代码审查修复: 依赖安全、COS桶名注释、去除函数包装、同步防重叠

Agent-Logs-Url: https://github.com/qinfendebingshuo/guanghulab/sessions/5fc8d967-00c4-4b70-9d49-bd775684c43b

Co-authored-by: qinfendebingshuo <207279273+qinfendebingshuo@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot] 2026-04-02 12:11:11 +00:00 committed by GitHub
parent 6df459247c
commit d76e27a20b
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
4 changed files with 21 additions and 20 deletions

View File

@ -476,6 +476,7 @@ function go(target){
if(target==='chars')renderChars(); if(target==='chars')renderChars();
if(target==='chapters')renderChapters(); if(target==='chapters')renderChapters();
if(target==='editor')renderEditor(); if(target==='editor')renderEditor();
if(target==='charEdit'&&editingCharId)renderCharEdit();
} }
window.go=go; window.go=go;
@ -776,7 +777,6 @@ document.getElementById('edSave').onclick=function(){
/* ════════════════════════════════════════ /* ════════════════════════════════════════
RENDER: CharEdit (on navigate) RENDER: CharEdit (on navigate)
════════════════════════════════════════ */ ════════════════════════════════════════ */
var origCharEditRender=null;
function renderCharEdit(){ function renderCharEdit(){
if(!editingCharId)return; if(!editingCharId)return;
var w=getWork(activeWorkId); var w=getWork(activeWorkId);
@ -790,14 +790,6 @@ function renderCharEdit(){
document.getElementById('ceTraits').value=c.traits||''; document.getElementById('ceTraits').value=c.traits||'';
document.getElementById('ceBackground').value=c.background||''; document.getElementById('ceBackground').value=c.background||'';
} }
// Hook into go() for charEdit page
var origGo=go;
go=function(t){
origGo(t);
if(t==='charEdit'&&editingCharId)renderCharEdit();
};
window.go=go;
/* ════════════════════════════════════════ /* ════════════════════════════════════════
THEME THEME
════════════════════════════════════════ */ ════════════════════════════════════════ */
@ -968,16 +960,17 @@ chatIn.onkeydown=function(e){if(e.key==='Enter'){e.preventDefault();send()}};
COS SYNC (团队内测用户 → COS) COS SYNC (团队内测用户 → COS)
════════════════════════════════════════ */ ════════════════════════════════════════ */
var cosSyncTimer=null; var cosSyncTimer=null;
var cosSyncing=false;
function syncToCOS(works){ function syncToCOS(works){
// 防抖:最多每10秒同步一次
clearTimeout(cosSyncTimer); clearTimeout(cosSyncTimer);
cosSyncTimer=setTimeout(function(){ cosSyncTimer=setTimeout(function(){
if(!usr.id)return; if(!usr.id||cosSyncing)return;
cosSyncing=true;
fetch('/api/cos/sync-works',{ fetch('/api/cos/sync-works',{
method:'POST', method:'POST',
headers:{'Content-Type':'application/json'}, headers:{'Content-Type':'application/json'},
body:JSON.stringify({userId:usr.id,works:works}) body:JSON.stringify({userId:usr.id,works:works})
}).catch(function(){/* 离线时静默失败,本地已保存 */}); }).then(function(){cosSyncing=false}).catch(function(){cosSyncing=false});
},10000); },10000);
} }
// 启动时尝试从COS恢复(团队用户) // 启动时尝试从COS恢复(团队用户)

View File

@ -14,7 +14,12 @@
'use strict'; 'use strict';
const https = require('https'); const https = require('https');
const smartRouter = require('./smart-router'); let smartRouter;
try {
smartRouter = require('./smart-router');
} catch (e) {
smartRouter = null;
}
// ─── 通感语言核心系统提示词 ─── // ─── 通感语言核心系统提示词 ───
const TCS_SYSTEM_PROMPT = `你是铸渊(Zhùyuān),光湖语言世界的代码守护人格体。 const TCS_SYSTEM_PROMPT = `你是铸渊(Zhùyuān),光湖语言世界的代码守护人格体。
@ -167,10 +172,10 @@ function callLLM(model, messages, temperature, maxTokens) {
*/ */
async function chat(userId, userMessage) { async function chat(userId, userMessage) {
// 1. 智能路由选择模型 // 1. 智能路由选择模型
const route = smartRouter.routeModel(userMessage, { const route = smartRouter ? smartRouter.routeModel(userMessage, {
messageCount: getUserContext(userId).messageCount, messageCount: getUserContext(userId).messageCount,
userId userId
}); }) : { model: 'deepseek-chat', modelName: 'DeepSeek-V3', reason: '默认', tier: 'economy', temperature: 0.7, maxTokens: 2000 };
// 2. 组装消息 // 2. 组装消息
const messages = assembleMessages(userId, userMessage); const messages = assembleMessages(userId, userMessage);
@ -191,7 +196,9 @@ async function chat(userId, userMessage) {
addMessage(userId, 'assistant', assistantMessage); addMessage(userId, 'assistant', assistantMessage);
// 6. 记录使用统计 // 6. 记录使用统计
smartRouter.recordUsage(route.model, usage.prompt_tokens, usage.completion_tokens); if (smartRouter) {
smartRouter.recordUsage(route.model, usage.prompt_tokens, usage.completion_tokens);
}
return { return {
message: assistantMessage, message: assistantMessage,
@ -238,8 +245,8 @@ function generateOfflineReply(userMessage) {
function getChatStats() { function getChatStats() {
return { return {
activeUsers: userContexts.size, activeUsers: userContexts.size,
modelUsage: smartRouter.getUsageStats(), modelUsage: smartRouter ? smartRouter.getUsageStats() : {},
pricing: smartRouter.getPricingTable() pricing: smartRouter ? smartRouter.getPricingTable() : {}
}; };
} }

View File

@ -18,7 +18,6 @@
const crypto = require('crypto'); const crypto = require('crypto');
const https = require('https'); const https = require('https');
const http = require('http');
const path = require('path'); const path = require('path');
const fs = require('fs'); const fs = require('fs');
@ -79,9 +78,10 @@ function generateSignature(method, pathname, headers, secretId, secretKey) {
/** /**
* 获取桶的完整域名 * 获取桶的完整域名
* 注意: bucketName需包含appid后缀,如 zy-core-bucket-1234567890
* 冰朔在腾讯云创建桶时的完整名称需配置在COS_CONFIG中
*/ */
function getBucketHost(bucketName, region) { function getBucketHost(bucketName, region) {
// 从bucket配置获取完整ID(包含appid)
return `${bucketName}.cos.${region}.myqcloud.com`; return `${bucketName}.cos.${region}.myqcloud.com`;
} }

View File

@ -153,6 +153,7 @@ function routeModel(userMessage, context = {}) {
function recordUsage(model, inputTokens, outputTokens) { function recordUsage(model, inputTokens, outputTokens) {
const pricing = MODEL_PRICING[model] || MODEL_PRICING['deepseek-chat']; const pricing = MODEL_PRICING[model] || MODEL_PRICING['deepseek-chat'];
// 价格单位: 元/百万token → cost = tokens * (元/百万token) / 1000000
const cost = (inputTokens * pricing.input + outputTokens * pricing.output) / 1000000; const cost = (inputTokens * pricing.input + outputTokens * pricing.output) / 1000000;
usageStats.totalCalls++; usageStats.totalCalls++;