Repository navigation
Sub2API 0.1.112-cli-tuple-lock
Pre-release
Pre-release
·
80 commits
to main
since this release
AI API Gateway Platform - 将 AI 订阅配额分发和管理
- Drop accept-language / sec-fetch-mode from forward whitelist; add
isClientHeaderForwardable with sec-* prefix denial as defense against
browser fingerprint headers leaking through. - Extend Fingerprint with AcceptEncoding + StainlessTimeout fields and make
ApplyUAFingerprint write the full version tuple (UA + Package-Version +
Runtime-Version + Accept-Encoding + Timeout) so passthrough no longer
produces UA=2.1.141 + Runtime=v23.x style internal mismatches. - Pin StainlessTimeout to the canonical real-CLI value (600) across all
platform profiles; reset on upgrade and in applyLockedProfile so cached
records never drift to client-inflated timeouts. - Record monotonic UA upgrades in Fingerprint.LastUpgrade (last event only)
for post-mortem inspection of version drift. - Add EmitsSessionID observation flag and ApplySessionIDHeader that injects
X-Claude-Code-Session-Id derived from body.metadata.user_id, keeping the
header consistent with the (possibly masked) body session identifier.
📥 Installation
Docker:
docker pull ghcr.io/easayliu/sub2api:0.1.112-cli-tuple-lockOne-line install (Linux):
curl -sSL https://raw.githubusercontent.com/easayliu/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.