mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-09-02 01:20:23 +08:00
* feat: add file-based admin settings panel at /admin
Settings saved in the panel are written to data/settings.json and
overlaid onto process.env, taking precedence over environment
variables and applying immediately without restart. Enable by setting
ADMIN_PASSWORD; on serverless platforms without persistent disk the
panel degrades to read-only.
* polish: admin panel UI improvements
- Provider logos in credential rows (shared ProviderLogo component,
extracted from model-config-dialog)
- Scroll-spy active state in the sidebar nav
- Green success state in the save bar that clears after a few seconds
- Wider content column (max-w-6xl) for less wasted space on desktop
* polish: admin panel section toggles and reorder
- Move Quota & Rate Limits to the end of the settings page
- Add enable switches to Observability and Quota sections; default off
with fields grayed out, auto-on when any field is already configured
* polish: make section enable switch more visible
Wrap the switch in a labeled pill ('Enabled'/'Disabled') with border
and background so the off state is clearly visible.
* refactor: derive admin registry from PROVIDER_INFO, simplify page state
- Provider options, labels, and base-URL placeholders now come from
PROVIDER_INFO instead of hand-copied lists (fixes SiliconFlow .com/.cn
placeholder drift; panel names now match the model-config dialog)
- Replace free-text subgroup strings + SUBGROUP_PROVIDERS reverse map
with a typed provider field on SettingDef
- Precompute SETTINGS_BY_GROUP and PROVIDER_SUBGROUPS at module level
- Merge justSaved into saveMessage, drop unused mainRef, hoist
fetchSettings out of the component, dedupe savedText logic
- Serialize from SETTINGS_REGISTRY directly; json validators in a map
instead of a hardcoded key check
- Make allowPrivateUrls a function so ALLOW_PRIVATE_URLS edits in the
admin panel apply without restart
* feat: graphical model management in admin panel
Replace the provider credential fields and raw AI_MODELS_CONFIG JSON
textarea with a Models section mirroring the in-app model settings UI:
provider instance list with logos, credential fields per provider type,
model add/remove with suggestions, per-model connectivity test, and a
default-provider star.
On save the server derives everything the runtime needs into
settings.json: credential env vars (with _2 suffixes for multiple
instances of one provider), AI_MODELS_CONFIG, and AI_PROVIDER/AI_MODEL
for the default. Secrets round-trip as masked markers and are never
sent back to the browser. The general settings registry now only
covers non-provider settings (generation, access, features,
observability, quota).
* fix: allow testing unsaved providers in admin panel
The test button previously looked up credentials by providerId in the
saved settings, so testing a newly added (unsaved) provider failed with
'Unknown provider or model'. The test endpoint now accepts the client's
current provider state; newly typed secrets are used as-is and masked
markers are resolved against the stored values, so testing works both
before and after saving.
* fix: merge env AI_MODELS_CONFIG with admin panel providers
Previously, saving in the admin panel wrote a complete AI_MODELS_CONFIG
into settings.json, which (by overlay precedence) replaced any config
from .env or ai-models.json — admins lost their env-configured models.
The panel no longer writes AI_MODELS_CONFIG. Instead its providers are
merged with the env baseline at read time in loadRawServerModelsConfig,
and panel credentials go to ADMIN_-prefixed env vars wired up via
apiKeyEnv/baseUrlEnv so they never shadow standard vars. Env-based
providers now appear read-only in the panel, name clashes are rejected,
and a panel default overrides the env default. data/ is now gitignored.
* fix: block global-credential providers already managed via env
Bedrock, Vertex AI, and Ollama credentials live in fixed env vars with
no apiKeyEnv redirection, so a panel instance of one of these would
silently override the credentials that env-configured models rely on.
The API now rejects saving such a provider when the env config already
uses that type, and the Add Provider dropdown disables it with a
'managed via env' note.
* fix: address admin panel review findings
- Security: test-model no longer resolves a stored secret when the
request's baseUrl/provider differs from the stored entry, closing a
path where a tampered baseUrl could exfiltrate a saved key
- Save failures are now visible: the save bar shows the error in red
(was masked by the persistent 'Unsaved changes' text), and per-field
validation errors from the settings API are surfaced under each field
- The Observability/Quota enable switch is now real: toggling off stages
deletion of the group's saved values, and the toggle no longer snaps
back to Enabled after saving
- Env provider's default star is hidden when a panel provider is the
active default (no more double star)
- Clearing a credential field reverts to the stored value instead of
silently deleting it; an explicit X button removes a stored secret
- Form inputs are disabled during an in-flight save
* refactor(admin): split 1549-line admin page into focused modules
Extract admin-shared.ts (types + fetch helper), setting-field.tsx
(registry-driven fields), and models-section.tsx (provider/model
manager) from page.tsx. Pure mechanical move, no behavior change.
* feat(admin): share credential fields with user dialog and localize panel
Extract ProviderCredentialsFields (display name + per-provider
credential inputs) used by both the user ModelConfigDialog and the
admin Models panel; secret input passed via renderSecret (plaintext
vs masked), test button via footer slot. Add full i18n for the admin
panel across en/zh/ja/zh-Hant, reusing modelConfig.* for shared parts.
* fix(admin): address Copilot review findings
- Reflect built-in defaults for boolean settings (ALLOW_PRIVATE_URLS
defaults on) and allow clearing a saved boolean back to default,
so the SSRF toggle matches actual runtime behavior.
- Harden JSON loading: filter settings values to strings only, and
schema-validate stored ADMIN_PROVIDERS entries, dropping malformed
ones instead of letting them reach runtime code.
- Set beforeunload returnValue so the unsaved-changes prompt shows in
all browsers; reject non-finite numbers in settings validation.
- Fix README/CN/JA docs that claimed the panel auto-generates
AI_MODELS_CONFIG (providers are merged at read time, not written).
- Add unit tests for corrupted-file value filtering and provider
schema validation.
* docs: move admin panel details to dedicated docs/{en,cn,ja}/admin-panel.md
The READMEs now carry a short blurb + link, matching the existing
per-topic docs (docker.md, ai-providers.md, ...). Removes the ~22-line
inline section and the duplicated data/settings.json mentions.
* fix(admin): address follow-up Copilot findings on the prior fixes
- loadAdminProviders now validates against a stored-shape schema where
secrets are plain strings, so a hand-edited ADMIN_PROVIDERS holding an
{isSet} marker is dropped instead of later crashing maskSecret().
- loadSettings guards against array values (typeof [] === 'object'),
which would otherwise overlay numeric keys onto process.env.
- Admin SecretInput uses the bare id so the shared component's
<Label htmlFor> stays associated (only one ProviderDetail mounts).
- Add tests: marker-secret rejection, array-values guard, bedrock
multi-secret round-trip.
184 lines
9.0 KiB
Plaintext
184 lines
9.0 KiB
Plaintext
# AI Provider Configuration
|
|
# AI_PROVIDER: Which provider to use
|
|
# Options: bedrock, openai, anthropic, google, vertexai, azure, ollama, openrouter, deepseek, siliconflow, gateway, novita
|
|
# Default: bedrock
|
|
AI_PROVIDER=bedrock
|
|
|
|
# AI_MODEL: The model ID for your chosen provider (REQUIRED)
|
|
AI_MODEL=global.anthropic.claude-sonnet-4-5-20250929-v1:0
|
|
|
|
# AWS Bedrock Configuration
|
|
# AWS_REGION=us-east-1
|
|
# AWS_ACCESS_KEY_ID=your-access-key-id
|
|
# AWS_SECRET_ACCESS_KEY=your-secret-access-key
|
|
# Note: Claude and Nova models support reasoning/extended thinking
|
|
# BEDROCK_REASONING_BUDGET_TOKENS=12000 # Optional: Claude reasoning budget in tokens (1024-64000)
|
|
# BEDROCK_REASONING_EFFORT=medium # Optional: Nova reasoning effort (low/medium/high)
|
|
|
|
# OpenAI Configuration
|
|
# OPENAI_API_KEY=sk-...
|
|
# OPENAI_BASE_URL=https://api.openai.com/v1 # Optional: Custom OpenAI-compatible endpoint
|
|
# OPENAI_ORGANIZATION=org-... # Optional
|
|
# OPENAI_PROJECT=proj_... # Optional
|
|
# Note: o1/o3/gpt-5 models automatically enable reasoning summary (default: detailed)
|
|
# OPENAI_REASONING_EFFORT=low # Optional: Reasoning effort (minimal/low/medium/high) - for o1/o3/gpt-5
|
|
# OPENAI_REASONING_SUMMARY=detailed # Optional: Override reasoning summary (none/brief/detailed)
|
|
|
|
# Anthropic (Direct) Configuration
|
|
# ANTHROPIC_API_KEY=sk-ant-... # Sent as `x-api-key` header
|
|
# ANTHROPIC_AUTH_TOKEN= # Alternative to ANTHROPIC_API_KEY; sent as `Authorization: Bearer` header (mutually exclusive)
|
|
# ANTHROPIC_BASE_URL=https://your-custom-anthropic/v1
|
|
# ANTHROPIC_THINKING_TYPE=enabled # Optional: Anthropic extended thinking (enabled)
|
|
# ANTHROPIC_THINKING_BUDGET_TOKENS=12000 # Optional: Budget for extended thinking in tokens
|
|
|
|
# Google Generative AI Configuration
|
|
# GOOGLE_GENERATIVE_AI_API_KEY=...
|
|
# GOOGLE_BASE_URL=https://generativelanguage.googleapis.com/v1beta # Optional: Custom endpoint
|
|
# GOOGLE_CANDIDATE_COUNT=1 # Optional: Number of candidates to generate
|
|
# GOOGLE_TOP_K=40 # Optional: Top K sampling parameter
|
|
# GOOGLE_TOP_P=0.95 # Optional: Nucleus sampling parameter
|
|
# Note: Gemini 2.5/3 models automatically enable reasoning display (includeThoughts: true)
|
|
# GOOGLE_THINKING_BUDGET=8192 # Optional: Gemini 2.5 thinking budget in tokens (for more/less thinking)
|
|
# GOOGLE_THINKING_LEVEL=high # Optional: Gemini 3 thinking level (low/high)
|
|
|
|
# Google Vertex AI Configuration (Enterprise GCP)
|
|
# For enterprise users needing data residency, VPC Service Controls, or GCP integration
|
|
# GOOGLE_VERTEX_API_KEY= # Required: Express Mode API key
|
|
# GOOGLE_VERTEX_BASE_URL=https://... # Optional: Custom endpoint URL
|
|
# Note: Gemini 2.5/3 models automatically enable reasoning display (includeThoughts: true)
|
|
# GOOGLE_VERTEX_THINKING_BUDGET=8192 # Optional: Gemini 2.5 thinking budget in tokens (1024-100000)
|
|
# GOOGLE_VERTEX_THINKING_LEVEL=high # Optional: Gemini 3 thinking level (minimal/low/medium/high)
|
|
|
|
# Azure OpenAI Configuration
|
|
# Configure endpoint using ONE of these methods:
|
|
# 1. AZURE_RESOURCE_NAME - SDK constructs: https://{name}.openai.azure.com/openai/v1{path}
|
|
# 2. AZURE_BASE_URL - SDK appends /v1{path} to your URL
|
|
# If both are set, AZURE_BASE_URL takes precedence.
|
|
# AZURE_RESOURCE_NAME=your-resource-name
|
|
# AZURE_API_KEY=...
|
|
# AZURE_BASE_URL=https://your-resource.openai.azure.com/openai # Alternative: Custom endpoint
|
|
# AZURE_REASONING_EFFORT=low # Optional: Azure reasoning effort (low, medium, high)
|
|
# AZURE_REASONING_SUMMARY=detailed
|
|
|
|
# Ollama Configuration (Local or Cloud)
|
|
# OLLAMA_BASE_URL=https://ollama.com/api # Optional, defaults to Ollama Cloud
|
|
# OLLAMA_API_KEY=your-ollama-cloud-api-key # Optional: For Ollama Cloud or authenticated remote instances
|
|
# OLLAMA_ENABLE_THINKING=true # Optional: Enable thinking for models that support it (e.g., qwen3)
|
|
|
|
# OpenRouter Configuration
|
|
# OPENROUTER_API_KEY=sk-or-v1-...
|
|
# OPENROUTER_BASE_URL=https://openrouter.ai/api/v1 # Optional: Custom endpoint
|
|
|
|
# DeepSeek Configuration
|
|
# DEEPSEEK_API_KEY=sk-...
|
|
# DEEPSEEK_BASE_URL=https://api.deepseek.com/v1 # Optional: Custom endpoint
|
|
|
|
# SiliconFlow Configuration (OpenAI-compatible)
|
|
# Base domain can be .com or .cn, defaults to https://api.siliconflow.com/v1
|
|
# SILICONFLOW_API_KEY=sk-...
|
|
# SILICONFLOW_BASE_URL=https://api.siliconflow.com/v1 # Optional: switch to https://api.siliconflow.cn/v1 if needed
|
|
|
|
# SGLang Configuration (OpenAI-compatible)
|
|
# SGLANG_API_KEY=your-sglang-api-key
|
|
# SGLANG_BASE_URL=http://127.0.0.1:8000/v1 # Your SGLang endpoint
|
|
|
|
# ModelScope Configuration
|
|
# MODELSCOPE_API_KEY=ms-...
|
|
# MODELSCOPE_BASE_URL=https://api-inference.modelscope.cn/v1 # Optional: Custom endpoint
|
|
|
|
# ByteDance Doubao Configuration (via Volcengine)
|
|
# DOUBAO_API_KEY=your-doubao-api-key
|
|
# DOUBAO_BASE_URL=https://ark.cn-beijing.volces.com/api/v3 # ByteDance Volcengine endpoint
|
|
|
|
# Vercel AI Gateway Configuration
|
|
# Get your API key from: https://vercel.com/ai-gateway
|
|
# Model format: "provider/model" e.g., "openai/gpt-4o", "anthropic/claude-sonnet-4-5"
|
|
# AI_GATEWAY_API_KEY=...
|
|
# AI_GATEWAY_BASE_URL=https://your-custom-gateway.com/v1/ai # Optional: Custom Gateway URL (for local dev or self-hosted Gateway)
|
|
# # If not set, uses Vercel default: https://ai-gateway.vercel.sh/v1/ai
|
|
|
|
# Langfuse Observability (Optional)
|
|
# Enable LLM tracing and analytics - https://langfuse.com
|
|
# LANGFUSE_PUBLIC_KEY=pk-lf-...
|
|
# LANGFUSE_SECRET_KEY=sk-lf-...
|
|
# LANGFUSE_BASEURL=https://cloud.langfuse.com # EU region, use https://us.cloud.langfuse.com for US
|
|
|
|
# Optional server-side multi-model configuration
|
|
# If set, points to a JSON file with server-provided models (see README for schema).
|
|
# Default: ./ai-models.json in project root
|
|
# AI_MODELS_CONFIG_PATH=/path/to/ai-models.json
|
|
|
|
# Temperature (Optional)
|
|
# Controls randomness in AI responses. Lower = more deterministic.
|
|
# Leave unset for models that don't support temperature (e.g., GPT-5.1 reasoning models)
|
|
# TEMPERATURE=0
|
|
|
|
# Access Control (Optional)
|
|
# ACCESS_CODE_LIST=your-secret-code,another-code
|
|
|
|
# Admin Panel (Optional)
|
|
# Set a password to enable the web admin panel at /admin, where most of the
|
|
# settings in this file can be edited at runtime (stored in data/settings.json,
|
|
# which takes precedence over environment variables).
|
|
# Leave unset to disable the admin panel entirely.
|
|
# ADMIN_PASSWORD=your-admin-password
|
|
# SETTINGS_FILE=./data/settings.json # Optional: custom settings file location
|
|
|
|
# Draw.io Configuration (Optional)
|
|
# NEXT_PUBLIC_DRAWIO_BASE_URL=https://embed.diagrams.net # Default: https://embed.diagrams.net
|
|
# Use this to point to a self-hosted draw.io instance
|
|
|
|
# Subdirectory Deployment (Optional)
|
|
# For deploying to a subdirectory (e.g., https://example.com/nextaidrawio)
|
|
# Set this to your subdirectory path with leading slash (e.g., /nextaidrawio)
|
|
# Leave empty for root deployment (default)
|
|
# NEXT_PUBLIC_BASE_PATH=/nextaidrawio
|
|
|
|
# PDF Input Feature (Optional)
|
|
# Enable PDF file upload to extract text and generate diagrams
|
|
# Enabled by default. Set to "false" to disable.
|
|
# ENABLE_PDF_INPUT=true
|
|
# NEXT_PUBLIC_MAX_EXTRACTED_CHARS=150000 # Max characters for PDF/text extraction (default: 150000)
|
|
|
|
# Security Settings (Optional)
|
|
# Allow private/internal URLs for reverse proxy setups (default: true)
|
|
# Set to "false" to block private IPs, localhost, and internal hostnames
|
|
# ALLOW_PRIVATE_URLS=false
|
|
|
|
# Self-hosted deployment (Optional)
|
|
# Self-hosted users may implement custom quota-management solutions,
|
|
# which triggers the client UI to display messages suggesting self-hosting or sponsorship.
|
|
# This switch allows self-hosted users to provide custom messages in response to a 429 code,
|
|
# in messageTokenSelfHosted, messageApiSelfHosted, and tipSelfHosted translation strings.
|
|
# NEXT_PUBLIC_SELFHOSTED=true
|
|
|
|
# Minimax Configuration (Optional)
|
|
# Get your API key from: https://platform.minimaxi.com/docs/guides/models-intro
|
|
# MINIMAX_API_KEY=your_minimax_api_key
|
|
# MINIMAX_BASE_URL=https://api.minimaxi.com/anthropic # Optional, default (China mainland)
|
|
|
|
# GLM Configuration (Optional)
|
|
# Get your API key from: https://open.bigmodel.cn/dev/api
|
|
# GLM_API_KEY=your_glm_api_key
|
|
# GLM_BASE_URL=https://open.bigmodel.cn/api/paas/v4 # Optional, default
|
|
|
|
# Qwen Configuration (Optional)
|
|
# Get your API key from: https://www.aliyun.com/product/bailian
|
|
# QWEN_API_KEY=your_qwen_api_key
|
|
# QWEN_BASE_URL=https://dashscope.aliyuncs.com/compatible-mode/v1 # Optional, default
|
|
|
|
# Kimi Configuration (Optional)
|
|
# Get your API key from: https://platform.moonshot.cn/
|
|
# KIMI_API_KEY=your_kimi_api_key
|
|
# KIMI_BASE_URL=https://api.moonshot.cn/v1 # Optional, default
|
|
|
|
# Qiniu Configuration (Optional)
|
|
# Get your API key from: https://www.qiniu.com/ai/models
|
|
# QINIU_API_KEY=your_qiniu_api_key
|
|
# QINIU_BASE_URL=https://api.qnaigc.com/v1 # Optional, default
|
|
|
|
# Novita AI Configuration (Optional)
|
|
# Get your API key from: https://novita.ai/dashboard/key
|
|
# NOVITA_API_KEY=your_novita_api_key
|
|
# NOVITA_BASE_URL=https://api.novita.ai/openai # Optional, default
|