):
kind = "stream"
default:
@@ -34,6 +34,7 @@ func TestIsEinoTransientRunError(t *testing.T) {
{"rate limit", errors.New(`{"error":"rate limit exceeded"}`), true},
{"connection reset", errors.New("read tcp: connection reset by peer"), true},
{"http2 goaway", errors.New("failed to receive stream chunk: error, http2: server sent GOAWAY and closed the connection; LastStreamID=791, ErrCode=NO_ERROR"), true},
{"unexpected internal stream chunk", errors.New("failed to receive stream chunk: error, The service encountered an unexpected internal error. Request id: 0217851391106464f01ec66621d0980a42fd45436ed75957a6a0a"), true},
{"unexpected eof", errors.New("unexpected EOF"), true},
{"503", errors.New("upstream returned 503"), true},
{"iteration limit", errors.New("max iteration reached"), false},
@@ -74,6 +75,7 @@ func TestEinoTransientRunErrorUserDetail(t *testing.T) {
{"upstream", errors.New("upstream returned 503"), "upstream_server"},
{"network", errors.New("read tcp: connection reset by peer"), "network"},
{"stream", errors.New("unexpected end of JSON"), "stream"},
{"stream chunk", errors.New("failed to receive stream chunk: error, The service encountered an unexpected internal error. Request id: abc"), "upstream_busy"},
}
for _, tc := range cases {
tc := tc
@@ -96,7 +96,17 @@ func (m *modelOutputGuardMiddleware) AfterModelRewriteState(
badIndex := -1
argumentBytes := 0
if strings.EqualFold(strings.TrimSpace(finishReason), "length") {
reason = "output_limit"
if len(last.ToolCalls) == 0 {
reason = "output_limit"
} else {
for i, tc := range last.ToolCalls {
r, n := validateGeneratedToolCall(tc, m.cfg)
if r != "" {
reason, badIndex, argumentBytes = "output_limit", i, n
break
}
}
}
} else {
for i, tc := range last.ToolCalls {
r, n := validateGeneratedToolCall(tc, m.cfg)
@@ -50,6 +50,18 @@ func TestModelOutputGuardRejectsTruncatedToolCallBeforeExecution(t *testing.T) {
}
}
func TestModelOutputGuardAllowsValidToolCallDespiteLengthFinish(t *testing.T) {
original := `{"command":"echo ok"}`
state, err := runModelOutputGuard(t, []adk.Message{schema.UserMessage("run"), guardedAssistant(original, "length")}, config.MultiAgentEinoMiddlewareConfig{})
if err != nil {
t.Fatal(err)
}
got := state.Messages[len(state.Messages)-1].ToolCalls[0].Function.Arguments
if got != original {
t.Fatalf("valid arguments should pass unchanged: %q", got)
}
}
func TestModelOutputGuardRejectsInvalidJSONShapes(t *testing.T) {
for _, arguments := range []string{"", `[]`, `{"command":`} {
t.Run(arguments, func(t *testing.T) {
+7
View File
@@ -40,6 +40,13 @@ type RunResult struct {
MCPExecutionIDs []string
LastAgentTraceInput string // 已序列化的消息带(JSON):原生循环或 Eino 均写入,供续跑/攻击链等恢复上下文
LastAgentTraceOutput string // 本轮助手侧对外展示文本(摘要或最终回复)
Finalized bool
Status string
CompletionReason string
EvidenceVerified bool
EvidenceRefs []string
PendingExecutionIDs []string
MissingChecks []string
}
// toolCallPendingInfo tracks a tool_call emitted to the UI so we can later
+1 -1
View File
@@ -893,7 +893,7 @@ func NewEinoHTTPClient(cfg *config.OpenAIConfig, base *http.Client) *http.Client
if transport == nil {
transport = http.DefaultTransport
}
transport = &reasoningToolChoiceCompatRoundTripper{base: transport}
transport = &reasoningToolChoiceCompatRoundTripper{base: transport, cfg: cfg}
if isClaudeProvider(cfg) {
transport = &claudeRoundTripper{
base: transport,
+38
View File
@@ -1,6 +1,8 @@
package openai
import (
"strings"
"github.com/bytedance/sonic"
)
@@ -52,6 +54,28 @@ func StripReasoningIfForcedToolChoice(rawBody []byte) ([]byte, error) {
return out, nil
}
// StripToolChoiceForThinkingMode removes tool_choice while preserving tools and
// thinking fields. DeepSeek thinking mode can use tools, but rejects the
// tool_choice parameter itself on some agent requests.
func StripToolChoiceForThinkingMode(rawBody []byte) ([]byte, error) {
var payload map[string]any
if err := sonic.Unmarshal(rawBody, &payload); err != nil {
return rawBody, nil
}
if !thinkingModeEnabledByPayload(payload) {
return rawBody, nil
}
if _, ok := payload["tool_choice"]; !ok {
return rawBody, nil
}
delete(payload, "tool_choice")
out, err := sonic.Marshal(payload)
if err != nil {
return rawBody, err
}
return out, nil
}
func stripReasoningFields(payload map[string]any) bool {
changed := false
for _, key := range reasoningPayloadKeys {
@@ -77,3 +101,17 @@ func forcedToolChoiceIncompatibleWithThinking(payload map[string]any) bool {
return false
}
}
func thinkingModeEnabledByPayload(payload map[string]any) bool {
thinking, ok := payload["thinking"]
if !ok || thinking == nil {
// DeepSeek enables thinking by default unless explicitly disabled.
return true
}
if m, ok := thinking.(map[string]any); ok {
if typ, ok := m["type"].(string); ok && strings.EqualFold(strings.TrimSpace(typ), "disabled") {
return false
}
}
return true
}
+92
View File
@@ -5,6 +5,8 @@ import (
"net/http"
"strings"
"testing"
"cyberstrike-ai/internal/config"
)
func TestStripReasoningFromChatCompletionBody(t *testing.T) {
@@ -82,6 +84,58 @@ func TestStripReasoningIfForcedToolChoice(t *testing.T) {
}
}
func TestStripToolChoiceForThinkingMode(t *testing.T) {
cases := []struct {
name string
in string
wantToolChoice bool
wantThinking bool
}{
{
name: "enabled thinking removes tool_choice",
in: `{"model":"deepseek-v4","messages":[],"thinking":{"type":"enabled"},"tool_choice":"required","tools":[{"type":"function","function":{"name":"scan"}}]}`,
wantToolChoice: false,
wantThinking: true,
},
{
name: "default thinking removes tool_choice",
in: `{"model":"deepseek-v4","messages":[],"tool_choice":"auto","tools":[]}`,
wantToolChoice: false,
wantThinking: false,
},
{
name: "disabled thinking keeps tool_choice",
in: `{"model":"deepseek-v4","messages":[],"thinking":{"type":"disabled"},"tool_choice":"required","tools":[]}`,
wantToolChoice: true,
wantThinking: true,
},
{
name: "no tool_choice unchanged",
in: `{"model":"deepseek-v4","messages":[],"thinking":{"type":"enabled"},"tools":[]}`,
wantToolChoice: false,
wantThinking: true,
},
}
for _, tc := range cases {
t.Run(tc.name, func(t *testing.T) {
out, err := StripToolChoiceForThinkingMode([]byte(tc.in))
if err != nil {
t.Fatal(err)
}
s := string(out)
if strings.Contains(s, "tool_choice") != tc.wantToolChoice {
t.Fatalf("tool_choice presence mismatch, got %s", s)
}
if strings.Contains(s, "thinking") != tc.wantThinking {
t.Fatalf("thinking presence mismatch, got %s", s)
}
if !strings.Contains(s, "tools") {
t.Fatalf("expected tools preserved, got %s", s)
}
})
}
}
func TestReasoningToolChoiceCompatRoundTripper(t *testing.T) {
var gotBody string
rt := &reasoningToolChoiceCompatRoundTripper{
@@ -113,6 +167,44 @@ func TestReasoningToolChoiceCompatRoundTripper(t *testing.T) {
}
}
func TestReasoningToolChoiceCompatRoundTripperDeepSeek(t *testing.T) {
var gotBody string
rt := &reasoningToolChoiceCompatRoundTripper{
cfg: &config.OpenAIConfig{
BaseURL: "https://api.deepseek.com/v1",
Model: "deepseek-v4",
},
base: roundTripperFunc(func(req *http.Request) (*http.Response, error) {
b, _ := io.ReadAll(req.Body)
gotBody = string(b)
return &http.Response{
StatusCode: 200,
Body: io.NopCloser(strings.NewReader(`{"choices":[{"message":{"content":"ok"}}]}`)),
Header: http.Header{"Content-Type": []string{"application/json"}},
}, nil
}),
}
req, err := http.NewRequest(http.MethodPost, "https://api.deepseek.com/v1/chat/completions", strings.NewReader(
`{"model":"deepseek-v4","thinking":{"type":"enabled"},"tool_choice":"required","tools":[],"messages":[]}`,
))
if err != nil {
t.Fatal(err)
}
_, err = rt.RoundTrip(req)
if err != nil {
t.Fatal(err)
}
if strings.Contains(gotBody, "tool_choice") {
t.Fatalf("expected DeepSeek tool_choice stripped in transit, got %s", gotBody)
}
if !strings.Contains(gotBody, "thinking") {
t.Fatalf("expected thinking preserved for DeepSeek, got %s", gotBody)
}
if !strings.Contains(gotBody, "tools") {
t.Fatalf("expected tools preserved for DeepSeek, got %s", gotBody)
}
}
type roundTripperFunc func(*http.Request) (*http.Response, error)
func (f roundTripperFunc) RoundTrip(req *http.Request) (*http.Response, error) {
@@ -6,6 +6,8 @@ import (
"net/http"
"strconv"
"strings"
"cyberstrike-ai/internal/config"
)
// reasoningToolChoiceCompatRoundTripper strips thinking/reasoning fields from
@@ -13,6 +15,7 @@ import (
// when thinking mode is enabled on the same request.
type reasoningToolChoiceCompatRoundTripper struct {
base http.RoundTripper
cfg *config.OpenAIConfig
}
func (rt *reasoningToolChoiceCompatRoundTripper) RoundTrip(req *http.Request) (*http.Response, error) {
@@ -32,7 +35,13 @@ func (rt *reasoningToolChoiceCompatRoundTripper) RoundTrip(req *http.Request) (*
return nil, err
}
patched, perr := StripReasoningIfForcedToolChoice(body)
patched := body
var perr error
if isDeepSeekToolChoiceCompatProfile(rt.cfg) {
patched, perr = StripToolChoiceForThinkingMode(body)
} else {
patched, perr = StripReasoningIfForcedToolChoice(body)
}
if perr != nil {
patched = body
}
@@ -41,3 +50,19 @@ func (rt *reasoningToolChoiceCompatRoundTripper) RoundTrip(req *http.Request) (*
req.Header.Set("Content-Length", strconv.Itoa(len(patched)))
return rt.base.RoundTrip(req)
}
func isDeepSeekToolChoiceCompatProfile(cfg *config.OpenAIConfig) bool {
if cfg == nil {
return false
}
profile := strings.ToLower(strings.TrimSpace(cfg.Reasoning.ProfileEffective()))
if profile == "deepseek" || profile == "deepseek_compat" {
return true
}
if profile != "" && profile != "auto" {
return false
}
baseURL := strings.ToLower(cfg.BaseURL)
model := strings.ToLower(cfg.Model)
return strings.Contains(baseURL, "deepseek") || strings.Contains(model, "deepseek")
}
+2 -2
View File
@@ -9,8 +9,8 @@ import (
)
var (
bodyDepFactLine = regexp.MustCompile(`(?im)^[\s\-*]*依赖事实\s*[:]\s*([a-z0-9][a-z0-9._/-]*)`)
bodyRelFactLine = regexp.MustCompile(`(?im)^[\s\-*]*相关\s*fact_key\s*[:]\s*([a-z0-9][a-z0-9._/-]*)`)
bodyDepFactLine = regexp.MustCompile(`(?im)^[\s\-*]*依赖事实\s*[:]\s*([a-zA-Z0-9][a-zA-Z0-9._/-]*)`)
bodyRelFactLine = regexp.MustCompile(`(?im)^[\s\-*]*相关\s*fact_key\s*[:]\s*([a-zA-Z0-9][a-zA-Z0-9._/-]*)`)
bodyAssocSection = regexp.MustCompile(`(?im)^##\s*关联\s*$`)
bodySyncLinksHead = "结构化关系边(自动同步)"
)
+99 -19
View File
@@ -61,25 +61,30 @@ show_progress() {
printf "\r"
}
echo ""
echo "=========================================="
echo " CyberStrikeAI Deploy & Start Script"
echo " (HTTPS with self-signed cert by default; plain HTTP: $0 --http)"
echo "=========================================="
echo ""
print_banner() {
local show_mirrors="${1:-1}"
echo ""
echo "=========================================="
echo " CyberStrikeAI Deploy & Start Script"
echo " (HTTPS with self-signed cert by default; plain HTTP: $0 --http)"
echo "=========================================="
echo ""
# Show temporary mirror/proxy info
echo ""
warning "Note: this script uses temporary mirrors to speed up downloads"
echo ""
info "Python pip temporary mirror:"
echo " ${PIP_INDEX_URL}"
info "Go temporary proxy:"
echo " ${GOPROXY}"
echo ""
note "These settings apply only while this script runs and do not change system config"
echo ""
sleep 1
if [ "$show_mirrors" -eq 1 ]; then
# Show temporary mirror/proxy info
echo ""
warning "Note: this script uses temporary mirrors to speed up downloads"
echo ""
info "Python pip temporary mirror:"
echo " ${PIP_INDEX_URL}"
info "Go temporary proxy:"
echo " ${GOPROXY}"
echo ""
note "These settings apply only while this script runs and do not change system config"
echo ""
sleep 1
fi
}
CONFIG_FILE="$ROOT_DIR/config.yaml"
EXAMPLE_CONFIG_FILE="$ROOT_DIR/config.example.yaml"
@@ -136,6 +141,28 @@ check_go() {
success "Go check passed: $(go version)"
}
check_go_quiet() {
if ! command -v go >/dev/null 2>&1; then
error "Go not found"
echo ""
info "Install Go 1.21 or later first:"
echo " macOS: brew install go"
echo " Ubuntu: sudo apt-get install golang-go"
echo " CentOS: sudo yum install golang"
echo " Or visit: https://go.dev/dl/"
exit 1
fi
GO_VERSION=$(go version | awk '{print $3}' | sed 's/go//')
GO_MAJOR=$(echo "$GO_VERSION" | cut -d. -f1)
GO_MINOR=$(echo "$GO_VERSION" | cut -d. -f2)
if [ "$GO_MAJOR" -lt 1 ] || ([ "$GO_MAJOR" -eq 1 ] && [ "$GO_MINOR" -lt 21 ]); then
error "Go version too old: $GO_VERSION (requires 1.21+)"
exit 1
fi
}
# Set up Python virtual environment
setup_python_env() {
if [ ! -d "$VENV_DIR" ]; then
@@ -331,6 +358,34 @@ build_go_project() {
fi
}
build_go_project_quiet() {
info "Building $BINARY_NAME..."
GO_DOWNLOAD_LOG=$(mktemp)
if ! GOPROXY="$GOPROXY" go mod download >"$GO_DOWNLOAD_LOG" 2>&1; then
error "Go dependency download failed"
echo ""
info "Download error details:"
cat "$GO_DOWNLOAD_LOG" | sed 's/^/ /'
echo ""
rm -f "$GO_DOWNLOAD_LOG"
exit 1
fi
rm -f "$GO_DOWNLOAD_LOG"
GO_BUILD_LOG=$(mktemp)
if ! GOPROXY="$GOPROXY" go build -o "$BINARY_NAME" cmd/server/main.go >"$GO_BUILD_LOG" 2>&1; then
error "Build failed"
echo ""
info "Build error details:"
cat "$GO_BUILD_LOG" | sed 's/^/ /'
echo ""
rm -f "$GO_BUILD_LOG"
exit 1
fi
rm -f "$GO_BUILD_LOG"
}
# Check whether a rebuild is needed
need_rebuild() {
if [ ! -f "$BINARY_NAME" ]; then
@@ -351,6 +406,7 @@ need_rebuild() {
# Default: HTTPS (--https passed to binary); --http forces plain HTTP even if config.yaml enables TLS.
main() {
USE_HTTPS=1
RESET_ADMIN_PASSWORD=0
FORWARD_ARGS=()
for arg in "$@"; do
if [ "$arg" = "--http" ]; then
@@ -361,9 +417,33 @@ main() {
USE_HTTPS=1
continue
fi
if [ "$arg" = "--reset-admin-password" ]; then
RESET_ADMIN_PASSWORD=1
continue
fi
FORWARD_ARGS+=("$arg")
done
if [ "$RESET_ADMIN_PASSWORD" -eq 1 ]; then
if [ ! -f "$CONFIG_FILE" ] && [ ! -f "$EXAMPLE_CONFIG_FILE" ]; then
error "config.yaml not found, and config.example.yaml is missing"
info "The server binary creates config.yaml from config.example.yaml on first start"
exit 1
fi
check_go_quiet
if need_rebuild; then
build_go_project_quiet
echo ""
fi
if [ "${#FORWARD_ARGS[@]}" -gt 0 ]; then
exec "./$BINARY_NAME" -config "$CONFIG_FILE" --reset-admin-password "${FORWARD_ARGS[@]}"
else
exec "./$BINARY_NAME" -config "$CONFIG_FILE" --reset-admin-password
fi
fi
print_banner 1
# Environment checks
info "Checking runtime environment..."
check_python
@@ -417,5 +497,5 @@ main() {
fi
}
# Run main (supports args, e.g. ./run.sh --http)
# Run main (supports args, e.g. ./run.sh --http, ./run.sh --reset-admin-password)
main "$@"
+546 -88
View File
@@ -3990,6 +3990,17 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
border-top-left-radius: 2px;
}
.message.assistant.assistant-not-finalized .message-bubble {
border-color: rgba(245, 124, 0, 0.28);
border-left: 4px solid #f57c00;
background: linear-gradient(90deg, rgba(245, 124, 0, 0.08), rgba(245, 124, 0, 0.035));
box-shadow: 0 6px 18px rgba(245, 124, 0, 0.08);
}
.message.assistant.assistant-not-finalized .message-bubble strong:first-child {
color: #b45309;
}
.message.assistant .message-bubble pre {
margin: 0;
white-space: pre-wrap;
@@ -4430,7 +4441,7 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
.ai-channel-manager {
border: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 88%, transparent);
border-radius: 10px;
border-radius: 8px;
background: var(--card-bg, #fff);
overflow: hidden;
}
@@ -4446,8 +4457,8 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
}
.ai-channel-manager-header h4 {
margin: 0 0 8px;
font-size: 16px;
margin: 0 0 6px;
font-size: 17px;
line-height: 1.25;
}
@@ -4467,55 +4478,75 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
color: var(--error-color, #e53e3e);
}
.ai-channel-header-actions {
display: flex;
align-items: center;
justify-content: flex-end;
flex-wrap: wrap;
gap: 10px;
flex-shrink: 0;
}
.ai-channel-save-btn {
flex-shrink: 0;
min-width: 92px;
}
.ai-channel-manager-body {
display: grid;
grid-template-columns: minmax(280px, 360px) minmax(0, 1fr);
display: block;
min-height: 0;
align-items: stretch;
background: var(--card-bg, #fff);
overflow: visible;
}
.ai-channel-sidebar {
position: relative;
display: flex;
flex-direction: column;
gap: 10px;
min-height: 0;
overflow: hidden;
border-right: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 76%, transparent);
background: color-mix(in srgb, var(--bg-secondary, #f8fafc) 86%, var(--card-bg, #fff));
padding: 18px;
}
.ai-channel-sidebar-head {
.ai-channel-switcher {
display: flex;
align-items: center;
justify-content: space-between;
gap: 10px;
margin-bottom: 0;
color: var(--text-secondary, #4a5568);
font-size: 12px;
font-weight: 700;
letter-spacing: 0;
gap: 16px;
padding: 16px 22px;
border-bottom: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 72%, transparent);
background: color-mix(in srgb, var(--bg-secondary, #f8fafc) 70%, var(--card-bg, #fff));
}
.ai-channel-bulk-actions {
.ai-channel-switcher-field {
display: grid;
grid-template-columns: auto minmax(260px, 420px);
align-items: center;
gap: 10px;
min-width: 0;
}
.ai-channel-switcher-field label {
color: var(--text-secondary, #4a5568);
font-size: 13px;
font-weight: 700;
white-space: nowrap;
}
.ai-channel-switch-select {
width: 100%;
min-height: 38px;
padding: 0.45rem 2rem 0.45rem 0.7rem;
border: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 88%, transparent);
border-radius: 7px;
background: color-mix(in srgb, var(--input-bg, var(--card-bg, #fff)) 92%, transparent);
color: var(--text-primary, #2d3748);
font-size: 0.875rem;
}
.ai-channel-switch-select:focus {
border-color: color-mix(in srgb, var(--accent-color, #3182ce) 70%, transparent);
box-shadow: 0 0 0 3px color-mix(in srgb, var(--accent-color, #3182ce) 12%, transparent);
outline: none;
}
.ai-channel-switcher-actions {
display: flex;
align-items: center;
justify-content: flex-end;
flex-wrap: wrap;
gap: 5px;
margin: 0;
min-width: 0;
padding: 0;
border: 0;
background: transparent;
gap: 8px;
}
.ai-channel-bulk-btn {
@@ -4523,8 +4554,8 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
align-items: center;
justify-content: center;
min-width: 0;
min-height: 26px;
padding: 4px 8px;
min-height: 28px;
padding: 5px 9px;
border: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 68%, transparent);
border-radius: 999px;
background: color-mix(in srgb, var(--card-bg, #fff) 38%, transparent);
@@ -4555,8 +4586,8 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
}
.ai-channel-icon-btn {
width: 30px;
height: 30px;
width: 32px;
height: 32px;
border: 1px solid var(--border-color, #e2e8f0);
border-radius: 8px;
background: var(--card-bg, #fff);
@@ -4577,19 +4608,7 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
}
.ai-channel-list {
position: absolute;
top: 64px;
right: 13px;
bottom: 18px;
left: 18px;
display: flex;
flex-direction: column;
gap: 10px;
min-height: 0;
overflow-y: auto;
overflow-x: hidden;
padding: 2px 5px 2px 1px;
scrollbar-gutter: stable;
display: none;
}
.ai-channel-list::-webkit-scrollbar {
@@ -4616,10 +4635,10 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
align-items: start;
gap: 10px;
width: 100%;
min-height: 92px;
padding: 12px;
min-height: 86px;
padding: 11px;
border: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 64%, transparent);
border-radius: 8px;
border-radius: 7px;
background: color-mix(in srgb, var(--card-bg, #fff) 70%, transparent);
color: var(--text-color, #2d3748);
text-align: left;
@@ -4640,7 +4659,7 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
height: 16px;
margin: 3px 0 0;
border: 1px solid color-mix(in srgb, var(--text-muted, #718096) 52%, transparent);
border-radius: 5px;
border-radius: 4px;
appearance: none;
-webkit-appearance: none;
background-color: color-mix(in srgb, var(--card-bg, #fff) 84%, transparent);
@@ -4671,7 +4690,6 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
.ai-channel-list-item:hover {
background: var(--card-bg, #fff);
border-color: color-mix(in srgb, var(--accent-color, #3182ce) 24%, transparent);
transform: translateY(-1px);
}
.ai-channel-list-item.active {
@@ -4732,6 +4750,10 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
color: #10b981;
}
.ai-channel-status-label.complete {
color: #3b82f6;
}
.ai-channel-status-label.testing {
color: #3b82f6;
}
@@ -4753,6 +4775,10 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
background: #10b981;
}
.ai-channel-status-dot.complete {
background: #3b82f6;
}
.ai-channel-status-dot.draft {
background: #f59e0b;
}
@@ -4779,17 +4805,17 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
min-width: 0;
min-height: 0;
overflow-y: visible;
padding: 22px 28px 28px;
padding: 20px 28px 28px;
background: var(--card-bg, #fff);
}
.ai-channel-editor-head {
display: flex;
align-items: flex-start;
align-items: center;
justify-content: space-between;
gap: 18px;
margin-bottom: 18px;
padding-bottom: 18px;
margin-bottom: 6px;
padding-bottom: 16px;
border-bottom: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 72%, transparent);
}
@@ -4801,18 +4827,60 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
font-weight: 700;
}
.ai-channel-editor-head h5 {
.ai-channel-editor-title {
margin: 0;
color: var(--text-color, #2d3748);
font-size: 22px;
font-weight: 700;
line-height: 1.2;
}
.ai-channel-editor-head p {
margin: 4px 0 0;
color: var(--text-muted, #718096);
font-size: 12px;
line-height: 1.5;
}
.ai-channel-editor-meta {
display: flex;
flex-wrap: wrap;
justify-content: flex-end;
gap: 8px;
min-width: 0;
}
.ai-channel-editor-chip {
max-width: 220px;
overflow: hidden;
text-overflow: ellipsis;
white-space: nowrap;
border: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 70%, transparent);
border-radius: 999px;
background: color-mix(in srgb, var(--card-bg, #fff) 92%, var(--primary-color, #3182ce));
color: var(--text-muted, #718096);
font-size: 12px;
font-weight: 600;
line-height: 1;
padding: 7px 10px;
}
.ai-channel-editor-chip.default,
.ai-channel-editor-chip.complete {
border-color: rgba(49, 130, 206, 0.22);
background: rgba(49, 130, 206, 0.1);
color: var(--primary-color, #3182ce);
}
.ai-channel-editor-chip.ready {
border-color: rgba(16, 185, 129, 0.22);
background: rgba(16, 185, 129, 0.1);
color: #059669;
}
.ai-channel-editor-chip.testing {
border-color: rgba(214, 158, 46, 0.24);
background: rgba(214, 158, 46, 0.1);
color: #b7791f;
}
.ai-channel-editor-chip.failed,
.ai-channel-editor-chip.draft {
border-color: rgba(229, 62, 62, 0.2);
background: rgba(229, 62, 62, 0.08);
color: var(--error-color, #e53e3e);
}
.ai-channel-editor-actions {
@@ -4827,8 +4895,9 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
color: var(--error-color, #e53e3e);
}
.ai-channel-editor-form {
max-width: 980px;
max-width: none;
}
.ai-channel-editor-form .form-group {
@@ -4837,7 +4906,7 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
.ai-channel-editor-form .form-group label {
display: block;
margin-bottom: 0;
margin-bottom: 6px;
color: var(--text-primary);
font-size: 0.875rem;
font-weight: 500;
@@ -4848,10 +4917,14 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
.ai-channel-editor-form input[type="password"],
.ai-channel-editor-form input[type="number"],
.ai-channel-editor-form select {
width: 100%;
min-height: 42px;
border-radius: 8px;
padding: 0.5rem 0.75rem;
border-radius: 7px;
border-color: color-mix(in srgb, var(--border-color, #e2e8f0) 88%, transparent);
background: color-mix(in srgb, var(--input-bg, var(--card-bg, #fff)) 92%, transparent);
color: var(--text-color, #2d3748);
font-size: 0.875rem;
}
.ai-channel-editor-form input:focus,
@@ -4863,9 +4936,175 @@ html[data-theme="dark"] .new-chat-btn:focus-visible {
.ai-channel-editor-form .form-hint,
.ai-channel-editor-form small {
display: block;
margin-top: 5px;
color: var(--text-muted, #718096);
font-size: 0.75rem;
line-height: 1.45;
}
.ai-channel-form-section {
padding: 18px 0;
border-bottom: 1px solid color-mix(in srgb, var(--border-color, #e2e8f0) 64%, transparent);
}
.ai-channel-form-section:last-of-type {
border-bottom: 0;
}
.ai-channel-form-section-head {
display: flex;
align-items: flex-start;
justify-content: space-between;
gap: 24px;
margin-bottom: 14px;
}
.ai-channel-form-section-head > div:first-child {
max-width: 620px;
}
.ai-channel-form-section-head h6 {
margin: 0;
color: var(--text-primary, #1f2937);
font-size: 14px;
font-weight: 700;
line-height: 1.35;
}
.ai-channel-form-section-head p {
margin: 4px 0 0;
color: var(--text-muted, #718096);
font-size: 12px;
line-height: 1.45;
}
.ai-channel-section-actions {
display: flex;
align-items: center;
justify-content: flex-end;
flex-wrap: wrap;
gap: 8px;
min-width: 210px;
}
.ai-channel-section-actions .form-inline-result {
margin-top: 0;
}
.ai-channel-section-actions .connection-test-result {
display: none;
max-width: min(760px, 54vw);
padding: 8px 10px;
border: 1px solid var(--border-color, #e2e8f0);
border-radius: 8px;
background: color-mix(in srgb, var(--surface-color, #ffffff) 86%, var(--bg-secondary, #f7fafc));
color: var(--text-muted, #718096);
font-size: 12px;
line-height: 1.45;
text-align: left;
white-space: pre-wrap;
overflow-wrap: anywhere;
word-break: break-word;
}
.ai-channel-section-actions .connection-test-result.is-visible {
display: inline-block;
}
.ai-channel-section-actions .connection-test-result.is-error {
border-color: color-mix(in srgb, var(--danger-color, #e53e3e) 42%, var(--border-color, #e2e8f0));
background: color-mix(in srgb, var(--danger-color, #e53e3e) 8%, var(--surface-color, #ffffff));
color: var(--danger-color, #e53e3e);
}
.ai-channel-section-actions .connection-test-result.is-success {
border-color: color-mix(in srgb, var(--success-color, #38a169) 38%, var(--border-color, #e2e8f0));
background: color-mix(in srgb, var(--success-color, #38a169) 9%, var(--surface-color, #ffffff));
color: var(--success-color, #38a169);
}
.ai-channel-form-grid,
.ai-channel-reasoning-grid {
display: grid;
grid-template-columns: repeat(auto-fit, minmax(340px, 1fr));
column-gap: 16px;
row-gap: 14px;
}
.ai-channel-reasoning-grid {
grid-template-columns: repeat(auto-fit, minmax(220px, 1fr));
}
.ai-channel-editor-form .span-2 {
grid-column: 1 / -1;
}
.required-mark {
color: var(--error-color, #e53e3e);
}
.form-inline-result {
display: block;
margin-top: 6px;
color: var(--text-muted, #718096);
font-size: 0.75rem;
line-height: 1.45;
}
.ai-channel-reasoning-toggle {
margin-top: 8px;
}
.ai-channel-advanced-section {
padding: 10px 0 0;
border-bottom: 0;
}
.ai-channel-advanced-section summary {
display: flex;
align-items: center;
gap: 10px;
min-height: 38px;
padding: 0;
color: var(--text-primary, #1f2937);
cursor: pointer;
list-style: none;
}
.ai-channel-advanced-section summary::-webkit-details-marker {
display: none;
}
.ai-channel-advanced-section summary::before {
content: "";
width: 8px;
height: 8px;
flex: 0 0 auto;
border-right: 2px solid var(--text-muted, #718096);
border-bottom: 2px solid var(--text-muted, #718096);
transform: rotate(-45deg);
transition: transform 0.16s ease;
}
.ai-channel-advanced-section[open] summary::before {
transform: rotate(45deg);
}
.ai-channel-advanced-section summary strong {
display: block;
font-size: 14px;
line-height: 1.35;
}
.ai-channel-advanced-section summary small {
margin-top: 4px;
}
.ai-channel-advanced-section[open] .ai-channel-reasoning-grid {
margin-top: 14px;
}
html[data-theme="dark"] .ai-channel-manager {
background: #111827;
border-color: rgba(71, 85, 105, 0.42);
@@ -4876,6 +5115,21 @@ html[data-theme="dark"] .ai-channel-manager-header {
border-bottom-color: rgba(71, 85, 105, 0.34);
}
html[data-theme="dark"] .ai-channel-switcher {
background: #101827;
border-bottom-color: rgba(71, 85, 105, 0.34);
}
html[data-theme="dark"] .ai-channel-switcher-field label {
color: #cbd5e1;
}
html[data-theme="dark"] .ai-channel-switch-select {
background: rgba(15, 23, 42, 0.72);
border-color: rgba(71, 85, 105, 0.44);
color: #e5e7eb;
}
html[data-theme="dark"] .ai-channel-sidebar {
background: #101827;
border-right-color: rgba(71, 85, 105, 0.34);
@@ -4928,6 +5182,74 @@ html[data-theme="dark"] .ai-channel-editor-head {
border-bottom-color: rgba(71, 85, 105, 0.34);
}
html[data-theme="dark"] .ai-channel-editor-chip {
border-color: rgba(71, 85, 105, 0.46);
background: rgba(15, 23, 42, 0.7);
color: #94a3b8;
}
html[data-theme="dark"] .ai-channel-editor-chip.default,
html[data-theme="dark"] .ai-channel-editor-chip.complete {
border-color: rgba(96, 165, 250, 0.34);
background: rgba(96, 165, 250, 0.12);
color: #93c5fd;
}
html[data-theme="dark"] .ai-channel-editor-chip.ready {
border-color: rgba(52, 211, 153, 0.28);
background: rgba(52, 211, 153, 0.1);
color: #6ee7b7;
}
html[data-theme="dark"] .ai-channel-editor-chip.testing {
border-color: rgba(251, 191, 36, 0.28);
background: rgba(251, 191, 36, 0.1);
color: #fbbf24;
}
html[data-theme="dark"] .ai-channel-editor-chip.failed,
html[data-theme="dark"] .ai-channel-editor-chip.draft {
border-color: rgba(248, 113, 113, 0.28);
background: rgba(248, 113, 113, 0.1);
color: #fca5a5;
}
html[data-theme="dark"] .ai-channel-form-section,
html[data-theme="dark"] .ai-channel-advanced-section {
border-color: rgba(71, 85, 105, 0.34);
}
html[data-theme="dark"] .ai-channel-form-section-head h6 {
color: #e5e7eb;
}
html[data-theme="dark"] .ai-channel-form-section-head p,
html[data-theme="dark"] .form-inline-result {
color: #94a3b8;
}
html[data-theme="dark"] .ai-channel-section-actions .connection-test-result {
border-color: rgba(71, 85, 105, 0.52);
background: rgba(15, 23, 42, 0.74);
color: #94a3b8;
}
html[data-theme="dark"] .ai-channel-section-actions .connection-test-result.is-error {
border-color: rgba(248, 113, 113, 0.42);
background: rgba(127, 29, 29, 0.22);
color: #f87171;
}
html[data-theme="dark"] .ai-channel-section-actions .connection-test-result.is-success {
border-color: rgba(52, 211, 153, 0.38);
background: rgba(6, 78, 59, 0.22);
color: #34d399;
}
html[data-theme="dark"] .ai-channel-advanced-section summary {
color: #e5e7eb;
}
html[data-theme="dark"] .ai-channel-icon-btn {
background: rgba(15, 23, 42, 0.72);
border-color: rgba(71, 85, 105, 0.44);
@@ -5009,23 +5331,13 @@ html[data-theme="dark"] .ai-channel-editor-form select {
align-items: stretch;
}
.ai-channel-manager-body {
grid-template-columns: 1fr;
height: auto;
overflow: visible;
.ai-channel-editor-meta {
justify-content: flex-start;
}
.ai-channel-sidebar {
border-right: 0;
border-bottom: 1px solid var(--border-color, #e2e8f0);
max-height: 420px;
}
.ai-channel-list {
position: static;
display: grid;
grid-template-columns: repeat(auto-fit, minmax(220px, 1fr));
max-height: 360px;
.ai-channel-switcher {
align-items: stretch;
flex-direction: column;
}
.ai-channel-editor {
@@ -5035,19 +5347,40 @@ html[data-theme="dark"] .ai-channel-editor-form select {
@media (max-width: 640px) {
.ai-channel-manager-header,
.ai-channel-sidebar,
.ai-channel-switcher,
.ai-channel-editor {
padding-left: 14px;
padding-right: 14px;
}
.ai-channel-editor-actions {
.ai-channel-switcher-actions {
justify-content: flex-start;
}
.ai-channel-bulk-actions {
.ai-channel-header-actions {
justify-content: flex-start;
}
.ai-channel-switcher-field {
grid-template-columns: 1fr;
}
.ai-channel-form-section-head,
.ai-channel-form-grid,
.ai-channel-reasoning-grid {
grid-template-columns: 1fr;
}
.ai-channel-form-section-head,
.ai-channel-section-actions {
align-items: stretch;
flex-direction: column;
}
.ai-channel-section-actions {
justify-content: flex-start;
min-width: 0;
}
}
.chat-reasoning-field-label {
@@ -7059,6 +7392,16 @@ html[data-theme="dark"] .login-card .login-submit:disabled {
background: rgba(245, 124, 0, 0.09);
}
.timeline-item-finalization_check {
border-left-color: #f57c00;
background: linear-gradient(90deg, rgba(245, 124, 0, 0.1), rgba(96, 125, 139, 0.045));
}
.timeline-item-finalization_check .timeline-item-title {
color: #9a5200;
font-weight: 600;
}
.timeline-item-tool_calls_detected {
border-left-color: #0277bd;
background: rgba(2, 119, 189, 0.06);
@@ -9923,6 +10266,54 @@ html[data-theme="dark"] .robot-binding-service-hint-icon {
white-space: nowrap;
}
.settings-custom-select-option--probe .settings-custom-select-label {
flex: 1 1 auto;
}
.settings-custom-select-status {
display: inline-flex;
flex: 0 0 auto;
align-items: center;
gap: 5px;
max-width: 42%;
padding: 2px 6px;
border-radius: 999px;
background: var(--bg-secondary, #f5f6f8);
color: var(--text-secondary, #64748b);
font-size: 11px;
font-weight: 600;
line-height: 1.3;
}
.settings-custom-select-status-text {
overflow: hidden;
text-overflow: ellipsis;
white-space: nowrap;
}
.settings-custom-select-status-dot {
flex: 0 0 auto;
width: 6px;
height: 6px;
border-radius: 999px;
background: currentColor;
}
.settings-custom-select-status.ready {
background: color-mix(in srgb, var(--success-color, #38a169) 11%, transparent);
color: var(--success-color, #38a169);
}
.settings-custom-select-status.failed {
background: color-mix(in srgb, var(--danger-color, #e53e3e) 10%, transparent);
color: var(--danger-color, #e53e3e);
}
.settings-custom-select-status.testing {
background: color-mix(in srgb, var(--accent-color, #0066ff) 10%, transparent);
color: var(--accent-color, #0066ff);
}
.form-group input:not([type="checkbox"]):not([type="radio"]):focus,
.form-group select:focus {
outline: none;
@@ -22597,6 +22988,18 @@ tr.mcp-stats-tool-row[data-tool-name]:focus-visible {
font-weight: 500;
color: var(--text-secondary);
}
.webshell-ai-timeline-finalization_check {
border-left: 3px solid #f57c00;
padding-left: 10px;
background: linear-gradient(90deg, rgba(245, 124, 0, 0.08), transparent);
}
.webshell-ai-timeline-finalization_check .webshell-ai-timeline-title {
color: #9a5200;
font-weight: 600;
}
.webshell-ai-timeline-msg {
margin-top: 4px;
padding-left: 0;
@@ -22774,6 +23177,11 @@ tr.mcp-stats-tool-row[data-tool-name]:focus-visible {
background: var(--bg-secondary);
border: 1px solid var(--border-color);
}
.webshell-ai-msg.assistant.webshell-ai-candidate-output {
border-color: rgba(245, 124, 0, 0.28);
background: linear-gradient(90deg, rgba(245, 124, 0, 0.08), rgba(245, 124, 0, 0.035));
box-shadow: 0 6px 16px rgba(245, 124, 0, 0.08);
}
.webshell-ai-msg.assistant.webshell-ai-msg-error {
max-width: 72%;
border-color: rgba(220, 53, 69, 0.35);
@@ -35862,12 +36270,42 @@ html[data-theme="dark"] .timeline-item-user_interrupt_continue {
background: rgba(251, 191, 36, 0.08);
}
html[data-theme="dark"] .timeline-item-finalization_check {
background: linear-gradient(90deg, rgba(251, 191, 36, 0.1), rgba(30, 41, 59, 0.18));
border-left-color: #fbbf24;
}
html[data-theme="dark"] .timeline-item-finalization_check .timeline-item-title,
html[data-theme="dark"] .webshell-ai-timeline-finalization_check .webshell-ai-timeline-title {
color: #fbbf24;
}
html[data-theme="dark"] .message.assistant .message-bubble {
background: #111827;
color: var(--text-primary);
border-color: var(--border-color);
}
html[data-theme="dark"] .message.assistant.assistant-not-finalized .message-bubble {
border-color: rgba(251, 191, 36, 0.24);
border-left-color: #fbbf24;
background: linear-gradient(90deg, rgba(251, 191, 36, 0.08), rgba(17, 24, 39, 0.9));
box-shadow: 0 8px 22px rgba(0, 0, 0, 0.22);
}
html[data-theme="dark"] .message.assistant.assistant-not-finalized .message-bubble strong:first-child {
color: #fbbf24;
}
html[data-theme="dark"] .webshell-ai-timeline-finalization_check {
border-left-color: #fbbf24;
background: linear-gradient(90deg, rgba(251, 191, 36, 0.08), rgba(17, 24, 39, 0.12));
}
html[data-theme="dark"] .webshell-ai-msg.assistant.webshell-ai-candidate-output {
background: linear-gradient(90deg, rgba(251, 191, 36, 0.08), rgba(17, 24, 39, 0.12));
}
html[data-theme="dark"] .message-copy-btn {
background: #1f2937;
border-color: #334155;
@@ -38401,6 +38839,26 @@ html[data-theme="dark"] #page-settings .audit-custom-select-option.is-selected {
color: #60a5fa !important;
}
html[data-theme="dark"] #page-settings .settings-custom-select-status {
background: rgba(148, 163, 184, 0.12);
color: #94a3b8;
}
html[data-theme="dark"] #page-settings .settings-custom-select-status.ready {
background: rgba(52, 211, 153, 0.14);
color: #34d399;
}
html[data-theme="dark"] #page-settings .settings-custom-select-status.failed {
background: rgba(248, 113, 113, 0.14);
color: #f87171;
}
html[data-theme="dark"] #page-settings .settings-custom-select-status.testing {
background: rgba(96, 165, 250, 0.14);
color: #60a5fa;
}
/* Chat @ tool mention panel dark theme. */
html[data-theme="dark"] .mention-suggestions {
background: #111827 !important;
Binary file not shown.

Before

Width:  |  Height:  |  Size: 85 KiB

After

Width:  |  Height:  |  Size: 6.6 KiB

+31 -5
View File
@@ -1106,6 +1106,7 @@
"importValidRows": "Import valid rows",
"importValidRowsCount": "Import {{count}} valid rows",
"importPreviewSummary": "{{total}} rows: {{valid}} valid, {{invalid}} need attention",
"importBackendRowError": "Excel row {{row}} (submitted valid asset #{{index}}): {{message}}",
"previewLimited": "Showing the first 100 rows; all {{count}} rows will be processed",
"fileTypeInvalid": "Only .xlsx and .csv files are supported",
"fileTooLarge": "The file must not exceed 100 MB",
@@ -2603,23 +2604,43 @@
"aiChannelNew": "New",
"aiChannelCopy": "Copy",
"aiChannelDelete": "Delete",
"aiChannelHint": "Saved channels appear on the left. Saving writes to ai.channels; the default channel is used by new chats and tasks without an explicit channel.",
"aiChannelHint": "Use the dropdown to switch saved channels. Saving writes to ai.channels; the default channel is used by new chats and tasks without an explicit channel.",
"aiChannelSavedList": "Saved channels",
"aiChannelListAria": "AI channel list",
"aiChannelEditing": "Editing",
"aiChannelFormContext": "Editing the selected channel",
"aiChannelFormContextHint": "Saving the form updates this channel configuration.",
"aiChannelBulkProbe": "Probe all",
"aiChannelBulkProbeTitle": "Check whether all complete channels are available",
"aiChannelSelectAria": "Select {name}",
"aiChannelDefaultBadge": "Default",
"aiChannelReady": "Ready",
"aiChannelReadyWithLatency": "Ready{latency}",
"aiChannelComplete": "Complete",
"aiChannelDraft": "Incomplete",
"aiChannelDefaultMeta": "Default channel",
"aiChannelCustomMeta": "Custom channel",
"aiChannelOpenAICompat": "OpenAI compatible",
"aiChannelModelMissing": "Model missing",
"aiChannelName": "Channel name",
"aiChannelConnectionSection": "Connection",
"aiChannelConnectionHint": "Confirm provider, endpoint, key, and model first. Test connection uses these values.",
"aiChannelModelSection": "Model and limits",
"aiChannelModelHint": "The model name controls routing. Token limits control context and single-response output.",
"aiChannelLimitsSection": "Limits",
"aiChannelLimitsHint": "Token limits control the context window and single-response output.",
"aiChannelUntitled": "New Channel",
"aiChannelDeleteConfirm": "Delete AI channel \"{name}\"?",
"aiChannelSaved": "Channel saved",
"aiChannelDefaultSaved": "Default channel saved",
"aiChannelCount": "{count} channel(s) saved",
"aiChannelSaving": "Saving channel...",
"aiChannelNewUnsaved": "New channel is not saved yet. Fill it in, then click Save changes.",
"aiChannelCopyUnsaved": "Copied channel is not saved yet. Review it, then click Save changes.",
"aiChannelDeleted": "Channel deleted",
"aiChannelProbeNoComplete": "No complete channel to probe. Fill in Base URL, API Key, and Model first.",
"aiChannelProbing": "Probing {count} channel(s)...",
"aiChannelProbeDone": "Probe complete: {ok}/{total} ready",
"apiProvider": "API Provider",
"providerOpenAI": "OpenAI / OpenAI-compatible API",
"providerClaude": "Claude (Anthropic Messages API)",
@@ -2645,8 +2666,8 @@
"maxTotalTokensPlaceholder": "120000",
"maxTotalTokensHint": "Shared by memory compression and attack chain building. Default: 120000",
"maxCompletionTokens": "Max Output Tokens",
"maxCompletionTokensPlaceholder": "16384",
"maxCompletionTokensHint": "Maximum tokens for a single model response. Default: 16384",
"maxCompletionTokensPlaceholder": "32768",
"maxCompletionTokensHint": "Maximum tokens for a single model response. Default: 32768",
"openaiReasoningTitle": "Reasoning settings",
"openaiReasoningHint": "Default reasoning settings for this AI channel; chat Session settings can override them.",
"openaiReasoningProfile": "Wire profile",
@@ -2795,11 +2816,16 @@
"visionTimeout": "Timeout (seconds)",
"visionTestFillRequired": "Enter vision model and ensure API Key is available (or reuse OpenAI)",
"testConnection": "Test Connection",
"testFillRequired": "Please fill in API Key and Model first",
"testFillRequired": "Please fill in Base URL, API Key, and Model first",
"testing": "Testing connection...",
"testSuccess": "Connection successful",
"testFailed": "Connection failed",
"testError": "Test error"
"testError": "Test error",
"testErrorInvalidApiKey": "API Key is invalid or unauthorized. Check that the key is correct.",
"testErrorUnauthorized": "Authentication failed. Check the API Key.",
"testErrorForbidden": "Request denied. Check account permissions or model access.",
"testErrorModelUnavailable": "Model is unavailable or the model name is incorrect.",
"testErrorBaseUrl": "Base URL is unavailable. Check that the endpoint is correct."
},
"settingsTerminal": {
"title": "Terminal",
+31 -5
View File
@@ -1094,6 +1094,7 @@
"importValidRows": "导入有效数据",
"importValidRowsCount": "导入 {{count}} 条有效数据",
"importPreviewSummary": "共 {{total}} 行,{{valid}} 行有效,{{invalid}} 行需修正",
"importBackendRowError": "Excel 第 {{row}} 行(提交有效数据第 {{index}} 条):{{message}}",
"previewLimited": "仅展示前 100 行;提交时将处理全部 {{count}} 行",
"fileTypeInvalid": "仅支持 .xlsx 和 .csv 文件",
"fileTooLarge": "文件不能超过 100 MB",
@@ -2591,23 +2592,43 @@
"aiChannelNew": "新增",
"aiChannelCopy": "复制",
"aiChannelDelete": "删除",
"aiChannelHint": "已保存通道会显示在左侧;保存后写入 ai.channels,默认通道用于新对话和未指定通道的任务。",
"aiChannelHint": "通过下拉切换已保存通道;保存后写入 ai.channels,默认通道用于新对话和未指定通道的任务。",
"aiChannelSavedList": "已保存通道",
"aiChannelListAria": "AI 通道列表",
"aiChannelEditing": "正在编辑",
"aiChannelFormContext": "编辑当前选择的通道",
"aiChannelFormContextHint": "表单保存后会更新该通道配置。",
"aiChannelBulkProbe": "批量探活",
"aiChannelBulkProbeTitle": "检测全部完整通道是否可用",
"aiChannelSelectAria": "选择 {name}",
"aiChannelDefaultBadge": "默认",
"aiChannelReady": "可用",
"aiChannelReadyWithLatency": "可用{latency}",
"aiChannelComplete": "配置完整",
"aiChannelDraft": "待完善",
"aiChannelDefaultMeta": "默认通道",
"aiChannelCustomMeta": "自定义通道",
"aiChannelOpenAICompat": "OpenAI 兼容",
"aiChannelModelMissing": "未填写模型",
"aiChannelName": "通道名称",
"aiChannelConnectionSection": "连接信息",
"aiChannelConnectionHint": "先确认服务商、地址、密钥和模型,测试连接会使用这些信息。",
"aiChannelModelSection": "模型与额度",
"aiChannelModelHint": "模型名决定请求路由,Token 上限控制上下文和单次输出。",
"aiChannelLimitsSection": "额度设置",
"aiChannelLimitsHint": "Token 上限控制上下文窗口和单次输出。",
"aiChannelUntitled": "新通道",
"aiChannelDeleteConfirm": "确定删除 AI 通道「{name}」吗?",
"aiChannelSaved": "通道已保存",
"aiChannelDefaultSaved": "已设为默认通道",
"aiChannelCount": "已保存 {count} 个通道",
"aiChannelSaving": "正在保存通道...",
"aiChannelNewUnsaved": "新通道尚未保存,填写后点击「保存更改」。",
"aiChannelCopyUnsaved": "复制的通道尚未保存,确认后点击「保存更改」。",
"aiChannelDeleted": "通道已删除",
"aiChannelProbeNoComplete": "没有可探活的完整通道,请先填写 Base URL、API Key 和模型",
"aiChannelProbing": "正在探活 {count} 个通道...",
"aiChannelProbeDone": "探活完成:{ok}/{total} 可用",
"apiProvider": "API 提供商",
"providerOpenAI": "OpenAI / 兼容 OpenAI 协议",
"providerClaude": "Claude (Anthropic Messages API)",
@@ -2633,8 +2654,8 @@
"maxTotalTokensPlaceholder": "120000",
"maxTotalTokensHint": "内存压缩和攻击链构建共用此配置,默认 120000",
"maxCompletionTokens": "最大输出 Token 数",
"maxCompletionTokensPlaceholder": "16384",
"maxCompletionTokensHint": "单次模型回复的输出上限,默认 16384",
"maxCompletionTokensPlaceholder": "32768",
"maxCompletionTokensHint": "单次模型回复的输出上限,默认 32768",
"openaiReasoningTitle": "推理设置",
"openaiReasoningHint": "作为该 AI 通道的默认推理设置;对话页「会话设置」可覆盖。",
"openaiReasoningProfile": "线路 profile",
@@ -2783,11 +2804,16 @@
"visionTimeout": "超时(秒)",
"visionTestFillRequired": "请填写视觉模型,并确保 API Key 可用(可复用 OpenAI",
"testConnection": "测试连接",
"testFillRequired": "请先填写 API Key 和模型",
"testFillRequired": "请先填写 Base URL、API Key 和模型",
"testing": "测试中...",
"testSuccess": "连接成功",
"testFailed": "连接失败",
"testError": "测试出错"
"testError": "测试出错",
"testErrorInvalidApiKey": "API Key 无效或无权限,请检查密钥是否填写正确",
"testErrorUnauthorized": "认证失败,请检查 API Key",
"testErrorForbidden": "请求被拒绝,请检查账号权限或模型访问权限",
"testErrorModelUnavailable": "模型不可用或模型名不正确,请检查模型名称",
"testErrorBaseUrl": "Base URL 不可用,请检查地址是否正确"
},
"settingsTerminal": {
"title": "终端",
+27 -2
View File
@@ -57,6 +57,12 @@ function syncAssetSelect(selectOrId) {
if (typeof syncSettingsCustomSelect === 'function') syncSettingsCustomSelect(select);
}
function closeAssetCustomSelects() {
if (typeof closeAllSettingsCustomSelects === 'function') {
closeAllSettingsCustomSelects();
}
}
function assetT(key, fallback, options) {
if (window.i18next && typeof window.i18next.t === 'function') {
const value = window.i18next.t(key, options || {});
@@ -352,7 +358,8 @@ function renderAssetImportPreview() {
async function submitAssetImport() {
if (assetPageState.importBusy) return;
const assets = assetPageState.importRows.filter(row => !row.error).map(row => row.asset);
const validRows = assetPageState.importRows.filter(row => !row.error);
const assets = validRows.map(row => row.asset);
if (!assets.length) return;
setAssetImportError('');
setAssetImportBusy(true);
@@ -361,7 +368,7 @@ async function submitAssetImport() {
method: 'POST', headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ assets, source: 'manual-import', source_query: assetPageState.importFileName })
});
if (!response.ok) throw new Error(await assetEditorResponseError(response));
if (!response.ok) throw new Error(formatAssetImportSubmitError(await assetEditorResponseError(response), validRows));
const result = await response.json();
const invalid = assetPageState.importRows.length - assets.length;
closeAssetImport(true);
@@ -378,6 +385,20 @@ async function submitAssetImport() {
}
}
function formatAssetImportSubmitError(message, validRows) {
const text = String(message || '').trim();
const match = text.match(/^第\s*(\d+)\s*个资产无效[:]\s*(.+)$/);
if (!match) return text;
const assetNumber = Number(match[1]);
const row = Array.isArray(validRows) ? validRows[assetNumber - 1] : null;
if (!row || !row.rowNumber) return text;
return assetT('assets.importBackendRowError', `Excel 第 ${row.rowNumber} 行(提交有效数据第 ${assetNumber} 条): ${match[2]}`, {
row: row.rowNumber,
index: assetNumber,
message: match[2]
});
}
async function loadAssetOverview() {
try {
const response = await apiFetch('/api/assets/stats?days=' + assetOverviewDays);
@@ -874,6 +895,7 @@ async function openAssetProjectModal() {
}
function closeAssetProjectModal() {
closeAssetCustomSelects();
if (typeof closeAppModal === 'function') closeAppModal('asset-project-modal');
else document.getElementById('asset-project-modal').style.display = 'none';
}
@@ -922,6 +944,7 @@ function openAssetBulkEdit() {
}
function closeAssetBulkEdit() {
closeAssetCustomSelects();
if (typeof closeAppModal === 'function') closeAppModal('asset-bulk-edit-modal');
else document.getElementById('asset-bulk-edit-modal').style.display = 'none';
}
@@ -1124,6 +1147,7 @@ async function sendAssetsToChat(assets, template) {
input.value = message;
if (typeof adjustTextareaHeight === 'function') adjustTextareaHeight(input);
// 消息流可能持续很久;启动发送即可返回,让提交弹窗立即关闭。
window.__csNextChatFinalizationPolicy = { requireExecutionEvidence: true };
void sendMessage();
}
@@ -1279,6 +1303,7 @@ async function openAssetEditor(indexOrAsset) {
function closeAssetEditor(force) {
if (!force && assetPageState.editorDirty && !confirm(assetT('assets.discardChanges', '放弃尚未保存的更改吗?'))) return;
closeAssetCustomSelects();
if (typeof closeAppModal === 'function') closeAppModal('asset-editor-modal');
else document.getElementById('asset-editor-modal').style.display = 'none';
const returnFocus = assetPageState.editorReturnFocus;
+49 -36
View File
@@ -80,6 +80,7 @@ let chatAttachmentSeq = 0;
// 对话模式:eino_single = Eino ADK 单代理(/api/eino-agent/stream);deep / plan_execute / supervisor = Eino 多代理(/api/multi-agent/stream,请求体 orchestration
const AGENT_MODE_STORAGE_KEY = 'cyberstrike-chat-agent-mode';
const AGENT_MODE_CONVERSATION_STORAGE_PREFIX = 'cyberstrike-chat-agent-mode:conversation';
const AI_CHANNEL_STORAGE_KEY = 'cyberstrike-chat-ai-channel';
const REASONING_MODE_LS = 'cyberstrike-chat-reasoning-mode';
const REASONING_EFFORT_LS = 'cyberstrike-chat-reasoning-effort';
@@ -733,6 +734,44 @@ function chatAgentModeNormalizeStored(stored, cfg) {
return CHAT_AGENT_MODE_EINO_SINGLE;
}
function normalizeConversationAgentModeForUI(mode) {
const v = String(mode || '').trim().toLowerCase().replace(/-/g, '_');
if (chatAgentModeIsEinoSingle(v)) return v;
if (chatAgentModeIsEino(v)) {
return multiAgentAPIEnabled ? v : CHAT_AGENT_MODE_EINO_SINGLE;
}
return '';
}
function conversationAgentModeStorageKey(conversationId) {
return `${AGENT_MODE_CONVERSATION_STORAGE_PREFIX}:${String(conversationId || '').trim()}`;
}
function readConversationAgentModePreference(conversationId) {
if (!conversationId) return '';
try {
return normalizeConversationAgentModeForUI(localStorage.getItem(conversationAgentModeStorageKey(conversationId)) || '');
} catch (e) {
return '';
}
}
function saveConversationAgentModePreference(conversationId, mode) {
const normalized = normalizeConversationAgentModeForUI(mode);
if (!conversationId || !normalized) return;
try {
localStorage.setItem(conversationAgentModeStorageKey(conversationId), normalized);
} catch (e) { /* ignore */ }
}
function applyConversationAgentMode(conversationId, conversation) {
const saved = readConversationAgentModePreference(conversationId);
const fromServer = normalizeConversationAgentModeForUI(conversation && (conversation.agentMode || conversation.agent_mode));
const mode = saved || fromServer;
if (!mode) return;
syncAgentModeFromValue(mode);
}
if (typeof window !== 'undefined') {
window.csaiHitlGlobalToolWhitelist = window.csaiHitlGlobalToolWhitelist || [];
window.csaiHitlDefaultReviewer = window.csaiHitlDefaultReviewer || 'human';
@@ -1098,6 +1137,7 @@ function toggleAgentModePanel() {
function selectAgentMode(mode) {
const ok = chatAgentModeIsEinoSingle(mode) || chatAgentModeIsEino(mode);
if (!ok) return;
saveConversationAgentModePreference(currentConversationId, mode);
try {
localStorage.setItem(AGENT_MODE_STORAGE_KEY, mode);
} catch (e) { /* ignore */ }
@@ -1351,6 +1391,10 @@ async function sendMessage() {
conversationId: currentConversationId,
role: typeof getCurrentRole === 'function' ? getCurrentRole() : ''
};
if (window.__csNextChatFinalizationPolicy && typeof window.__csNextChatFinalizationPolicy === 'object') {
body.finalization = window.__csNextChatFinalizationPolicy;
window.__csNextChatFinalizationPolicy = null;
}
let streamConversationId = body.conversationId ? String(body.conversationId) : null;
const isStreamStillVisibleForRequest = function () {
if (!document.getElementById(progressId)) return false;
@@ -1405,6 +1449,7 @@ async function sendMessage() {
try {
const modeSel = document.getElementById('agent-mode-select');
let modeVal = modeSel ? modeSel.value : CHAT_AGENT_MODE_EINO_SINGLE;
saveConversationAgentModePreference(streamConversationId || currentConversationId, modeVal);
const useMulti = multiAgentAPIEnabled && chatAgentModeIsEino(modeVal);
const streamPath = useMulti ? '/api/multi-agent/stream' : '/api/eino-agent/stream';
if (useMulti && modeVal) {
@@ -3572,39 +3617,14 @@ function getCachedToolExecutionSummaries(messageElement) {
}
}
/**
* 过程摘要中的早期/快速工具结果可能没有 executionId但消息本身会按调用顺序保存 ID
* 合并两份数据避免渲染摘要时丢失可用的弹窗详情入口
*/
function mergeToolExecutionSummariesWithIds(summaries, executionIds) {
const normalizedSummaries = Array.isArray(summaries)
? summaries.map(normalizeToolExecutionSummaryForButton)
: [];
const normalizedIds = normalizeMcpExecutionIds(executionIds);
const claimedIds = new Set(
normalizedSummaries.map((item) => item.executionId).filter(Boolean)
);
const fallbackIds = normalizedIds.filter((id) => !claimedIds.has(id));
let fallbackIndex = 0;
return normalizedSummaries.map((item) => {
if (item.executionId || fallbackIndex >= fallbackIds.length) return item;
return {
...item,
executionId: fallbackIds[fallbackIndex++]
};
});
}
function selectToolExecutionSummariesForButtons(summaries, executionIds) {
const normalizedSummaries = Array.isArray(summaries)
? summaries.map(normalizeToolExecutionSummaryForButton)
: [];
const normalizedIds = normalizeMcpExecutionIds(executionIds);
if (normalizedSummaries.length > 0) return normalizedSummaries;
if (normalizedIds.length === 0) return normalizedSummaries;
if (normalizedSummaries.length === 0) {
return normalizedIds.map((executionId) => normalizeToolExecutionSummaryForButton({ executionId }));
}
return mergeToolExecutionSummariesWithIds(normalizedSummaries, normalizedIds);
return normalizedIds.map((executionId) => normalizeToolExecutionSummaryForButton({ executionId }));
}
function setPendingToolExecutionSummaries(messageElement, summaries) {
@@ -3819,10 +3839,6 @@ async function findToolExecutionTimelineItem(messageElement, summary, index) {
if (!target && item.toolCallId) {
target = timeline.querySelector('[data-tool-call-id="' + cssEscapeValue(item.toolCallId) + '"]');
}
if (!target) {
const toolItems = timeline.querySelectorAll('.timeline-item-tool_call');
target = toolItems[index] || null;
}
if (!target && item.processDetailId && messageElement.dataset && messageElement.dataset.backendMessageId && typeof window.loadProcessDetailsPaginated === 'function') {
await window.loadProcessDetailsPaginated(messageElement.id, messageElement.dataset.backendMessageId, {
autoLoadAll: false,
@@ -3995,11 +4011,7 @@ async function openTaskToolExecutionDetail(messageElement, item, index) {
let detailItem = item;
if (!detailItem.executionId) {
const refreshedItem = await resolveToolExecutionSummaryForFocus(messageElement, '', index);
const mergedItems = mergeToolExecutionSummariesWithIds(
getCachedToolExecutionSummaries(messageElement),
getCachedMcpExecutionIds(messageElement)
);
detailItem = mergedItems[index] || refreshedItem || detailItem;
detailItem = refreshedItem || detailItem;
}
if (detailItem.executionId) {
await showMCPDetail(detailItem.executionId);
@@ -4878,6 +4890,7 @@ async function loadConversation(conversationId) {
if (typeof window.setCurrentRole === 'function') {
window.setCurrentRole(conversationRoleName || '默认');
}
applyConversationAgentMode(conversationId, conversation);
try {
window.currentConversationId = conversationId;
} catch (e) { /* ignore */ }
+1
View File
@@ -1334,6 +1334,7 @@ function scanFofaRow(encodedRowJson, clickEvent) {
}
if (autoSend) {
if (typeof sendMessage === 'function') {
window.__csNextChatFinalizationPolicy = { requireExecutionEvidence: true };
sendMessage();
} else {
alert(_t('infoCollect.noSendMessage'));
+122 -3
View File
@@ -198,6 +198,92 @@ function resolveFinalAssistantResponseText(finalMessage, streamState) {
return finalMessage;
}
function isFinalizedResponseData(data) {
return !!(data && data.finalized === true);
}
function hasFinalizationContract(data) {
if (!data || typeof data !== 'object') return false;
return Object.prototype.hasOwnProperty.call(data, 'finalized')
|| Object.prototype.hasOwnProperty.call(data, 'finalizable')
|| Object.prototype.hasOwnProperty.call(data, 'completionReason')
|| Object.prototype.hasOwnProperty.call(data, 'evidenceVerified')
|| Object.prototype.hasOwnProperty.call(data, 'missingChecks');
}
function finalizationCheckTitle(data) {
return isFinalizedResponseData(data) ? '最终回复检查通过' : '最终回复检查未通过';
}
function finalizationReasonLabel(reason, status) {
const key = String(reason || status || '').trim();
const labels = {
pending_tool_executions: '等待工具执行完成',
missing_execution_evidence: '缺少完成态证据',
awaiting_hitl: '等待人工确认',
empty_response: '未捕获到有效回复',
missing_finalization_contract: '缺少最终化证明',
in_progress: '仍在验证',
blocked: '检查未通过',
failed: '任务失败',
cancelled: '任务已取消',
verified: '已验证'
};
return labels[key] || key || '检查未通过';
}
function finalizationMissingCheckLabel(check) {
const s = String(check || '').trim();
if (!s) return '';
if (s.indexOf('tool execution still queued or running') !== -1) return '仍有工具执行未结束';
if (s.indexOf('execution evidence is required but no completed tool execution was recorded') !== -1) return '本轮要求执行证据,但没有 completed 工具记录';
if (s.indexOf('workflow is awaiting HITL approval') !== -1) return '工作流正在等待人工确认';
if (s.indexOf('assistant final text is empty') !== -1) return '未捕获到有效最终文本';
if (s.indexOf('agent run status is ') === 0) return '任务状态仍为 ' + s.replace('agent run status is ', '');
return s;
}
function compactStringList(values, limit) {
const arr = Array.isArray(values) ? values.filter(Boolean).map(String) : [];
const max = limit || 3;
if (arr.length <= max) return arr;
return arr.slice(0, max).concat('另 ' + (arr.length - max) + ' 项');
}
function finalizationNoticeMarkdown(responseData, eventMessage) {
const hasContract = hasFinalizationContract(responseData);
const reason = hasContract
? finalizationReasonLabel(responseData && responseData.completionReason, responseData && responseData.status)
: finalizationReasonLabel('missing_finalization_contract');
const lines = ['**仍在验证,暂不生成最终结论**', '', '状态:' + reason];
const pending = compactStringList(responseData && responseData.pendingExecutionIds, 3);
if (pending.length) {
lines.push('待完成工具:`' + pending.join('`, `') + '`');
}
const rawMissingChecks = responseData && responseData.missingChecks;
const missingChecks = Array.isArray(rawMissingChecks)
? rawMissingChecks
: (rawMissingChecks ? [rawMissingChecks] : []);
const missing = compactStringList(missingChecks.map(finalizationMissingCheckLabel).filter(Boolean), 3);
if (missing.length) {
lines.push('待完成检查:' + missing.join(''));
}
if (!hasContract && eventMessage != null && String(eventMessage).trim() !== '') {
lines.push('', '候选输出已移入过程详情,避免误判为最终结论。');
}
return lines.join('\n');
}
function markAssistantFinalizationState(assistantMessageId, responseData) {
const assistantElement = document.getElementById(assistantMessageId);
if (!assistantElement) return;
const finalized = isFinalizedResponseData(responseData);
assistantElement.dataset.finalized = finalized ? 'true' : 'false';
assistantElement.dataset.finalizationStatus = responseData && responseData.status ? String(responseData.status) : '';
assistantElement.classList.toggle('assistant-finalized', finalized);
assistantElement.classList.toggle('assistant-not-finalized', !finalized);
}
/**
* 主通道 response 结束时将流式占位条目固化为 planning与后端 flushResponsePlan 落库类型一致
* 避免 integrateProgressToMCPSection 快照前删除占位导致助手输出仅刷新后才出现
@@ -2440,6 +2526,26 @@ function handleStreamEvent(event, progressElement, progressId,
});
break;
case 'finalization_check':
const finalizationCheckData = event.data || {};
const finalizationCheckPassed = isFinalizedResponseData(finalizationCheckData);
addTimelineItem(timeline, 'finalization_check', {
title: finalizationCheckTitle(finalizationCheckData),
message: finalizationCheckPassed ? (event.message || '最终回复检查通过。') : finalizationNoticeMarkdown(finalizationCheckData, event.message),
data: event.data,
expanded: !finalizationCheckPassed
});
break;
case 'finalization_auto_continue':
addTimelineItem(timeline, 'progress', {
title: '继续验证',
message: event.message,
data: event.data,
expanded: false
});
break;
case 'hitl_interrupt':
const hitlTargetItem = findToolCallItemForHitl(timeline, event.data || {});
if (hitlTargetItem && hitlTargetItem.id) {
@@ -2958,7 +3064,12 @@ function handleStreamEvent(event, progressElement, progressId,
const streamState = responseStreamStateByProgressId.get(progressId);
const existingAssistantId = streamState?.assistantId || getAssistantId();
let assistantIdFinal = existingAssistantId;
const bubbleText = resolveFinalAssistantResponseText(event.message, streamState);
const responseFinalized = isFinalizedResponseData(responseData);
const responseHasFinalizationContract = hasFinalizationContract(responseData);
const resolvedResponseText = resolveFinalAssistantResponseText(event.message, streamState);
const bubbleText = responseFinalized
? resolvedResponseText
: finalizationNoticeMarkdown(responseData, event.message);
if (!assistantIdFinal) {
assistantIdFinal = addMessage('assistant', bubbleText, mcpIds, progressId);
@@ -2967,11 +3078,12 @@ function handleStreamEvent(event, progressElement, progressId,
setAssistantId(assistantIdFinal);
updateAssistantBubbleContent(assistantIdFinal, bubbleText, true);
}
markAssistantFinalizationState(assistantIdFinal, responseData);
// 将 response_start/response_delta 占位固化为 planning,与后端落库一致后再快照过程详情
if (streamState && streamState.itemId) {
finalizeMainResponseStreamItem(streamState, event.message, responseData);
} else if (timeline && bubbleText && String(bubbleText).trim() && !isEinoEmptyResponsePlaceholder(event.message)) {
finalizeMainResponseStreamItem(streamState, responseFinalized ? event.message : '', responseData);
} else if (timeline && responseFinalized && bubbleText && String(bubbleText).trim() && !isEinoEmptyResponsePlaceholder(event.message)) {
addTimelineItem(timeline, 'planning', {
title: typeof einoMainStreamPlanningTitle === 'function'
? einoMainStreamPlanningTitle(responseData)
@@ -2980,6 +3092,13 @@ function handleStreamEvent(event, progressElement, progressId,
data: responseData,
expanded: false
});
} else if (timeline && !responseFinalized && !responseHasFinalizationContract && resolvedResponseText && String(resolvedResponseText).trim()) {
addTimelineItem(timeline, 'finalization_check', {
title: '候选输出缺少最终化证明',
message: resolvedResponseText,
data: Object.assign({}, responseData, { missingFinalizationContract: true }),
expanded: true
});
}
// 最终回复时隐藏进度卡片(多代理模式下,迭代过程已完整展示)
+327 -66
View File
@@ -142,6 +142,19 @@ function syncSettingsCustomSelect(select) {
item.appendChild(check);
item.appendChild(label);
if (select.id === 'ai-channel-select') {
const probeStatus = option.dataset.probeStatus || '';
const probeMessage = option.dataset.probeMessage || '';
if (probeStatus) {
item.classList.add('settings-custom-select-option--probe', `probe-${probeStatus}`);
const status = document.createElement('span');
status.className = `settings-custom-select-status ${probeStatus}`;
status.innerHTML = `<span class="settings-custom-select-status-dot" aria-hidden="true"></span><span class="settings-custom-select-status-text"></span>`;
status.querySelector('.settings-custom-select-status-text').textContent = probeMessage || probeStatus;
item.appendChild(status);
}
}
reg.menu.appendChild(item);
});
}
@@ -2506,7 +2519,7 @@ function ensureAIConfigShape(cfg) {
function readAIChannelFromMainForm(id) {
const prev = currentConfig?.ai?.channels?.[id] || {};
const maxCompletionTokens = parseInt(document.getElementById('openai-max-completion-tokens')?.value, 10) || 16384;
const maxCompletionTokens = parseInt(document.getElementById('openai-max-completion-tokens')?.value, 10) || 32768;
return {
...prev,
name: (document.getElementById('ai-channel-name')?.value || '').trim() || prev.name || id,
@@ -2546,7 +2559,7 @@ function writeAIChannelToMainForm(id) {
const maxTokensEl = document.getElementById('openai-max-total-tokens');
if (maxTokensEl) maxTokensEl.value = ch.max_total_tokens || 120000;
const maxCompletionTokensEl = document.getElementById('openai-max-completion-tokens');
if (maxCompletionTokensEl) maxCompletionTokensEl.value = ch.max_completion_tokens || 16384;
if (maxCompletionTokensEl) maxCompletionTokensEl.value = ch.max_completion_tokens || 32768;
const r = ch.reasoning || {};
const modeEl = document.getElementById('openai-reasoning-mode');
if (modeEl) modeEl.value = ['auto', 'on', 'off'].includes(String(r.mode || '').toLowerCase()) ? String(r.mode).toLowerCase() : 'auto';
@@ -2557,6 +2570,100 @@ function writeAIChannelToMainForm(id) {
const allowEl = document.getElementById('openai-reasoning-allow-client');
if (allowEl) allowEl.checked = r.allow_client_reasoning !== false;
syncModelListFetchButtons();
syncAIChannelEditorPreview();
syncConnectionTestResultForSelectedAIChannel();
}
function displayAIChannelName(id, ch) {
const name = String(ch?.name || '').trim();
if ((name === '新通道' || name === 'New Channel') && !String(ch?.model || '').trim()) {
return settingsT('settingsBasic.aiChannelUntitled', name || id);
}
return name || id;
}
function aiChannelSelectLabel(id, ch) {
const marker = id === currentConfig?.ai?.default_channel ? ' *' : '';
return `${displayAIChannelName(id, ch)}${marker} · ${ch?.model || '-'}`;
}
function aiChannelOptionProbeMeta(id) {
const probe = aiChannelProbeResults[id];
if (!probe) return null;
const status = probe.status || '';
if (!['testing', 'ready', 'failed'].includes(status)) return null;
return {
status,
message: probe.message || (status === 'ready'
? settingsT('settingsBasic.aiChannelReady', '可用')
: status === 'testing'
? settingsT('settingsBasic.testing', '测试中...')
: settingsT('settingsBasic.testFailed', '连接失败'))
};
}
function updateAIChannelSelectOption(id) {
const select = document.getElementById('ai-channel-select');
if (!select || !currentConfig?.ai?.channels) return;
const channelId = normalizeAIChannelId(id || selectedAIChannelId || currentConfig.ai.default_channel || 'default');
const ch = currentConfig.ai.channels[channelId];
if (!ch) return;
const opt = Array.from(select.options).find((option) => option.value === channelId);
if (opt) {
opt.textContent = aiChannelSelectLabel(channelId, ch);
const probeMeta = aiChannelOptionProbeMeta(channelId);
if (probeMeta) {
opt.dataset.probeStatus = probeMeta.status;
opt.dataset.probeMessage = probeMeta.message;
} else {
delete opt.dataset.probeStatus;
delete opt.dataset.probeMessage;
}
if (channelId === selectedAIChannelId) {
select.value = channelId;
select.selectedIndex = opt.index;
}
}
if (typeof syncSettingsCustomSelect === 'function') {
syncSettingsCustomSelect(select);
}
}
function syncSelectedAIChannelUI() {
updateAIChannelSelectOption(selectedAIChannelId);
updateAIChannelEditorChrome(selectedAIChannelId);
renderAIChannelList();
syncConnectionTestResultForSelectedAIChannel();
}
function syncAIChannelEditorPreview() {
if (!currentConfig?.ai?.channels || !selectedAIChannelId || !currentConfig.ai.channels[selectedAIChannelId]) return;
const id = normalizeAIChannelId(selectedAIChannelId);
const prev = currentConfig.ai.channels[id] || {};
const next = readAIChannelFromMainForm(id);
const connectionChanged = ['provider', 'base_url', 'api_key', 'model'].some((key) => String(prev[key] || '') !== String(next[key] || ''));
if (connectionChanged) {
delete aiChannelProbeResults[id];
}
currentConfig.ai.channels[id] = next;
syncSelectedAIChannelUI();
}
function bindAIChannelEditorPreviewSync() {
const ids = [
'ai-channel-name',
'openai-provider',
'openai-api-key',
'openai-base-url',
'openai-model'
];
ids.forEach((fieldId) => {
const el = document.getElementById(fieldId);
if (!el || el.dataset.aiChannelPreviewBound === '1') return;
el.dataset.aiChannelPreviewBound = '1';
const eventName = el.tagName === 'SELECT' ? 'change' : 'input';
el.addEventListener(eventName, syncAIChannelEditorPreview);
});
}
function renderAIChannelSelect() {
@@ -2570,16 +2677,24 @@ function renderAIChannelSelect() {
const ch = currentConfig.ai.channels[id] || {};
const opt = document.createElement('option');
opt.value = id;
const marker = id === currentConfig.ai.default_channel ? ' *' : '';
opt.textContent = `${ch.name || id}${marker} · ${ch.model || '-'}`;
opt.textContent = aiChannelSelectLabel(id, ch);
const probeMeta = aiChannelOptionProbeMeta(id);
if (probeMeta) {
opt.dataset.probeStatus = probeMeta.status;
opt.dataset.probeMessage = probeMeta.message;
}
select.appendChild(opt);
});
selectedAIChannelId = selectedAIChannelId && currentConfig.ai.channels[selectedAIChannelId]
? selectedAIChannelId
: currentConfig.ai.default_channel;
select.value = selectedAIChannelId;
renderAIChannelList(ids);
updateAIChannelSelectOption(selectedAIChannelId);
if (typeof syncSettingsCustomSelect === 'function') {
syncSettingsCustomSelect(select);
}
updateAIChannelEditorChrome(selectedAIChannelId);
renderAIChannelList(ids);
const countLabel = typeof window.t === 'function'
? window.t('settingsBasic.aiChannelCount').replace('{count}', String(ids.length))
: `已保存 ${ids.length} 个通道`;
@@ -2621,7 +2736,7 @@ function renderAIChannelList(ids) {
checkbox.type = 'checkbox';
checkbox.className = 'ai-channel-bulk-check';
checkbox.checked = selectedAIChannelBulkIds.has(id);
checkbox.setAttribute('aria-label', `选择 ${ch.name || id}`);
checkbox.setAttribute('aria-label', settingsT('settingsBasic.aiChannelSelectAria', '选择 {name}').replace('{name}', displayAIChannelName(id, ch)));
checkbox.onclick = (event) => {
event.stopPropagation();
if (checkbox.checked) {
@@ -2631,11 +2746,12 @@ function renderAIChannelList(ids) {
}
item.classList.toggle('checked', checkbox.checked);
};
const displayName = displayAIChannelName(id, ch);
const defaultBadge = isDefault ? `<span class="ai-channel-badge">${escapeAIChannelHtml(settingsT('settingsBasic.aiChannelDefaultBadge', '默认'))}</span>` : '';
let statusText = isComplete
? settingsT('settingsBasic.aiChannelReady', '可用')
? settingsT('settingsBasic.aiChannelComplete', '配置完整')
: settingsT('settingsBasic.aiChannelDraft', '待完善');
let statusClass = isComplete ? 'ready' : 'draft';
let statusClass = isComplete ? 'complete' : 'draft';
if (probe) {
statusText = probe.message || statusText;
statusClass = probe.status || statusClass;
@@ -2645,7 +2761,7 @@ function renderAIChannelList(ids) {
body.innerHTML = `
<div class="ai-channel-list-main">
<span class="ai-channel-status-dot ${statusClass}" aria-hidden="true"></span>
<strong title="${escapeAIChannelHtml(ch.name || id)}">${escapeAIChannelHtml(ch.name || id)}</strong>
<strong title="${escapeAIChannelHtml(displayName)}">${escapeAIChannelHtml(displayName)}</strong>
${defaultBadge}
</div>
<div class="ai-channel-list-meta" title="${escapeAIChannelHtml(ch.model || '-')} · ${escapeAIChannelHtml(channelHostLabel(ch.base_url))}">${escapeAIChannelHtml(ch.model || '-')} · ${escapeAIChannelHtml(channelHostLabel(ch.base_url))}</div>
@@ -2672,19 +2788,36 @@ function updateAIChannelEditorChrome(id) {
const ai = ensureAIConfigShape(currentConfig || {});
const channelId = normalizeAIChannelId(id || ai.default_channel || 'default');
const ch = ai.channels[channelId] || {};
const isDefault = channelId === ai.default_channel;
const isComplete = !validateSelectedAIChannelPayload(ch);
const probe = aiChannelProbeResults[channelId] || null;
const title = document.getElementById('ai-channel-editor-title');
const meta = document.getElementById('ai-channel-editor-meta');
if (title) title.textContent = ch.name || channelId;
if (title) {
title.textContent = settingsT('settingsBasic.aiChannelFormContextHint', '表单保存后会更新该通道配置。');
}
if (meta) {
const parts = [
channelId === ai.default_channel
? settingsT('settingsBasic.aiChannelDefaultMeta', '默认通道')
: settingsT('settingsBasic.aiChannelCustomMeta', '自定义通道'),
ch.provider === 'claude' ? 'Claude' : settingsT('settingsBasic.aiChannelOpenAICompat', 'OpenAI 兼容'),
ch.model || settingsT('settingsBasic.aiChannelModelMissing', '未填写模型'),
channelHostLabel(ch.base_url)
].filter(Boolean);
meta.textContent = parts.join(' / ');
const provider = ch.provider === 'claude' ? 'Claude' : settingsT('settingsBasic.aiChannelOpenAICompat', 'OpenAI 兼容');
const statusText = probe?.message || (isComplete
? settingsT('settingsBasic.aiChannelComplete', '配置完整')
: settingsT('settingsBasic.aiChannelDraft', '待完善'));
const statusClass = probe?.status || (isComplete ? 'complete' : 'draft');
const chips = [
{
label: isDefault
? settingsT('settingsBasic.aiChannelDefaultMeta', '默认通道')
: settingsT('settingsBasic.aiChannelCustomMeta', '自定义通道'),
className: isDefault ? 'default' : ''
},
{ label: provider },
{ label: ch.model || settingsT('settingsBasic.aiChannelModelMissing', '未填写模型') },
{ label: channelHostLabel(ch.base_url) },
{ label: statusText, className: statusClass }
].filter((chip) => chip.label);
meta.innerHTML = chips.map((chip) => {
const className = chip.className ? ` ${escapeAIChannelHtml(chip.className)}` : '';
return `<span class="ai-channel-editor-chip${className}" title="${escapeAIChannelHtml(chip.label)}">${escapeAIChannelHtml(chip.label)}</span>`;
}).join('');
}
}
@@ -2699,6 +2832,41 @@ function validateSelectedAIChannelPayload(ch) {
return '';
}
function resolveSavedAIChannelId(ai, preferredId, preferredPayload) {
const channels = ai?.channels || {};
const normalizedPreferred = normalizeAIChannelId(preferredId || '');
if (normalizedPreferred && channels[normalizedPreferred]) return normalizedPreferred;
const payload = preferredPayload || {};
const targetName = String(payload.name || '').trim();
const targetModel = String(payload.model || '').trim();
const targetBaseUrl = String(payload.base_url || '').trim();
const targetProvider = String(payload.provider || '').trim();
const ids = Object.keys(channels).sort();
const matched = ids.find((id) => {
const ch = channels[id] || {};
return String(ch.name || '').trim() === targetName
&& String(ch.model || '').trim() === targetModel
&& String(ch.base_url || '').trim() === targetBaseUrl
&& String(ch.provider || '').trim() === targetProvider;
});
return matched || ai?.default_channel || ids[0] || normalizedPreferred || 'default';
}
async function refreshAIChannelsFromServer(preferredId, preferredPayload) {
const response = await apiFetch('/api/config');
if (!response.ok) return false;
currentConfig = await response.json();
currentConfig.ai = ensureAIConfigShape(currentConfig);
selectedAIChannelId = resolveSavedAIChannelId(currentConfig.ai, preferredId, preferredPayload);
renderAIChannelSelect();
writeAIChannelToMainForm(selectedAIChannelId);
if (typeof populateChatAIChannelSelect === 'function') {
populateChatAIChannelSelect(currentConfig.ai);
}
return true;
}
async function persistAIChannelsToServer(successMessage, options = {}) {
if (typeof requirePermission === 'function' && !requirePermission('config:write')) return false;
if (!currentConfig) currentConfig = {};
@@ -2714,7 +2882,7 @@ async function persistAIChannelsToServer(successMessage, options = {}) {
return false;
}
renderAIChannelSelect();
showAIChannelSaveHint('正在保存通道...', true);
showAIChannelSaveHint(settingsT('settingsBasic.aiChannelSaving', '正在保存通道...'), true);
try {
const shouldMergeLatest = options.mergeLatest !== false;
const latestResponse = shouldMergeLatest ? await apiFetch('/api/config') : null;
@@ -2744,17 +2912,7 @@ async function persistAIChannelsToServer(successMessage, options = {}) {
const error = await applyResponse.json().catch(() => ({}));
throw new Error(error.error || '应用通道失败');
}
const response = await apiFetch('/api/config');
if (response.ok) {
currentConfig = await response.json();
currentConfig.ai = ensureAIConfigShape(currentConfig);
selectedAIChannelId = currentConfig.ai.channels[id] ? id : currentConfig.ai.default_channel;
renderAIChannelSelect();
writeAIChannelToMainForm(selectedAIChannelId);
if (typeof populateChatAIChannelSelect === 'function') {
populateChatAIChannelSelect(currentConfig.ai);
}
}
await refreshAIChannelsFromServer(id, channelPayload);
showAIChannelSaveHint(successMessage || '通道已保存', true);
return true;
} catch (error) {
@@ -2768,7 +2926,7 @@ async function persistAIConfigOnlyToServer(successMessage) {
if (typeof requirePermission === 'function' && !requirePermission('config:write')) return false;
if (!currentConfig) return false;
currentConfig.ai = ensureAIConfigShape(currentConfig);
showAIChannelSaveHint('正在保存通道...', true);
showAIChannelSaveHint(settingsT('settingsBasic.aiChannelSaving', '正在保存通道...'), true);
try {
const updateResponse = await apiFetch('/api/config', {
method: 'PUT',
@@ -2784,9 +2942,7 @@ async function persistAIConfigOnlyToServer(successMessage) {
const error = await applyResponse.json().catch(() => ({}));
throw new Error(error.error || '应用通道失败');
}
if (typeof populateChatAIChannelSelect === 'function') {
populateChatAIChannelSelect(currentConfig.ai);
}
await refreshAIChannelsFromServer(selectedAIChannelId);
showAIChannelSaveHint(successMessage || '通道已保存', true);
return true;
} catch (error) {
@@ -2844,13 +3000,13 @@ function createAIChannelFromForm() {
base_url: '',
model: '',
max_total_tokens: 120000,
max_completion_tokens: 16384,
max_completion_tokens: 32768,
reasoning: { mode: 'auto', effort: '', profile: 'auto', allow_client_reasoning: true }
};
selectedAIChannelId = id;
renderAIChannelSelect();
writeAIChannelToMainForm(id);
showAIChannelSaveHint('新通道尚未保存,填写后点击「保存更改」。', true);
showAIChannelSaveHint(settingsT('settingsBasic.aiChannelNewUnsaved', '新通道尚未保存,填写后点击「保存更改」。'), true);
}
function copyAIChannelFromForm() {
@@ -2862,10 +3018,10 @@ function copyAIChannelFromForm() {
selectedAIChannelId = id;
renderAIChannelSelect();
writeAIChannelToMainForm(id);
showAIChannelSaveHint('复制的通道尚未保存,确认后点击「保存更改」。', true);
showAIChannelSaveHint(settingsT('settingsBasic.aiChannelCopyUnsaved', '复制的通道尚未保存,确认后点击「保存更改」。'), true);
}
function deleteSelectedAIChannel() {
async function deleteSelectedAIChannel() {
if (!currentConfig) return;
currentConfig.ai = ensureAIConfigShape(currentConfig);
const ids = Object.keys(currentConfig.ai.channels || {});
@@ -2883,10 +3039,21 @@ function deleteSelectedAIChannel() {
return;
}
delete currentConfig.ai.channels[id];
currentConfig.ai.default_channel = Object.keys(currentConfig.ai.channels).sort()[0];
delete aiChannelProbeResults[id];
selectedAIChannelBulkIds.delete(id);
const remainingIds = Object.keys(currentConfig.ai.channels || {}).sort();
if (!currentConfig.ai.channels[currentConfig.ai.default_channel]) {
currentConfig.ai.default_channel = remainingIds[0];
}
selectedAIChannelId = currentConfig.ai.default_channel || remainingIds[0];
renderAIChannelSelect();
writeAIChannelToMainForm(currentConfig.ai.default_channel);
persistAIChannelsToServer('通道已删除', { mergeLatest: false });
writeAIChannelToMainForm(selectedAIChannelId);
const saved = await persistAIConfigOnlyToServer(settingsT('settingsBasic.aiChannelDeleted', '通道已删除'));
if (saved) {
renderAIChannelSelect();
writeAIChannelToMainForm(selectedAIChannelId);
}
}
function selectedOrAllAIChannelIdsForProbe() {
@@ -2904,12 +3071,13 @@ async function probeSelectedAIChannels() {
if (typeof requirePermission === 'function' && !requirePermission('config:write')) return;
const ids = selectedOrAllAIChannelIdsForProbe();
if (!ids.length) {
alert('没有可探活的完整通道,请先填写 Base URL、API Key 和模型');
alert(settingsT('settingsBasic.aiChannelProbeNoComplete', '没有可探活的完整通道,请先填写 Base URL、API Key 和模型'));
return;
}
showAIChannelSaveHint(`正在探活 ${ids.length} 个通道...`, true);
showAIChannelSaveHint(settingsT('settingsBasic.aiChannelProbing', '正在探活 {count} 个通道...').replace('{count}', String(ids.length)), true);
ids.forEach((id) => {
aiChannelProbeResults[id] = { status: 'testing', message: '测试中...' };
aiChannelProbeResults[id] = { status: 'testing', message: settingsT('settingsBasic.testing', '测试中...') };
updateAIChannelSelectOption(id);
});
renderAIChannelList();
let okCount = 0;
@@ -2933,13 +3101,14 @@ async function probeSelectedAIChannels() {
if (response.ok && result.success) {
okCount += 1;
const latency = result.latency_ms ? ` ${result.latency_ms}ms` : '';
aiChannelProbeResults[id] = { status: 'ready', message: `可用${latency}` };
aiChannelProbeResults[id] = { status: 'ready', message: settingsT('settingsBasic.aiChannelReadyWithLatency', '可用{latency}').replace('{latency}', latency) };
} else {
aiChannelProbeResults[id] = { status: 'failed', message: (result.error || '连接失败') };
aiChannelProbeResults[id] = { status: 'failed', message: formatConnectionTestError(result.error || settingsT('settingsBasic.testFailed', '连接失败')).message };
}
} catch (error) {
aiChannelProbeResults[id] = { status: 'failed', message: error.message || '测试出错' };
aiChannelProbeResults[id] = { status: 'failed', message: formatConnectionTestError(error.message || settingsT('settingsBasic.testError', '测试出错')).message };
}
updateAIChannelSelectOption(id);
renderAIChannelList();
}
const workers = Array.from({ length: Math.min(AI_CHANNEL_PROBE_CONCURRENCY, ids.length) }, async function () {
@@ -2948,7 +3117,7 @@ async function probeSelectedAIChannels() {
}
});
await Promise.all(workers);
showAIChannelSaveHint(`探活完成:${okCount}/${ids.length} 可用`, okCount === ids.length);
showAIChannelSaveHint(settingsT('settingsBasic.aiChannelProbeDone', '探活完成:{ok}/{total} 可用').replace('{ok}', String(okCount)).replace('{total}', String(ids.length)), okCount === ids.length);
}
async function deleteCheckedAIChannels() {
@@ -2997,7 +3166,17 @@ if (typeof window !== 'undefined') {
window.deleteCheckedAIChannels = deleteCheckedAIChannels;
}
if (typeof document !== 'undefined' && !document.__aiChannelI18nBound) {
document.__aiChannelI18nBound = true;
document.addEventListener('languagechange', function () {
if (!currentConfig?.ai) return;
renderAIChannelSelect();
updateAIChannelEditorChrome(selectedAIChannelId || currentConfig.ai.default_channel);
});
}
function initModelListControls() {
bindAIChannelEditorPreviewSync();
const providerEl = document.getElementById('openai-provider');
if (providerEl && !providerEl.dataset.modelListBound) {
providerEl.dataset.modelListBound = '1';
@@ -3048,6 +3227,9 @@ function bindModelSelect(scope) {
if (!select.value) return;
const input = document.getElementById(inputId);
if (input) input.value = select.value;
if (scope === 'openai') {
syncAIChannelEditorPreview();
}
});
}
@@ -3381,10 +3563,10 @@ async function testHitlAuditModelConnection() {
const resultEl = document.getElementById('test-hitl-audit-model-result');
const cfg = collectHitlAuditModelEffectiveConfig();
if (!cfg.api_key || !cfg.model) {
if (!cfg.base_url || !cfg.api_key || !cfg.model) {
if (resultEl) {
resultEl.style.color = 'var(--danger-color, #e53e3e)';
resultEl.textContent = typeof window.t === 'function' ? window.t('settingsBasic.testFillRequired') : '请先填写 API Key 和模型';
resultEl.textContent = typeof window.t === 'function' ? window.t('settingsBasic.testFillRequired') : '请先填写 Base URL、API Key 和模型';
}
return;
}
@@ -3430,6 +3612,59 @@ async function testHitlAuditModelConnection() {
}
}
function formatConnectionTestError(errorText) {
const raw = String(errorText || '').trim() || settingsT('settingsBasic.testError', '测试出错');
return {
message: raw,
detail: raw
};
}
function setConnectionTestResult(resultEl, state, message, title) {
if (!resultEl) return;
resultEl.classList.remove('is-error', 'is-success', 'is-muted', 'is-visible');
resultEl.style.color = '';
resultEl.textContent = message || '';
resultEl.title = title || '';
if (message) {
resultEl.classList.add('is-visible', state || 'is-muted');
}
}
function syncConnectionTestResultForSelectedAIChannel() {
const resultEl = document.getElementById('test-openai-result');
if (!resultEl) return;
const channelId = normalizeAIChannelId(selectedAIChannelId || currentConfig?.ai?.default_channel || 'default');
const probe = aiChannelProbeResults[channelId];
if (!probe) {
setConnectionTestResult(resultEl, '', '');
return;
}
const state = probe.status === 'ready'
? 'is-success'
: probe.status === 'failed'
? 'is-error'
: 'is-muted';
let message = probe.message || '';
const fillRequiredMessage = settingsT('settingsBasic.testFillRequired', '请先填写 Base URL、API Key 和模型');
const failedPrefix = (typeof window.t === 'function' ? window.t('settingsBasic.testFailed') : '连接失败') + ': ';
if (probe.status === 'failed' && message && message !== fillRequiredMessage && !message.startsWith(failedPrefix)) {
message = failedPrefix + message;
}
setConnectionTestResult(resultEl, state, message);
}
function showConnectionTestFailure(resultEl, errorText) {
if (!resultEl) return;
const formatted = formatConnectionTestError(errorText);
setConnectionTestResult(
resultEl,
'is-error',
(typeof window.t === 'function' ? window.t('settingsBasic.testFailed') : '连接失败') + ': ' + formatted.message,
formatted.detail || formatted.message
);
}
// 测试OpenAI连接
async function testOpenAIConnection() {
const btn = document.getElementById('test-openai-btn');
@@ -3439,17 +3674,29 @@ async function testOpenAIConnection() {
const baseUrl = document.getElementById('openai-base-url').value.trim();
const apiKey = document.getElementById('openai-api-key').value.trim();
const model = document.getElementById('openai-model').value.trim();
const channelId = normalizeAIChannelId(selectedAIChannelId || currentConfig?.ai?.default_channel || 'default');
const isTestingSameChannel = () => normalizeAIChannelId(selectedAIChannelId || currentConfig?.ai?.default_channel || 'default') === channelId;
if (!apiKey || !model) {
resultEl.style.color = 'var(--danger-color, #e53e3e)';
resultEl.textContent = typeof window.t === 'function' ? window.t('settingsBasic.testFillRequired') : '请先填写 API Key 和模型';
if (!baseUrl || !apiKey || !model) {
const message = typeof window.t === 'function' ? window.t('settingsBasic.testFillRequired') : '请先填写 Base URL、API Key 和模型';
aiChannelProbeResults[channelId] = { status: 'failed', message };
if (isTestingSameChannel()) {
setConnectionTestResult(resultEl, 'is-error', message);
}
syncSelectedAIChannelUI();
return;
}
btn.style.pointerEvents = 'none';
btn.style.opacity = '0.5';
resultEl.style.color = 'var(--text-muted, #888)';
resultEl.textContent = typeof window.t === 'function' ? window.t('settingsBasic.testing') : '测试中...';
if (btn) {
btn.style.pointerEvents = 'none';
btn.style.opacity = '0.5';
}
const testingMessage = settingsT('settingsBasic.testing', '测试中...');
aiChannelProbeResults[channelId] = { status: 'testing', message: testingMessage };
if (isTestingSameChannel()) {
setConnectionTestResult(resultEl, 'is-muted', testingMessage);
}
syncSelectedAIChannelUI();
try {
const response = await apiFetch('/api/config/test-openai', {
@@ -3466,20 +3713,33 @@ async function testOpenAIConnection() {
const result = await response.json();
if (result.success) {
resultEl.style.color = 'var(--success-color, #38a169)';
const latency = result.latency_ms ? ` (${result.latency_ms}ms)` : '';
const modelInfo = result.model ? ` [${result.model}]` : '';
resultEl.textContent = (typeof window.t === 'function' ? window.t('settingsBasic.testSuccess') : '连接成功') + modelInfo + latency;
const message = (typeof window.t === 'function' ? window.t('settingsBasic.testSuccess') : '连接成功') + modelInfo + latency;
aiChannelProbeResults[channelId] = { status: 'ready', message };
if (isTestingSameChannel()) {
setConnectionTestResult(resultEl, 'is-success', message);
}
} else {
resultEl.style.color = 'var(--danger-color, #e53e3e)';
resultEl.textContent = (typeof window.t === 'function' ? window.t('settingsBasic.testFailed') : '连接失败') + ': ' + (result.error || '未知错误');
const message = formatConnectionTestError(result.error || '未知错误').message;
aiChannelProbeResults[channelId] = { status: 'failed', message };
if (isTestingSameChannel()) {
showConnectionTestFailure(resultEl, message);
}
}
} catch (error) {
resultEl.style.color = 'var(--danger-color, #e53e3e)';
resultEl.textContent = (typeof window.t === 'function' ? window.t('settingsBasic.testError') : '测试出错') + ': ' + error.message;
const message = formatConnectionTestError(error.message || '测试出错').message;
aiChannelProbeResults[channelId] = { status: 'failed', message };
if (isTestingSameChannel()) {
showConnectionTestFailure(resultEl, message);
}
} finally {
btn.style.pointerEvents = '';
btn.style.opacity = '';
updateAIChannelSelectOption(channelId);
syncSelectedAIChannelUI();
if (btn) {
btn.style.pointerEvents = '';
btn.style.opacity = '';
}
}
}
@@ -4388,3 +4648,4 @@ document.addEventListener('languagechange', function () {
window.initSettingsCustomSelects = initSettingsCustomSelects;
window.refreshSettingsCustomSelects = refreshSettingsCustomSelects;
window.closeAllSettingsCustomSelects = closeAllSettingsCustomSelects;
+77 -1
View File
@@ -1338,6 +1338,55 @@ function escapeHtmlAttr(s) {
return escapeHtml(s).replace(/"/g, '&quot;').replace(/'/g, '&#39;');
}
function webshellFinalizationReasonLabel(reason, status) {
var key = String(reason || status || '').trim();
var labels = {
pending_tool_executions: '等待工具执行完成',
missing_execution_evidence: '缺少完成态证据',
awaiting_hitl: '等待人工确认',
empty_response: '未捕获到有效回复',
missing_finalization_contract: '缺少最终化证明',
in_progress: '仍在验证',
blocked: '检查未通过',
failed: '任务失败',
cancelled: '任务已取消',
verified: '已验证'
};
return labels[key] || key || '检查未通过';
}
function webshellFinalizationMissingCheckLabel(check) {
var s = String(check || '').trim();
if (!s) return '';
if (s.indexOf('tool execution still queued or running') !== -1) return '仍有工具执行未结束';
if (s.indexOf('execution evidence is required but no completed tool execution was recorded') !== -1) return '本轮要求执行证据,但没有 completed 工具记录';
if (s.indexOf('workflow is awaiting HITL approval') !== -1) return '工作流正在等待人工确认';
if (s.indexOf('assistant final text is empty') !== -1) return '未捕获到有效最终文本';
if (s.indexOf('agent run status is ') === 0) return '任务状态仍为 ' + s.replace('agent run status is ', '');
return s;
}
function webshellFinalizationNotice(data, eventMessage, hasContract) {
var reason = hasContract
? webshellFinalizationReasonLabel(data && data.completionReason, data && data.status)
: webshellFinalizationReasonLabel('missing_finalization_contract');
var lines = ['仍在验证,暂不生成最终结论', '状态:' + reason];
var pending = Array.isArray(data && data.pendingExecutionIds) ? data.pendingExecutionIds.filter(Boolean).map(String) : [];
if (pending.length) {
lines.push('待完成工具:' + pending.slice(0, 3).join(', ') + (pending.length > 3 ? ' 等' : ''));
}
var missing = Array.isArray(data && data.missingChecks)
? data.missingChecks.map(webshellFinalizationMissingCheckLabel).filter(Boolean)
: [];
if (missing.length) {
lines.push('待完成检查:' + missing.slice(0, 2).join('') + (missing.length > 2 ? ' 等' : ''));
}
if (!hasContract && eventMessage) {
lines.push('候选输出已移入过程详情。');
}
return lines.join('\n');
}
function escapeSingleQuotedShellArg(value) {
var s = value == null ? '' : String(value);
return "'" + s.replace(/'/g, "'\\''") + "'";
@@ -3393,7 +3442,10 @@ function runWebshellAiSend(conn, inputEl, sendBtn, messagesContainer) {
message: message,
webshellConnectionId: conn.id,
conversationId: convId,
role: wsRole
role: wsRole,
finalization: {
requireExecutionEvidence: true
}
};
if (!convId) {
var wsPid = getWebshellAiProjectSelection(conn);
@@ -3465,6 +3517,8 @@ function runWebshellAiSend(conn, inputEl, sendBtn, messagesContainer) {
streamingTarget = '';
webshellStreamingTypingId += 1;
streamingTypingId = webshellStreamingTypingId;
assistantDiv.dataset.finalized = 'false';
assistantDiv.classList.add('webshell-ai-candidate-output');
assistantDiv.textContent = '…';
messagesContainer.scrollTop = messagesContainer.scrollHeight;
} else if (_et === 'response_delta') {
@@ -3485,6 +3539,23 @@ function runWebshellAiSend(conn, inputEl, sendBtn, messagesContainer) {
}
} else if (_et === 'response') {
var text = (_em != null && _em !== '') ? _em : (typeof _ed === 'string' ? _ed : '');
var finalized = !!(_ed && _ed.finalized === true);
var hasFinalizationContract = !!(_ed && (
Object.prototype.hasOwnProperty.call(_ed, 'finalized') ||
Object.prototype.hasOwnProperty.call(_ed, 'finalizable') ||
Object.prototype.hasOwnProperty.call(_ed, 'completionReason') ||
Object.prototype.hasOwnProperty.call(_ed, 'evidenceVerified') ||
Object.prototype.hasOwnProperty.call(_ed, 'missingChecks')
));
assistantDiv.dataset.finalized = finalized ? 'true' : 'false';
assistantDiv.classList.toggle('webshell-ai-candidate-output', !finalized);
assistantDiv.classList.toggle('webshell-ai-finalized-output', finalized);
if (!finalized && !hasFinalizationContract && text) {
appendTimelineItem('finalization_check', '候选输出缺少最终化证明', text, Object.assign({}, _ed || {}, { missingFinalizationContract: true }));
text = webshellFinalizationNotice(_ed || {}, text, false);
} else if (!finalized && hasFinalizationContract) {
text = webshellFinalizationNotice(_ed || {}, text, true);
}
if (text) {
streamingTarget = String(text);
webshellStreamingTypingId += 1;
@@ -3493,6 +3564,11 @@ function runWebshellAiSend(conn, inputEl, sendBtn, messagesContainer) {
}
// ─── Terminal events ───
} else if (_et === 'finalization_check') {
var finalizationOk = !!(_ed && _ed.finalized === true);
appendTimelineItem('finalization_check', finalizationOk ? '最终回复检查通过' : '最终回复检查未通过', finalizationOk ? (_em || '最终回复检查通过。') : webshellFinalizationNotice(_ed || {}, _em, true), _ed);
} else if (_et === 'finalization_auto_continue') {
appendTimelineItem('progress', '继续验证', _em, _ed);
} else if (_et === 'error' && _em) {
streamingTypingId += 1;
var errLabel = wsTOr('chat.error', '错误');
+132 -101
View File
@@ -4,8 +4,8 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>CyberStrikeAI</title>
<link rel="icon" type="image/png" href="/static/logo.png">
<link rel="shortcut icon" type="image/png" href="/static/favicon.ico">
<link rel="icon" type="image/x-icon" href="/static/favicon.ico?v=20260728">
<link rel="shortcut icon" type="image/x-icon" href="/static/favicon.ico?v=20260728">
<script>
(function () {
try {
@@ -3446,115 +3446,146 @@
<div class="ai-channel-manager-header">
<div>
<h4 data-i18n="settingsBasic.openaiConfig">AI 通道配置</h4>
<p id="ai-channel-save-hint" class="ai-channel-manager-hint" data-i18n="settingsBasic.aiChannelHint">已保存通道会显示在左侧;保存后写入 ai.channels,默认通道用于新对话和未指定通道的任务。</p>
<p id="ai-channel-save-hint" class="ai-channel-manager-hint" data-i18n="settingsBasic.aiChannelHint">通过下拉切换已保存通道;保存后写入 ai.channels,默认通道用于新对话和未指定通道的任务。</p>
</div>
<div class="ai-channel-header-actions">
<button type="button" class="btn-secondary" onclick="createAIChannelFromForm()" data-i18n="settingsBasic.aiChannelNew">新增</button>
<button type="button" class="btn-primary ai-channel-save-btn" onclick="saveSelectedAIChannel()" data-i18n="settingsBasic.aiChannelSave">保存更改</button>
</div>
<button type="button" class="btn-primary ai-channel-save-btn" onclick="saveSelectedAIChannel()" data-i18n="settingsBasic.aiChannelSave">保存更改</button>
</div>
<div class="ai-channel-manager-body">
<aside class="ai-channel-sidebar" aria-label="AI 通道列表" data-i18n="settingsBasic.aiChannelListAria" data-i18n-attr="aria-label">
<div class="ai-channel-sidebar-head">
<span data-i18n="settingsBasic.aiChannelSavedList">已保存通道</span>
<div class="ai-channel-bulk-actions">
<button type="button" class="ai-channel-bulk-btn" onclick="probeSelectedAIChannels()" title="检测所选或全部完整通道是否可用">批量探活</button>
<button type="button" class="ai-channel-bulk-btn danger" onclick="deleteCheckedAIChannels()" title="删除已勾选的非默认通道">删除所选</button>
<button type="button" class="ai-channel-icon-btn" onclick="createAIChannelFromForm()" title="新增通道" aria-label="新增通道">+</button>
</div>
<div class="ai-channel-switcher" aria-label="AI 通道选择" data-i18n="settingsBasic.aiChannelListAria" data-i18n-attr="aria-label">
<div class="ai-channel-switcher-field">
<label for="ai-channel-select" data-i18n="settingsBasic.aiChannelCurrent">当前通道</label>
<select id="ai-channel-select" class="ai-channel-switch-select" onchange="selectAIChannelForEditing(this.value)"></select>
</div>
<div class="ai-channel-switcher-actions">
<button type="button" class="btn-secondary" onclick="probeSelectedAIChannels()" data-i18n="settingsBasic.aiChannelBulkProbe" data-i18n-title="settingsBasic.aiChannelBulkProbeTitle" data-i18n-attr="title">批量探活</button>
<button type="button" class="btn-secondary" onclick="copyAIChannelFromForm()" data-i18n="settingsBasic.aiChannelCopy">复制</button>
<button type="button" class="btn-secondary" onclick="setSelectedAIChannelDefault()" data-i18n="settingsBasic.aiChannelSetDefault">设为默认</button>
<button type="button" class="btn-secondary danger" onclick="deleteSelectedAIChannel()" data-i18n="settingsBasic.aiChannelDelete">删除</button>
</div>
<select id="ai-channel-select" class="ai-channel-native-select" onchange="selectAIChannelForEditing(this.value)" aria-hidden="true" tabindex="-1"></select>
<div id="ai-channel-list" class="ai-channel-list" aria-live="polite"></div>
</aside>
</div>
<div class="ai-channel-editor">
<div class="ai-channel-editor-head">
<div>
<span class="ai-channel-editor-kicker" data-i18n="settingsBasic.aiChannelEditing">正在编辑</span>
<h5 id="ai-channel-editor-title">-</h5>
<p id="ai-channel-editor-meta">-</p>
</div>
<div class="ai-channel-editor-actions">
<button type="button" class="btn-secondary" onclick="setSelectedAIChannelDefault()" data-i18n="settingsBasic.aiChannelSetDefault">设为默认</button>
<button type="button" class="btn-secondary" onclick="copyAIChannelFromForm()" data-i18n="settingsBasic.aiChannelCopy">复制</button>
<button type="button" class="btn-secondary danger" onclick="deleteSelectedAIChannel()" data-i18n="settingsBasic.aiChannelDelete">删除</button>
<span class="ai-channel-editor-kicker" data-i18n="settingsBasic.aiChannelFormContext">编辑当前选择的通道</span>
<p id="ai-channel-editor-title" class="ai-channel-editor-title">-</p>
</div>
<div id="ai-channel-editor-meta" class="ai-channel-editor-meta" aria-live="polite"></div>
</div>
<div class="settings-form ai-channel-editor-form">
<div class="form-group">
<label for="ai-channel-name" data-i18n="settingsBasic.aiChannelName">通道名称</label>
<input type="text" id="ai-channel-name" placeholder="Qwen Max" maxlength="24" />
</div>
<div class="form-group">
<label for="openai-provider" data-i18n="settingsBasic.apiProvider">API 提供商</label>
<select id="openai-provider" style="width: 100%; padding: 0.5rem 0.75rem; border: 1px solid var(--border-color, #e2e8f0); border-radius: 6px; background: var(--card-bg, #fff); color: var(--text-color, #2d3748); font-size: 0.875rem;">
<option value="openai_compatible" data-i18n="settingsBasic.providerOpenAI">OpenAI / 兼容 OpenAI 协议</option>
<option value="claude" data-i18n="settingsBasic.providerClaude">Claude (Anthropic Messages API)</option>
</select>
</div>
<div class="form-group">
<label for="openai-base-url">Base URL <span style="color: red;">*</span></label>
<input type="text" id="openai-base-url" data-i18n="settingsBasic.openaiBaseUrlPlaceholder" data-i18n-attr="placeholder" placeholder="https://api.openai.com/v1" required />
</div>
<div class="form-group">
<label for="openai-api-key">API Key <span style="color: red;">*</span></label>
<input type="password" id="openai-api-key" data-i18n="settingsBasic.openaiApiKeyPlaceholder" data-i18n-attr="placeholder" placeholder="输入OpenAI API Key" required />
</div>
<div class="form-group">
<label for="openai-model"><span data-i18n="settingsBasic.model">模型</span> <span style="color: red;">*</span></label>
<div class="model-pick-row">
<input type="text" id="openai-model" class="model-pick-input" data-i18n="settingsBasic.modelPlaceholder" data-i18n-attr="placeholder" placeholder="gpt-4" required />
<select id="openai-model-select" class="model-pick-native" style="display: none;" title="" aria-hidden="true" tabindex="-1">
<option value="" disabled data-i18n="settingsBasic.modelsListSelectPlaceholder">请选择模型</option>
</select>
<a href="javascript:void(0)" id="fetch-openai-models-btn" class="model-pick-fetch-link" onclick="fetchModelList('openai')" data-i18n="settingsBasic.fetchModels">获取列表</a>
</div>
<small id="fetch-openai-models-hint" class="form-hint" style="display: none; font-size: 0.75rem; margin-top: 4px;"></small>
<span id="fetch-openai-models-result" style="font-size: 0.75rem; margin-top: 2px; display: block;"></span>
</div>
<div class="form-group">
<label for="openai-max-total-tokens"><span data-i18n="settingsBasic.maxTotalTokens">最大上下文 Token 数</span></label>
<input type="number" id="openai-max-total-tokens" data-i18n="settingsBasic.maxTotalTokensPlaceholder" data-i18n-attr="placeholder" placeholder="120000" min="1000" step="1000" />
<small style="color: var(--text-muted, #718096); font-size: 0.75rem;" data-i18n="settingsBasic.maxTotalTokensHint">内存压缩和攻击链构建共用此配置,默认 120000</small>
</div>
<div class="form-group">
<label for="openai-max-completion-tokens"><span data-i18n="settingsBasic.maxCompletionTokens">最大输出 Token 数</span></label>
<input type="number" id="openai-max-completion-tokens" data-i18n="settingsBasic.maxCompletionTokensPlaceholder" data-i18n-attr="placeholder" placeholder="16384" min="1" step="256" />
<small style="color: var(--text-muted, #718096); font-size: 0.75rem;" data-i18n="settingsBasic.maxCompletionTokensHint">单次模型回复的输出上限,默认 16384</small>
</div>
<div class="form-group">
<label data-i18n="settingsBasic.openaiReasoningTitle">推理设置</label>
<small class="form-hint" data-i18n="settingsBasic.openaiReasoningHint">作为该 AI 通道的默认推理设置;对话页「会话设置」可覆盖。</small>
<div style="display: flex; flex-wrap: wrap; gap: 10px; margin-top: 8px; align-items: center;">
<label for="openai-reasoning-mode" style="font-size: 0.8125rem;" data-i18n="chat.reasoningModeLabel">模式</label>
<select id="openai-reasoning-mode" style="min-width: 140px; padding: 0.35rem 0.5rem; border-radius: 6px; border: 1px solid var(--border-color, #e2e8f0);">
<option value="auto" data-i18n="chat.reasoningModeAuto">自动</option>
<option value="on" data-i18n="chat.reasoningModeOn">开启</option>
<option value="off" data-i18n="chat.reasoningModeOff">关闭</option>
</select>
<label for="openai-reasoning-effort" style="font-size: 0.8125rem;" data-i18n="chat.reasoningEffortLabel">强度</label>
<select id="openai-reasoning-effort" style="min-width: 140px; padding: 0.35rem 0.5rem; border-radius: 6px; border: 1px solid var(--border-color, #e2e8f0);">
<option value="" data-i18n="chat.reasoningEffortUnset">不指定</option>
<option value="low">low</option>
<option value="medium">medium</option>
<option value="high">high</option>
<option value="xhigh">xhigh</option>
<option value="max">max</option>
</select>
<label for="openai-reasoning-profile" style="font-size: 0.8125rem;" data-i18n="settingsBasic.openaiReasoningProfile">线路</label>
<select id="openai-reasoning-profile" style="min-width: 220px; padding: 0.35rem 0.5rem; border-radius: 6px; border: 1px solid var(--border-color, #e2e8f0);">
<option value="auto">auto</option>
<option value="deepseek_compat">deepseek_compat</option>
<option value="openai_compat">openai_compat</option>
<option value="output_config_effort">output_config_effort</option>
</select>
</div>
<label class="checkbox-label" style="margin-top: 8px;">
<input type="checkbox" id="openai-reasoning-allow-client" class="modern-checkbox" checked />
<span class="checkbox-custom"></span>
<span class="checkbox-text" data-i18n="settingsBasic.openaiReasoningAllowClient">允许对话页覆盖推理选项</span>
</label>
</div>
<div style="display: flex; align-items: center; gap: 8px; margin-top: 2px;">
<a href="javascript:void(0)" id="test-openai-btn" onclick="testOpenAIConnection()" style="font-size: 0.8125rem; color: var(--accent-color, #3182ce); text-decoration: none; cursor: pointer; user-select: none;" data-i18n="settingsBasic.testConnection">测试连接</a>
<span id="test-openai-result" style="font-size: 0.8125rem;"></span>
</div>
<section class="ai-channel-form-section">
<div class="ai-channel-form-section-head">
<div>
<h6 data-i18n="settingsBasic.aiChannelConnectionSection">连接信息</h6>
<p data-i18n="settingsBasic.aiChannelConnectionHint">先确认服务商、地址、密钥和模型,测试连接会使用这些信息。</p>
</div>
<div class="ai-channel-section-actions">
<button type="button" id="test-openai-btn" class="btn-secondary" onclick="testOpenAIConnection()" data-i18n="settingsBasic.testConnection">测试连接</button>
<span id="test-openai-result" class="form-inline-result connection-test-result"></span>
</div>
</div>
<div class="ai-channel-form-grid">
<div class="form-group">
<label for="ai-channel-name" data-i18n="settingsBasic.aiChannelName">通道名称</label>
<input type="text" id="ai-channel-name" placeholder="Qwen Max" maxlength="24" />
</div>
<div class="form-group">
<label for="openai-provider" data-i18n="settingsBasic.apiProvider">API 提供商</label>
<select id="openai-provider">
<option value="openai_compatible" data-i18n="settingsBasic.providerOpenAI">OpenAI / 兼容 OpenAI 协议</option>
<option value="claude" data-i18n="settingsBasic.providerClaude">Claude (Anthropic Messages API)</option>
</select>
</div>
<div class="form-group span-2">
<label for="openai-base-url">Base URL <span class="required-mark">*</span></label>
<input type="text" id="openai-base-url" data-i18n="settingsBasic.openaiBaseUrlPlaceholder" data-i18n-attr="placeholder" placeholder="https://api.openai.com/v1" required />
</div>
<div class="form-group span-2">
<label for="openai-api-key">API Key <span class="required-mark">*</span></label>
<input type="password" id="openai-api-key" data-i18n="settingsBasic.openaiApiKeyPlaceholder" data-i18n-attr="placeholder" placeholder="输入OpenAI API Key" required />
</div>
<div class="form-group span-2">
<label for="openai-model"><span data-i18n="settingsBasic.model">模型</span> <span class="required-mark">*</span></label>
<div class="model-pick-row">
<input type="text" id="openai-model" class="model-pick-input" data-i18n="settingsBasic.modelPlaceholder" data-i18n-attr="placeholder" placeholder="gpt-4" required />
<select id="openai-model-select" class="model-pick-native" style="display: none;" title="" aria-hidden="true" tabindex="-1">
<option value="" disabled data-i18n="settingsBasic.modelsListSelectPlaceholder">请选择模型</option>
</select>
<a href="javascript:void(0)" id="fetch-openai-models-btn" class="model-pick-fetch-link" onclick="fetchModelList('openai')" data-i18n="settingsBasic.fetchModels">获取列表</a>
</div>
<small id="fetch-openai-models-hint" class="form-hint" style="display: none;"></small>
<span id="fetch-openai-models-result" class="form-inline-result"></span>
</div>
</div>
</section>
<section class="ai-channel-form-section">
<div class="ai-channel-form-section-head">
<div>
<h6 data-i18n="settingsBasic.aiChannelLimitsSection">额度设置</h6>
<p data-i18n="settingsBasic.aiChannelLimitsHint">Token 上限控制上下文窗口和单次输出。</p>
</div>
</div>
<div class="ai-channel-form-grid">
<div class="form-group">
<label for="openai-max-total-tokens"><span data-i18n="settingsBasic.maxTotalTokens">最大上下文 Token 数</span></label>
<input type="number" id="openai-max-total-tokens" data-i18n="settingsBasic.maxTotalTokensPlaceholder" data-i18n-attr="placeholder" placeholder="120000" min="1000" step="1000" />
<small class="form-hint" data-i18n="settingsBasic.maxTotalTokensHint">内存压缩和攻击链构建共用此配置,默认 120000</small>
</div>
<div class="form-group">
<label for="openai-max-completion-tokens"><span data-i18n="settingsBasic.maxCompletionTokens">最大输出 Token 数</span></label>
<input type="number" id="openai-max-completion-tokens" data-i18n="settingsBasic.maxCompletionTokensPlaceholder" data-i18n-attr="placeholder" placeholder="16384" min="1" step="256" />
<small class="form-hint" data-i18n="settingsBasic.maxCompletionTokensHint">单次模型回复的输出上限,默认 16384</small>
</div>
</div>
</section>
<details class="ai-channel-form-section ai-channel-advanced-section">
<summary>
<span>
<strong data-i18n="settingsBasic.openaiReasoningTitle">推理设置</strong>
<small data-i18n="settingsBasic.openaiReasoningHint">作为该 AI 通道的默认推理设置;对话页「会话设置」可覆盖。</small>
</span>
</summary>
<div class="ai-channel-reasoning-grid">
<div class="form-group">
<label for="openai-reasoning-mode" data-i18n="chat.reasoningModeLabel">模式</label>
<select id="openai-reasoning-mode">
<option value="auto" data-i18n="chat.reasoningModeAuto">自动</option>
<option value="on" data-i18n="chat.reasoningModeOn">开启</option>
<option value="off" data-i18n="chat.reasoningModeOff">关闭</option>
</select>
</div>
<div class="form-group">
<label for="openai-reasoning-effort" data-i18n="chat.reasoningEffortLabel">强度</label>
<select id="openai-reasoning-effort">
<option value="" data-i18n="chat.reasoningEffortUnset">不指定</option>
<option value="low">low</option>
<option value="medium">medium</option>
<option value="high">high</option>
<option value="xhigh">xhigh</option>
<option value="max">max</option>
</select>
</div>
<div class="form-group">
<label for="openai-reasoning-profile" data-i18n="settingsBasic.openaiReasoningProfile">线路</label>
<select id="openai-reasoning-profile">
<option value="auto">auto</option>
<option value="deepseek_compat">deepseek_compat</option>
<option value="openai_compat">openai_compat</option>
<option value="output_config_effort">output_config_effort</option>
</select>
</div>
</div>
<label class="checkbox-label ai-channel-reasoning-toggle">
<input type="checkbox" id="openai-reasoning-allow-client" class="modern-checkbox" checked />
<span class="checkbox-custom"></span>
<span class="checkbox-text" data-i18n="settingsBasic.openaiReasoningAllowClient">允许对话页覆盖推理选项</span>
</label>
</details>
</div>
</div>
</div>
@@ -6645,7 +6676,7 @@
<script src="/static/js/dashboard.js"></script>
<script src="/static/js/chat-scroll.js"></script>
<script src="/static/js/monitor.js?v=20260723-1"></script>
<script src="/static/js/chat.js?v=20260723-1"></script>
<script src="/static/js/chat.js?v=20260724-1"></script>
<script src="/static/js/hitl.js"></script>
<script src="/static/js/settings.js?v=20260717-1"></script>
<script src="/static/js/audit-datetime-picker.js"></script>