feat(xiaomi-mimo): server-assisted desktop login, five account clusters, v2.6 models

Reproduce the MiMo Desktop login surface server-side so headless/Docker
deployments can link a Xiaomi account without the Desktop client. The
account session (passToken) is captured during the proxied login and
stored per connection.

- Five account clusters (cn/sgp/ams/ru/in): per-region mimo-server host
  and SSO sid, unknown region falls back to sgp
- mimo-v2.6-pro/flash/pro-ultraspeed dual-route models: account-service
  route when desktop credentials exist, cloud API (sk- key) otherwise;
  drops obsolete mimo-x-*-preview ids
- Desktop ServiceTokenManager 2-phase handshake (single serviceLogin with
  target sid, raw 64-bit nonce preserved), per-region session cache
- reasoning_effort bridged to output_config.effort; i18n runtime now
  observes characterData mutations so React text rewrites get translated
- Security hardening on the login proxy: session travels only in the
  httpOnly cookie (never in the URL), proxy branch requires dashboard
  auth, authorization/proxy-authorization never forwarded upstream, and
  upstream Set-Cookie is not replayed onto the app origin
This commit is contained in:
wismyzhizi
2026-09-23 09:43:54 +07:00
committed by decolua
parent 6af26a9ee8
commit 910db749aa
16 changed files with 1687 additions and 352 deletions
+3
View File
@@ -191,6 +191,9 @@ function isPublicApi(pathname) {
return PUBLIC_API_PATHS.some((p) => pathname === p || pathname.startsWith(`${p}/`));
}
// Shared with src/proxy.js — the mimo login branch must respect dashboard auth.
export { isAuthenticated };
export const __test__ = {
isLocalRequest,
isPublicLlmApi,