feat: add local auth billing and usage management

This commit is contained in:
inman
2026-08-12 12:13:06 +08:00
parent f642b5e71f
commit 196fdde83f
119 changed files with 15695 additions and 2650 deletions

View File

@@ -11,48 +11,16 @@ ZHINIAN_LOG_DIR=
ZHINIAN_LOG_MAX_BYTES=5242880
ZHINIAN_PUBLIC_BASE_URL=http://127.0.0.1:3000
# Account login / Web SSO.
# Platform-owned account login.
# Production requires login by default. Set ZHINIAN_AUTH_REQUIRED=0 only for trusted local development.
ZHINIAN_AUTH_REQUIRED=auto
ZHINIAN_AUTH_BASE_URL=https://<gateway-domain>/auth
ZHINIAN_AUTH_CLIENT_ID=custom
ZHINIAN_AUTH_CLIENT_SECRET=custom
ZHINIAN_ADMIN_AUTH_CLIENT_ID=app
ZHINIAN_ADMIN_AUTH_CLIENT_SECRET=app
# Optional tenant for platform password login. Defaults to ZHINIAN_ORG_TENANT_ID when empty.
ZHINIAN_AUTH_TENANT_ID=
# Optional tenant for admin password login; leave empty for the default admin tenant.
ZHINIAN_ADMIN_AUTH_TENANT_ID=
ZHINIAN_AUTH_SCOPE=server
ZHINIAN_AUTH_ISSUER=https://pig4cloud.com
ZHINIAN_AUTH_PASSWORD_ENC_KEY=thanks,pig4cloud
ZHINIAN_AUTH_SESSION_SECRET=change-me-to-a-long-random-secret
# Comma-separated authorities that can access logs/settings/accounts.
ZHINIAN_ADMIN_AUTHORITIES=ROLE_ADMIN,sys_user_view,sys_log_view,sys_config_view
# Comma-separated usernames that can access logs/settings/accounts. Defaults include ceshiop.
ZHINIAN_ADMIN_USERS=ceshiop
# Optional overrides when endpoints do not follow AUTH_BASE defaults.
ZHINIAN_AUTH_AUTHORIZE_URL=
ZHINIAN_AUTH_TOKEN_URL=
ZHINIAN_AUTH_JWKS_URL=
ZHINIAN_AUTH_LOGOUT_URL=
# Organization/member management API from basic-capability-services-biz.
# Base URL should include the gateway/service prefix before /organization...
ZHINIAN_ORG_API_BASE_URL=
# Optional fallback token. Account management forwards the current logged-in access_token by default.
ZHINIAN_ORG_API_TOKEN=
ZHINIAN_STAFF_API_BASE_URL=
# Optional fallback token. If empty, uses the current logged-in access_token or ZHINIAN_ORG_API_TOKEN.
ZHINIAN_STAFF_API_TOKEN=
ZHINIAN_ORG_TENANT_ID=
ZHINIAN_ORG_ID=
# Optional path overrides when the gateway exposes organization APIs through wrapper routes.
ZHINIAN_ORG_LIST_PATH=
ZHINIAN_ORG_GROUP_LIST_PATH=
ZHINIAN_ORG_ROLE_LIST_PATH=
# Defaults to /adminOrganization/organizationMember/organizationMemberList through hotelStaff.
ZHINIAN_ORG_MEMBER_LIST_PATH=
ZHINIAN_BILLING_REQUIRED=1
ZHINIAN_BILLING_ACCOUNT_NAME=
ZHINIAN_BILLING_ACCOUNT_BANK=
ZHINIAN_BILLING_ACCOUNT_NUMBER=
ZHINIAN_BILLING_CONTACT=
# Run `npm run bootstrap:admin -- --phone 13800138000 --password 'change-me-now'` once to create the first super admin.
# Public API v1 and worker task management.
# Format: accountId:key,anotherAccount:anotherKey.
@@ -73,9 +41,8 @@ NEXT_PUBLIC_SUPABASE_URL=
NEXT_PUBLIC_SUPABASE_ANON_KEY=
SUPABASE_SERVICE_ROLE_KEY=
# Image creation engines by capability: jimeng or evolink.
# Image creation engine: jimeng, evolink, or bailian.
IMAGE_GENERATE_ENGINE=jimeng
IMAGE_INPAINT_ENGINE=jimeng
# Volcengine Visual API for Jimeng image capabilities.
VOLCENGINE_ACCESS_KEY_ID=
@@ -84,17 +51,14 @@ VOLCENGINE_REGION=cn-north-1
VOLCENGINE_SERVICE=cv
VOLCENGINE_VISUAL_ENDPOINT=https://visual.volcengineapi.com
JIMENG_IMAGE_GENERATE_46_REQ_KEY=jimeng_seedream46_cvtob
JIMENG_IMAGE_INPAINT_REQ_KEY=jimeng_image2image_dream_inpaint
JIMENG_IMAGE_UPSCALE_REQ_KEY=jimeng_i2i_seed3_tilesr_cvtob
# auto mocks image jobs when Volcengine credentials are missing.
JIMENG_VISUAL_MOCK=auto
# EvoLink GPT Image 2 relay for image generation and inpainting.
# EvoLink GPT Image 2 relay for image generation.
EVOLINK_API_KEY=
EVOLINK_BASE_URL=https://api.evolink.ai
EVOLINK_IMAGE_MODEL=gpt-image-2
EVOLINK_IMAGE_QUALITY=medium
EVOLINK_IMAGE_RESOLUTION=2K
# auto mocks EvoLink image jobs when EVOLINK_API_KEY is missing.
EVOLINK_MOCK=auto