Skip to content

v0.10.4

Choose a tag to compare

@Mars-Sea Mars-Sea released this 11 Sep 01:35
· 68 commits to main since this release

中文

✨ 新增

  • 终端界面现在有 Command Code 设置页(#28)— 在 dsh --profile dsh-tui 下打开 /settings 就能看到 Command Code:填 API key、改 API 地址、隐藏超出套餐的模型、设置模型白名单、切换当前账号和命令语言。API key 是只写字段,页面只显示「是否已配置」,内容直接存进凭据库、不会写进配置文件。此前只用终端的用户完全没有地方可以填 key。

🔧 修复

  • 工具读到的图片现在能被视觉模型看到了(#30)— 用 read_image 读取本地图片时,模型只收到文字说明、看不到画面,会回答「我看不到图片」。现在图片会随请求一起送达模型。
  • 取消登录现在真的会取消 — 在验证 key 的过程中取消,之前仍然会把 key 存下来并把状态改回成功。
  • 登录完成后再点一次「登录」会重新开始 — 之前会把上一次已经失效的回调地址原样返回,浏览器打开的是一个已经关闭的端口。
  • 保存设置不再误删账号条目 — 只在配置文件里写、页面上没有对应行的账号(以及它内联的 key),之前会被任何一次保存悄悄删掉。
  • 保存失败不再丢失已经输入的内容 — 账号备注和路由规则的修改之前会被静默还原,而且页面显示为「没有改动」,无法重试。
  • 「清理失效模型」按钮不再清空白名单 — 模型目录还没加载出来(或加载失败)时,之前点一下会把整个白名单清空。
  • API key 前后的空格不再破坏多账号轮换 — 之前限流状态会记录在一个后续查找不到的 key 上,导致同一个账号被反复尝试、账户卡片也不显示限流标记。

🔄 变更

  • 声明兼容 dsh 0.1.5-rc.1 — 插件在最新版 Harness 上可以正常从商店列出和安装。

🔒 安全

  • 写在配置里的明文 API key 不再随设置响应回传 — 之前手动写进配置文件的 key 会被原样发回浏览器,在「浏览器与 Host 不在同一台机器」的部署下等于发给了另一台机器。
  • 任意网页无法再取消进行中的登录 — 之前任何打开的页面都可以向本机回调端口发一个请求,把别人的登录流程打断并显示「授权被拒绝」。

📦 安装 / 升级

⚠️ dsh plugin update 可能不生效:pnpm ≥ 11 的 minimumReleaseAge 策略会拒绝刚发布的版本,并误报 "Already up to date"。

# 推荐:指定版本安装
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider@0.10.4

# 或卸载后重装
dsh plugin --profile web remove @mars-sea/dsh-commandcode-provider
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider

# 从 GitHub tag 安装
dsh plugin --profile web add github:Mars-Sea/dsh-commandcode-provider#v0.10.4

终端用户把上面的 web 换成 dsh-tui 即可;终端里的设置页就在 /settings → Command Code。
卸载重装不会丢失你的 API key(存放在 dsh 凭据库或 ~/.commandcode/auth.json)。


English

✨ Added

  • The terminal UI now has a Command Code settings page (#28) — under dsh --profile dsh-tui, open /settings to set the API key, change the API base, hide out-of-plan models, set a model allowlist, and pick the active account and command language. The key field is write-only: the page shows only whether one is configured, and what you type goes to the credential store rather than a settings file. Until now a terminal-only user had nowhere to enter a key at all.

🔧 Fixed

  • Images read by a tool are visible to Vision models again (#30) — when the agent opened a local image with read_image, the model received only the text description and answered that it could see no picture. The image now travels with the request.
  • Cancelling a login really cancels it — cancelling while the key was being validated still stored the key and flipped the state back to success.
  • Signing in again after a completed login starts fresh — it used to hand back the previous attempt's callback address, which pointed at a port that was already closed.
  • Saving the settings page no longer deletes account entries — accounts that exist only in the config file (and their inline keys), which have no row on the page, were silently removed by any save.
  • A failed save no longer throws away what you typed — account labels and routing-rule edits were silently reverted with the page reporting "no changes", leaving nothing to retry.
  • The "clean up stale models" button no longer empties the allowlist — while the model catalog had not loaded yet (or had failed to load), one click cleared the whole list.
  • Whitespace around an API key no longer breaks multi-account rotation — the rate-limit mark landed on a key nothing looked up again, so the same account was retried and the account card showed no mark.

🔄 Changed

  • Declared compatible with dsh 0.1.5-rc.1 — the plugin stays listable and installable from the store on the latest Harness release.

🔒 Security

  • A plaintext API key written into the config no longer rides a settings response — it was sent back to the browser verbatim, which on a remote-Host setup means another machine.
  • A web page can no longer cancel a login in progress — any open page could previously reach the local callback port and kill someone else's sign-in with an "authorization denied" message.

📦 Install / upgrade

⚠️ dsh plugin update may not take effect: pnpm ≥ 11's minimumReleaseAge policy rejects a freshly published version and misreports "Already up to date".

# Recommended: install the exact version
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider@0.10.4

# Or remove and reinstall
dsh plugin --profile web remove @mars-sea/dsh-commandcode-provider
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider

# Install from the GitHub tag
dsh plugin --profile web add github:Mars-Sea/dsh-commandcode-provider#v0.10.4

Terminal users: swap web for dsh-tui above; the settings page lives under /settings → Command Code.
Removing and reinstalling never loses your API key (it lives in the dsh credential store or ~/.commandcode/auth.json).