Commit Graph

46 Commits

Author SHA1 Message Date
qcq01083097 cb25bc4149 feat: When console login is not performed, throw more explicit errors and prompts 2026-06-16 15:11:10 +08:00
qcq01083097 2ed513124e feat: Use command.skipDefaultApiKeySetup instead of NO_AUTH_SETUP to determine whether an API key is required 2026-06-16 14:59:14 +08:00
qcq01083097 83ea0dfd03 feat: Clear invalid remnants of the command "model list" 2026-06-16 13:58:34 +08:00
若麒 ef7aa493e0 chore: release 1.3.2
Bump bailian-cli / bailian-cli-core to 1.3.2, sync skill version, and
document the omni --audio HTTP 400 fix (#54) in CHANGELOG. Also add the
.ogg extension to the --audio help text and reference doc.
2026-06-12 18:33:36 +08:00
clh02467605 e67acc118f fix(omni): use input_audio instead of audio_url
Fixes #54
2026-06-12 17:34:41 +08:00
若麒 ada7ed32fb Merge remote-tracking branch 'origin/main' into fix/proxy-env-support-v2 2026-06-12 16:07:43 +08:00
若麒 a96f3a2adf refactor: remove now-unused region threading in help printing
After dropping the API Reference line, printCommandHelp no longer reads
region, so the --region/DASHSCOPE_REGION resolution done solely for help
output is dead code. Endpoint selection via loadConfig is untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-12 16:03:00 +08:00
qcq01083097 489ba4f843 feat: No longer expose API documentation 2026-06-12 15:35:00 +08:00
若麒 8a0de83c24 fix: honor HTTP_PROXY / HTTPS_PROXY / NO_PROXY env vars (#35)
Node's built-in fetch (undici) ignores proxy environment variables, so
bl always connected directly and failed with ECONNRESET behind a VPN or
corporate proxy. Install an EnvHttpProxyAgent as the global dispatcher at
startup, but only when a proxy variable is actually set — behavior is
unchanged otherwise. Lowercase variables take precedence over uppercase
(curl convention) and NO_PROXY is honored.

Values are trimmed and passed explicitly to work around undici reading
env vars with ??, where an empty lowercase variable (https_proxy="")
masks a configured uppercase one. Invalid proxy URLs fail with a clear
usage error instead of a stack trace, and the ECONNRESET hint now
suggests exporting HTTPS_PROXY.

Tests are fully offline and need no credentials: unit tests cover env
parsing, and the e2e test runs a minimal probe (setupProxyFromEnv + a
bare fetch) against a .invalid host through a local CONNECT proxy to
verify traffic routes through the proxy, NO_PROXY is honored, no
dispatcher is installed when unset, and invalid values error clearly.
2026-06-12 14:53:22 +08:00
clark-fc b36eaf34be Merge pull request #49 from modelstudioai/feat/knowledge-api-key
fix(core): 修复 Rerank 字段类型用于请求体中
2026-06-12 10:53:53 +08:00
zeyu.fz d20eea5c1c fix(core): 修复 Rerank 字段类型用于请求体中
- 将 Rerank 字段从单对象修改为对象数组以支持多重重排序配置
- 更新 API 类型定义中 Rerank 为数组类型
- 修正 CLI 命令中构造请求体时将单一 Rerank 包装为数组
- 确保传递给后端的 Rerank 参数格式正确匹配接口要求
2026-06-12 10:21:53 +08:00
故璃 a72f0508c3 Merge branch 'main' into feat/model-usage 2026-06-11 12:26:06 +08:00
故璃 8b4dceafab feat: update doc 2026-06-10 19:47:17 +08:00
故璃 418596b960 Merge branch 'main' into feat/model-usage 2026-06-10 16:05:37 +08:00
故璃 dd56b04569 feat: add usage/quota/workspace cli command 2026-06-10 16:04:39 +08:00
zeyu.fz 822c4e6bfe fix(cli): 更新知识检索参数兼容性提示 2026-06-10 14:32:40 +08:00
zeyu.fz f90ed8a0cc feat(cli): 优化知识检索命令的rerank参数支持和请求构造 2026-06-10 14:19:17 +08:00
zeyu.fz 3395858c96 fix(cli): 修复检索命令中的 rerank 参数字段名 2026-06-10 13:59:55 +08:00
zeyu.fz d5407ae39b Merge remote-tracking branch 'origin/main' into feat/knowledge-api-key 2026-06-09 15:29:50 +08:00
zeyu.fz 20704ff1c6 fix(cli): 优化鉴权逻辑以支持显式API-Key和AK/SK优先级
- 优先使用显式提供的API-Key进行鉴权
- 在无显式API-Key时优先采用显式AK/SK鉴权
- 保持对无显式鉴权信息情况下的自动鉴权兼容
- 重构鉴权判断逻辑以提高代码清晰度和可维护性
2026-06-09 15:25:15 +08:00
zeyu.fz 6317da8454 feat(cli): 重构知识库检索命令,支持API-KEY和AK/SK鉴权
- 增加API-KEY鉴权路径,采用DashScope协议(snake_case)请求后端接口
- 保留AK/SK鉴权路径,但打印废弃警告,采用PascalCase请求后端
- 命令参数调整,新增dense-similarity-top-k、sparse-similarity-top-k等API-KEY专用选项
- 废弃部分旧参数如顶层top-k,提醒用户改用rerank-top-n
- 统一输出格式以及静默模式下文本结果的打印逻辑优化
- 添加相关类型定义,完善请求与响应结构的类型支持
- CLI端增加dry-run模式,展示实际请求参数与地址
- E2E测试覆盖API-KEY和AK/SK两条路径,包含帮助提示、错误场景及关键参数测试
- 更新依赖的核心包导出与接口,新增knowledgeRetrieveEndpoint方法接口调用
2026-06-08 18:43:50 +08:00
qcq01083097 d75ddb407a feat: Version synchronization & automatic build generation skills 2026-06-08 17:12:25 +08:00
Gong Shiqi d17fdd7e6f Merge pull request #30 from modelstudioai/feat/model-recommend
add model recommend cli commend
2026-06-05 17:09:08 +08:00
故璃 e22dff3b3b feat: add model preferrence 2026-06-05 16:05:50 +08:00
Gong Shiqi 73acb39c2b Merge pull request #27 from modelstudioai/feat/mcp-command
Feat/mcp command
2026-06-05 16:01:53 +08:00
若麒 4ae68ef61e fix(mcp): let mcp commands handle auth after arg validation and dry-run check 2026-06-05 15:52:47 +08:00
故璃 a767bee41e feat: model recommend beta version 2026-06-05 13:56:24 +08:00
qcq01083097 99ef96d209 feat: Fix the null value verification of the flag 2026-06-05 11:14:17 +08:00
若麒 6683ff172c Merge branch 'main' into feat/mcp-command 2026-06-05 00:00:45 +08:00
qcq01083097 ce59e2bd08 feat: Deal with text redundancy of flag default values 2026-06-04 17:49:03 +08:00
qcq01083097 fa3d3a6905 feat: Unify the text format of flag default values 2026-06-04 17:40:22 +08:00
qcq01083097 ea37be0e30 feat: Add illegal flag verification 2026-06-04 17:36:47 +08:00
qcq01083097 f3c35c411b feat: Dealing with redundancy and semanticization of file names 2026-06-04 17:30:30 +08:00
qcq01083097 6436ca88eb fix: Fix the issue of the watermark being always on and address the issue of paired flags 2026-06-04 17:07:11 +08:00
若麒 73d9d7ef07 feat(cli): add bl mcp command group (list/tools/call)
- `bl mcp list` — list MCP servers enabled under the current Bailian
  account via console gateway PageList (always activated=1).
- `bl mcp tools <server-code>` — list tools exposed by a server.
- `bl mcp call <server-code>.<tool>` — invoke a tool. Accepts `--json`,
  repeatable `--arg k=v` (JSON-parsed when possible) and `--query` sugar;
  `--url` overrides the endpoint for non-Bailian MCPs.
- core: export `bailianMcpUrl(baseUrl, code)` building
  `/api/v1/mcps/<code>/mcp`; `McpClient` now takes a full URL.
- `bl search web` switches to `mcpWebSearchEndpoint` directly.
- e2e: `mcp.e2e.test.ts` covering help, dry-run, arg-merge semantics,
  invalid-input paths, and one live `tools/list` against WebSearch.
2026-06-03 19:00:51 +08:00
mamba 14371a0647 Merge pull request #5 from lhfer/claude/busy-noether-Rjbaz
security: harden credential handling, pipeline JS execution, and the HTTP/stream layer
2026-06-03 15:06:26 +08:00
clh02467605 a490969d58 feat(auth): add retry logic and error handling for API key validation 2026-06-02 16:29:43 +08:00
lishengzxc 64f7e71783 feat(auth): 支持在控制台登录时自动处理 API 密钥 2026-06-02 10:53:31 +08:00
lishengzxc c04deceb27 feat(auth): split console login into separate file and auto-request apikey
Extract console login logic to login-console.ts for better separation
of concerns. When no api_key is configured, append needapikey=true to
the console login URL so the frontend returns an apiKey in the callback.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-06-01 16:59:02 +08:00
Claude bb9f941849 fix(security): require script/js code to be a literal (block untrusted-code RCE)
script/js executes its `code` as host JavaScript (via new Function), and a step's
`code` is a *resolved* input — so it could be written as `{ $from: <chat-step> }`,
turning model/API output into the body of the executed function (untrusted data
-> arbitrary host code execution). Pipeline validation now requires script/js
`code` to be a literal string: any $from/expression-sourced code is rejected.

Authoring a literal script/js step remains supported (the pipeline file is the
trust boundary, like a shell/npm script). Combined with "dry-run never executes
$js", this closes the path where untrusted text reaches the JS sink.

Adds regression tests: $from-sourced code rejected, literal code accepted,
dry-run does not execute $js, getByJsonPointer blocks prototype/inherited keys,
and concurrency clamps to the maximum.

https://claude.ai/code/session_017ZGQCjwNQF5Pz96gLUnnG1
2026-05-29 12:44:48 +00:00
Claude 8b9986bb47 fix(security): harden pipeline planning, pointer traversal, and concurrency
- expressions: never execute $js during planning/dry-run. `pipeline run --dry-run`
  is the command a cautious user runs to preview an unfamiliar pipeline; it must
  not run embedded JavaScript. Planning now returns the expression placeholder
  instead of calling new Function.
- schema (getByJsonPointer): block __proto__/constructor/prototype and require
  own properties, so a crafted $from/$input path cannot pull object internals
  (e.g. constructor) out of step output and feed them downstream.
- scheduler: clamp --concurrency to a maximum (64) to bound fan-out so a single
  run cannot launch an unbounded number of concurrent API calls / downloads.

Note: the runtime new Function sinks in script/js and $js (arbitrary host code
execution) are intentionally left unchanged here — remediating them is a design
decision (sandbox vs. literal-only code) for the maintainers; see PR notes.

https://claude.ai/code/session_017ZGQCjwNQF5Pz96gLUnnG1
2026-05-29 12:34:24 +00:00
Claude 3e4f1f0ebf fix(security): stop leaking credentials and tighten on-disk permissions
- config set: mask api_key/access_token/access_key_id/access_key_secret in the
  confirmation echo. It previously printed the stored secret verbatim to stdout
  (CI logs, pipes, screen shares), unlike `config show` / `auth status` which
  already maskToken().
- http / knowledge retrieve: use maskToken() in --verbose request logs instead
  of printing the first 8 chars of the bearer token / AccessKey id.
- telemetry: write telemetry.jsonl with mode 0600 (was created world-readable
  by default), matching the other credential-area writers.
- ensureConfigDir: chmod 0700 after mkdir, so a pre-existing ~/.bailian created
  by an older build/another tool (where mkdir's mode is ignored) holding
  cleartext credentials gets locked down too. Best-effort; never fatal.

https://claude.ai/code/session_017ZGQCjwNQF5Pz96gLUnnG1
2026-05-29 12:34:19 +00:00
clh02467605 208b1ce459 feat(cli): update the default vision model to qwen3-vl-plus 2026-05-29 17:50:07 +08:00
clh02467605 03d1c48d41 feat(cli): update the default vision model to qwen3-vl-plus 2026-05-29 17:20:33 +08:00
clh02467605 ee8aed0edf feat(cli): update the default vision model to qwen3-vl-plus 2026-05-29 16:57:45 +08:00
若麒 1533e2013e Initial commit 2026-05-28 18:37:07 +08:00