From 432dbac0a09d1b9ad1c475a4f1de80010f50fa8f Mon Sep 17 00:00:00 2001 From: fylorn <249551762+fylorn@users.noreply.github.com> Date: Fri, 2 Oct 2026 00:18:20 +0800 Subject: [PATCH] Lite docs and page for 2026.10.0: five more clients, search, check-up, ID and card redaction - Features: the get-started checklist and hints; searching the whole history, including request and answer text; Pi, oh-my-pi, Grok Build, Qwen Code and Hermes Agent on the Clients and MCP pages, and DeepSeek Harness's web and desktop apps; the upstream Check-up tab; resident ID and bank card numbers in outbound redaction; the shared skills folder; showing hidden hints again. - Overview: twelve clients in one step, thirteen on the MCP page, ID and card numbers, history search. - Lite page: the client count (12), the client marquee, redaction and search in the feature copy. Co-Authored-By: Claude Opus 5.5 --- src/components/pages/LitePage.astro | 18 +++++++++++++++++- src/content/docs-lite/en/features.md | 16 ++++++++++------ src/content/docs-lite/en/overview.md | 8 ++++---- src/content/docs-lite/zh-CN/features.md | 16 ++++++++++------ src/content/docs-lite/zh-CN/overview.md | 8 ++++---- src/i18n/pages/lite.ts | 20 ++++++++++---------- 6 files changed, 55 insertions(+), 31 deletions(-) diff --git a/src/components/pages/LitePage.astro b/src/components/pages/LitePage.astro index d285d03..b10de07 100644 --- a/src/components/pages/LitePage.astro +++ b/src/components/pages/LitePage.astro @@ -83,7 +83,23 @@ const changelogHref = localePath(lang, "/changelog"); const feat = Object.fromEntries(c.features.items.map((item) => [item.id, item])) as Record; /** The four stops of the scroll story, in the order a request meets them */ const storyIds = ["routing", "security", "traffic", "overview"] as const; -const clients = ["Claude Code", "Codex", "Claude Desktop", "opencode", "Cursor", "Zed", "Aider", "DeepSeek Harness", "Continue", "Antigravity CLI"]; +const clients = [ + "Claude Code", + "Codex", + "Claude Desktop", + "opencode", + "Pi", + "oh-my-pi", + "Grok Build", + "Qwen Code", + "Hermes Agent", + "Cursor", + "Zed", + "Aider", + "DeepSeek Harness", + "Continue", + "Antigravity CLI", +]; const delay = (i: number) => `animation-delay: ${i * 90}ms;`; const eyebrow = "font-mono text-[11px] uppercase tracking-[0.08em] text-[var(--color-muted)] sm:text-[13px]"; diff --git a/src/content/docs-lite/en/features.md b/src/content/docs-lite/en/features.md index e9ded41..0ffeead 100644 --- a/src/content/docs-lite/en/features.md +++ b/src/content/docs-lite/en/features.md @@ -10,15 +10,17 @@ The Overview page reports tokens, cost and requests for the last 24 hours, 7 day The cost figure states how much of it is estimated, for instance for a response that was cut off before it finished. Requests whose model has no price, and requests whose upstream reported no usage, are counted separately and never added in as zero. Prices come from price sheets: the default one follows LiteLLM's public prices and is refreshed once a day, and a custom one applies a multiplier and its own prices for particular models, as needed for a relay whose prices differ from the official ones. A subscription account such as a ChatGPT sign-in is priced from the price sheet like any other upstream, and an upstream such as a local model can be set to free. Each request's cost is fixed when the request finishes, and the request records the price sheet and the date of the prices it was costed with. +Until the first request has gone to an upstream, the Overview page shows a get-started checklist instead: add an upstream, connect a client, send a first request. Other pages show a hint for the next step where it applies, such as connecting a client once an upstream exists. A hint can be hidden, and Settings › General shows the hidden ones again. + ## Traffic and sessions -The Traffic page lists requests as they arrive: status, key, model, upstream, time to first token and total time (with the generation speed on hover), tokens and cost, with marks for a converted API format, redacted keys and a blocked or suspicious tool call. The list can be filtered by key, upstream and model, or narrowed to failed or unpriced requests. The Sessions view groups the requests of one conversation into turns, with the input tokens and the cost of each turn. +The Traffic page lists requests as they arrive: status, key, model, upstream, time to first token and total time (with the generation speed on hover), tokens and cost, with marks for a converted API format, redacted keys and a blocked or suspicious tool call. The list can be searched (path, key, upstream, model and error message), filtered by key, upstream and model, or narrowed to failed or unpriced requests. It holds the latest 2,000 requests, and a search or filter also runs over the stored history, further back on request. With content search on, it also covers what each request newly sent (the last user turn, tool results included) and its answer (tool calls included), for as long as payloads are kept; a match shows its excerpt under the request. The Sessions view groups the requests of one conversation into turns, with the input tokens and the cost of each turn. A request opens into its timeline, its routing (the rule it matched, the group it went through and each attempt with its status and duration), the request and response bodies, and its usage and cost. A request from DeepSeek Harness also shows the size of the session log it carried, the whole conversation the client attaches to every request; the gateway removes it before a request goes to an upstream other than DeepSeek. A finished request can be sent again, unchanged, to another upstream after an estimate of its cost, and the two responses are shown side by side. ## Client setup -The Clients page points Claude Code, Claude Desktop, Codex, opencode, Zed, Aider and DeepSeek Harness at the gateway. Before anything is written, it lists the fields that change and what else the change affects (the ChatGPT desktop app, for instance, reads the same configuration file as Codex), shows the full diff and backs up the original file. Only the settings that point the client at the gateway change, and each client receives a key of its own. Claude Desktop is connected through its official third-party inference mode, and the page lists each of the files that change for it; a Claude Desktop managed by an organization is left as it is. A connected client can be restored at any time, on its own or together with all the others; a restored Codex keeps a plain OpenAI entry in place of the gateway's, so sessions started while it was connected can still be opened. opencode (v1 and v2) also gets the list of models its key can use on the gateway; when that list changes, the page offers to update it, through the same diff. Cursor, Continue and Antigravity CLI come with step-by-step instructions and a key created for them. For every client the page shows whether it is in use, waiting for its first request or not in effect, and its requests over the last 24 hours. +The Clients page points Claude Code, Claude Desktop, Codex, opencode, Pi, oh-my-pi, Grok Build, Qwen Code, Hermes Agent, Zed, Aider and DeepSeek Harness at the gateway. Before anything is written, it lists the fields that change and what else the change affects (the ChatGPT desktop app, for instance, reads the same configuration file as Codex), shows the full diff and backs up the original file. Only the settings that point the client at the gateway change, and each client receives a key of its own. Claude Desktop is connected through its official third-party inference mode, and the page lists each of the files that change for it; a Claude Desktop managed by an organization is left as it is. A connected client can be restored at any time, on its own or together with all the others; a restored Codex keeps a plain OpenAI entry in place of the gateway's, so sessions started while it was connected can still be opened. opencode (v1 and v2), Pi, oh-my-pi, Grok Build and Qwen Code also get the list of models their key can use on the gateway; when that list changes, the page offers to update it, through the same diff. DeepSeek Harness is covered in its web app, its desktop app and headless runs, which all read the same configuration; models used through a DeepSeek account signed in to the desktop app still go to DeepSeek directly. Cursor, Continue and Antigravity CLI come with step-by-step instructions and a key created for them. For every client the page shows whether it is in use, waiting for its first request or not in effect, and its requests over the last 24 hours. On Windows, Claude Code and Codex installed inside WSL appear in a group of their own for each distribution, next to the clients on the computer itself. They are pointed at the gateway on Windows, restored and diagnosed the same way, each with a key separate from the Windows copy, and their files are edited through `\\wsl.localhost`. They are given `127.0.0.1`, the same address as the clients on Windows, which WSL reaches in two setups: @@ -35,6 +37,8 @@ Clients reach the gateway with a key, on the local machine as well. The Keys pag Upstreams are the services requests are forwarded to: API keys for Anthropic, OpenAI, Google Gemini, DeepSeek or any compatible endpoint, Amazon Bedrock (with an API key, access keys or an AWS profile), a ChatGPT account or a Z.ai / BigModel account signed in from the app, relays such as OpenRouter, and local models such as Ollama. A ChatGPT account shows its usage limits and reset times. So does an upstream on a GLM Coding Plan, that is, one whose address is on `api.z.ai` or `open.bigmodel.cn`, whether it was signed in from the app or added with a key: its 5-hour and weekly limits and, on a plan billed in credits, the credits left (“1,976 / 2,000 credits left”). When a client and an upstream use different API formats, requests are converted between Anthropic Messages, OpenAI Chat Completions, OpenAI Responses and Gemini, and the fields that cannot be carried over are listed on the request. Upstreams can be reached through an outbound proxy and priced with a price sheet of their own; proxies and price sheets have tabs on the same page. A connection test times the DNS lookup and the TCP, TLS and proxy handshakes without incurring any cost; an inference test measures the time to first token and estimates its cost before it runs. +The Check-up tab compares the upstreams over the last 24 hours, 7 days, 30 days or a custom range: requests and failure rate; whether the model named in each answer matches the one sent; the input tokens each upstream reports, as a multiple of the gateway's own estimate, against other upstreams serving the same model; the share of input read from the prompt cache in follow-up turns, also against other upstreams; and the median time to first token and generation speed. Each figure comes with its sample size, and a deviation is marked only when both sides have enough samples. + API keys and header values can be written as `${NAME}` to read a system environment variable. On macOS these come from the login shell, so variables exported in `~/.zshrc` and similar files apply, and the same holds on Linux (`~/.bashrc`, `~/.profile` and so on); on Windows they are the environment variables configured in system settings. After a variable changes, reopening the app picks it up. Proxy variables such as `HTTPS_PROXY`, and `PATH`, are not read. A relay or vendor can hand out an import link, `thinkwatch://import?…` or its web form `https://thinkwat.ch/import#…`, that pre-fills a new upstream with a name, base URL, protocol, API key and model list. The app shows the settings and the host that will receive requests and the key in a confirmation dialog, and writes nothing and contacts nothing before Create is chosen. A link only ever adds one upstream: it cannot change existing ones, headers, proxies, pricing or routing, and a key that refers to an environment variable is rejected. The parameters and a link builder are in [Import links](/docs/lite/import-links). @@ -51,7 +55,7 @@ Every request records the rule it matched, the group it went through and each at The Security page holds five protections. They apply to every upstream and every key alike, and each runs in one of three modes: Off, Observe (detect and record, change nothing) or Enforce. The output limit starts Off and the other four start in Observe, so out of the box no request is changed or blocked. -- **Outbound redaction** looks for credentials in a request before it leaves: API keys and tokens for Anthropic, OpenAI, GitHub, Slack, AWS, Google, GitLab, Stripe, npm, DigitalOcean and SendGrid, private keys, JWTs and passwords in connection strings. In Enforce mode they are replaced with placeholders and restored where the response repeats them. Rules for internal IP addresses and internal domains are included and start off. +- **Outbound redaction** looks for credentials in a request before it leaves: API keys and tokens for Anthropic, OpenAI, GitHub, Slack, AWS, Google, GitLab, Stripe, npm, DigitalOcean and SendGrid, private keys, JWTs and passwords in connection strings, as well as Chinese resident ID numbers and bank card numbers, which count only when their structure and check digit are valid. In Enforce mode they are replaced with placeholders and restored where the response repeats them. Rules for internal IP addresses and internal domains are included and start off. - **Tool-call inspection** checks the tool calls a model returns for commands that download or decode code and run it, send out environment variables or credential files, read private keys or cloud credentials, or install startup items and scheduled jobs. In Enforce mode such a call cuts the response off, so the client never receives a complete call to run. Deleting the home or root directory and making files world-writable are only recorded by default. - **Hidden characters** looks for Unicode tag characters and bidirectional control characters in what the client sends, tool results included, and in Enforce mode refuses the request. - **Content filter** matches keywords or regular expressions against the messages the client sends, tool results included, and in Enforce mode refuses a request that matches a blocking rule. Of the built-in rules, the three against explicit "ignore previous instructions" phrasing are on by default; rules for jailbreaks, persona manipulation, prompt extraction and their Chinese counterparts can be switched on. @@ -63,15 +67,15 @@ The page lists every rule. Built-in rules can be switched on or off one at a tim The MCP page covers what clients load from their own configuration files, which does not pass through the gateway. -- **Servers:** the MCP servers configured in Claude Code, Claude Desktop, Cursor, Codex, opencode, Antigravity CLI, Zed and DeepSeek Harness, side by side. A server can be copied from one client to another or removed from a client; the change is shown before anything is written, and the original file is backed up. Copying and removing work for Claude Code, Claude Desktop, Cursor and Codex; opencode, Antigravity CLI, Zed and DeepSeek Harness are listed but not written to. A remote server on another host is marked as third party, since using it sends the surrounding context to that host, and a server configured differently in different clients is marked as well and can be compared side by side. -- **Skills and hooks:** the installed skills and configured hooks, with the client each belongs to. +- **Servers:** the MCP servers configured in Claude Code, Claude Desktop, Cursor, Codex, opencode, Antigravity CLI, Zed, Pi, oh-my-pi, Grok Build, Qwen Code, Hermes Agent and DeepSeek Harness, side by side. A server can be copied from one client to another or removed from a client; the change is shown before anything is written, and the original file is backed up. Copying and removing work for Claude Code, Claude Desktop, Cursor and Codex; the other clients are listed but not written to. A remote server on another host is marked as third party, since using it sends the surrounding context to that host, and a server configured differently in different clients is marked as well and can be compared side by side. +- **Skills and hooks:** the installed skills and configured hooks, with the client each belongs to; skills in the shared `~/.agents/skills` folder are listed as such. - **Findings:** client configuration, skills, hooks, slash commands, subagents and project instruction files are scanned for hidden characters, prompt injection, dangerous commands and overly broad permissions, and each finding is graded high, medium or low. The scan only reports; it never changes a file. The app watches these files while it runs, and a new finding raises a system notification. ## Settings -Settings has six sections. Connection lists the local core and the saved remote cores, described in [Connecting to a remote core](/docs/lite/remote-core). General sets the language, the appearance, what the menu bar item shows on macOS, launch at login, and whether notices arrive as system notifications, in the app only or not at all. Listening sets who can reach the gateway (this machine only, the local network of a chosen interface, or every interface), its port and the allowed address ranges. Log retention sets how long request payloads and request records are kept, and a size cap for payloads. About shows the version, checks for updates and produces a diagnostics bundle with keys and addresses masked. Uninstall restores every connected client and removes the autostart entry, and is meant to be run before the app is deleted. +Settings has six sections. Connection lists the local core and the saved remote cores, described in [Connecting to a remote core](/docs/lite/remote-core). General sets the language, the appearance, what the menu bar item shows on macOS, launch at login, whether notices arrive as system notifications, in the app only or not at all, and shows hidden guidance hints again. Listening sets who can reach the gateway (this machine only, the local network of a chosen interface, or every interface), its port and the allowed address ranges. Log retention sets how long request payloads and request records are kept, and a size cap for payloads. About shows the version, checks for updates and produces a diagnostics bundle with keys and addresses masked. Uninstall restores every connected client and removes the autostart entry, and is meant to be run before the app is deleted. ## Menu bar, system tray and notifications diff --git a/src/content/docs-lite/en/overview.md b/src/content/docs-lite/en/overview.md index fd1d9f0..9f624be 100644 --- a/src/content/docs-lite/en/overview.md +++ b/src/content/docs-lite/en/overview.md @@ -6,10 +6,10 @@ ThinkWatch Lite is a local gateway for Claude Code, Codex and other AI clients, ## Highlights -- **Connect once, switch freely.** Seven clients are pointed at the gateway in one step, with the change previewed and the original backed up; Cursor, Continue and Antigravity CLI come with instructions. -- **Protection against relays.** A relay sees every request and can rewrite every answer. Outbound redaction can replace credentials before a request leaves, and tool-call inspection can cut off an answer that carries a dangerous tool call, such as download-and-run or sending out credential files, before the client runs it. Hidden-character detection, a content filter and an output limit complete the five protections, each in Off, Observe or Enforce. -- **MCP servers, skills and hooks, scanned.** The MCP servers of eight clients side by side, and a scan of client configuration for hidden characters, prompt injection, dangerous commands and overly broad permissions. -- **Every request traceable.** The matched rule, each attempt, any format conversion and the cost, with replay against another upstream. +- **Connect once, switch freely.** Twelve clients are pointed at the gateway in one step, with the change previewed and the original backed up; Cursor, Continue and Antigravity CLI come with instructions. +- **Protection against relays.** A relay sees every request and can rewrite every answer. Outbound redaction can replace credentials, ID numbers and bank card numbers before a request leaves, and tool-call inspection can cut off an answer that carries a dangerous tool call, such as download-and-run or sending out credential files, before the client runs it. Hidden-character detection, a content filter and an output limit complete the five protections, each in Off, Observe or Enforce. +- **MCP servers, skills and hooks, scanned.** The MCP servers of thirteen clients side by side, and a scan of client configuration for hidden characters, prompt injection, dangerous commands and overly broad permissions. +- **Every request traceable.** The matched rule, each attempt, any format conversion and the cost, with replay against another upstream; the whole history can be searched, including the text of requests and answers. - **Routing and failover.** Rules by model, tools, images and more; groups that fail over before the answer begins and keep each session on one upstream. - **Any upstream.** API keys, Amazon Bedrock, ChatGPT and Z.ai accounts, relays and local models, with conversion between the Anthropic, OpenAI and Gemini APIs. - **Costs stated as they are.** Estimates marked, unpriced requests counted separately rather than as zero. diff --git a/src/content/docs-lite/zh-CN/features.md b/src/content/docs-lite/zh-CN/features.md index 8425376..45f5cce 100644 --- a/src/content/docs-lite/zh-CN/features.md +++ b/src/content/docs-lite/zh-CN/features.md @@ -10,15 +10,17 @@ 费用会注明其中估算的部分,例如响应结束前被中断的请求。模型未定价的请求和上游未报告用量的请求单独计数,从不按零计入。价格来自价目表:默认价目表采用 LiteLLM 的公开价格,每天更新一次;自定义价目表在其基础上设置倍率,并可单独为个别模型定价,适用于价格与官方不同的中转服务。ChatGPT 这类订阅账号同样按价目表计价,本地模型等上游可设为不计费。每个请求的费用在请求结束时确定,并注明计价所用的价目表及其数据日期。 +还没有请求经过上游时,概览页改为显示「开始使用」清单:添加上游、接管客户端、发出第一条请求。其他页面在适用之处提示下一步,例如有了上游之后提示接管客户端。提示可以设为不再显示,「设置 › 通用」可以让它们重新显示。 + ## 流量与会话 -流量页实时列出请求:状态、密钥、模型、上游、首 token 时间与总耗时(悬停时显示生成速度)、token 和费用,并标出格式转换、被脱敏的密钥,以及被拦截或可疑的工具调用。列表可以按密钥、上游和模型筛选,或只看失败、无法计价的请求。「会话」视图把同一段对话的请求归为若干轮次,给出每一轮的输入 token 与费用。 +流量页实时列出请求:状态、密钥、模型、上游、首 token 时间与总耗时(悬停时显示生成速度)、token 和费用,并标出格式转换、被脱敏的密钥,以及被拦截或可疑的工具调用。列表可以搜索(路径、密钥、上游、模型与错误信息),可以按密钥、上游和模型筛选,或只看失败、无法计价的请求。列表装有最近 2,000 条请求,搜索与筛选同时在全部请求记录中进行,可以继续向更早的记录搜索。打开「搜索内容」后,还会搜索每个请求新发送的内容(最后一轮用户消息,含工具结果)及其回答(含工具调用),范围以报文仍保留的请求为限;命中的片段显示在对应请求的下方。「会话」视图把同一段对话的请求归为若干轮次,给出每一轮的输入 token 与费用。 打开一个请求可以查看时间线、路由(命中的规则、经过的策略组,以及每一次尝试的状态与耗时)、请求与响应正文、用量与费用。DeepSeek Harness 发出的请求还会显示所带会话日志的大小:这是客户端随每个请求附带的整段对话记录,发往 DeepSeek 以外的上游之前由网关去除。已结束的请求可以在预估费用后原样发送到另一个上游,两次的响应并排对照。 ## 客户端接管 -客户端页可以把 Claude Code、Claude Desktop、Codex、opencode、Zed、Aider 与 DeepSeek Harness 指向网关。写入之前,页面列出将要修改的字段和这次接管的其他影响(例如 ChatGPT 桌面版与 Codex 读取同一份配置文件),给出完整的改动差异,并完整备份原文件。只修改指向网关所需的配置,每个客户端使用各自的密钥。Claude Desktop 通过官方的第三方推理模式接入,页面逐一列出要修改的各个文件;由组织统一管理的 Claude Desktop 不做修改。已接管的客户端可以随时单独还原或全部还原;Codex 还原后保留一项直连 OpenAI 的配置,接管期间的会话仍可打开。opencode(v1 与 v2)的配置中同时写入其密钥在网关上可用的模型列表;网关上可用的模型变化后,页面提示更新,更新同样先给出改动差异。Cursor、Continue 与 Antigravity CLI 提供逐步的配置方法,并为其创建密钥。页面列出每个客户端处于使用中、等待首个请求还是未生效,以及最近 24 小时的请求。 +客户端页可以把 Claude Code、Claude Desktop、Codex、opencode、Pi、oh-my-pi、Grok Build、Qwen Code、Hermes Agent、Zed、Aider 与 DeepSeek Harness 指向网关。写入之前,页面列出将要修改的字段和这次接管的其他影响(例如 ChatGPT 桌面版与 Codex 读取同一份配置文件),给出完整的改动差异,并完整备份原文件。只修改指向网关所需的配置,每个客户端使用各自的密钥。Claude Desktop 通过官方的第三方推理模式接入,页面逐一列出要修改的各个文件;由组织统一管理的 Claude Desktop 不做修改。已接管的客户端可以随时单独还原或全部还原;Codex 还原后保留一项直连 OpenAI 的配置,接管期间的会话仍可打开。opencode(v1 与 v2)、Pi、oh-my-pi、Grok Build 与 Qwen Code 的配置中同时写入其密钥在网关上可用的模型列表;网关上可用的模型变化后,页面提示更新,更新同样先给出改动差异。DeepSeek Harness 的网页版、桌面版与 headless 模式读取同一份配置,都会经过网关;在桌面版中通过 DeepSeek 账号登录使用的模型仍直接连接 DeepSeek。Cursor、Continue 与 Antigravity CLI 提供逐步的配置方法,并为其创建密钥。页面列出每个客户端处于使用中、等待首个请求还是未生效,以及最近 24 小时的请求。 在 Windows 上,安装在 WSL 中的 Claude Code 与 Codex 按发行版单独成组,列在这台电脑的客户端之后。它们同样可以指向 Windows 上的网关、还原和检查,使用与 Windows 上那一份分开的密钥,配置文件经由 `\\wsl.localhost` 修改。写入的地址与 Windows 上的客户端相同,是 `127.0.0.1`,WSL 在以下两种情况下可以访问: @@ -35,6 +37,8 @@ WSL 2 默认使用 NAT 网络,此时 Windows 上的网关无法从 WSL 内访 上游是网关转发请求的目标:Anthropic、OpenAI、Google Gemini、DeepSeek 或任何兼容接口的 API 密钥,Amazon Bedrock(API 密钥、访问密钥或 AWS 配置文件),在应用内登录的 ChatGPT 账号或 Z.ai / BigModel 账号,OpenRouter 等中转服务,以及 Ollama 等本机模型。ChatGPT 账号显示订阅额度与重置时间;GLM Coding Plan 的上游(地址在 `api.z.ai` 或 `open.bigmodel.cn` 上,在应用内登录或手动填写密钥均可)同样显示:5 小时与每周额度,积分制套餐另外显示剩余积分(「剩余 1,976 / 2,000 积分」)。客户端与上游的 API 格式不同时,请求在 Anthropic Messages、OpenAI Chat Completions、OpenAI Responses 与 Gemini 之间自动转换,无法转换的字段会在请求上逐一列出。上游可以经出站代理访问,也可以使用单独的价目表计价,代理与价目表在同一页的标签中管理。链路测速测量 DNS 解析以及 TCP、TLS、代理握手的耗时,不产生费用;推理测速测量首个 token 的时间,运行前先给出费用预估。 +「体检」标签按最近 24 小时、7 天、30 天或自定义区间对照各个上游:请求数与失败率;回答中的模型名与发出的是否相同;各上游报告的输入 token 相对网关本地估算的倍数,与服务同一模型的其他上游对照;后续轮次中输入从提示缓存读取的比例,同样与其他上游对照;以及首 token 时间与生成速度的中位数。每项数字都附样本数,两边样本都足够时才标出偏差。 + API 密钥和请求头的值可以写成 `${变量名}`,读取系统环境变量。macOS 上读的是登录 shell 里的环境变量,`~/.zshrc` 等文件中 `export` 的变量都会生效,Linux 同理(`~/.bashrc`、`~/.profile` 等);Windows 上读的是系统设置里配置的环境变量。修改变量后,重新打开应用即可生效。代理相关的变量(`HTTPS_PROXY` 等)和 `PATH` 不会被读取。 中转站或服务商可以提供导入链接(`thinkwatch://import?…`,或网页形式 `https://thinkwat.ch/import#…`),预填新上游的名称、接口地址、接口协议、API 密钥与模型清单。应用在确认对话框中列出这些设置,并写明请求与密钥将发往的主机;选择「创建」之前不写入配置,也不连接该地址。一条链接只能新增一个上游,不能修改已有的上游、请求头、代理、价目表或路由,引用环境变量的密钥一律拒绝。参数说明与链接生成器见[导入链接](/zh-CN/docs/lite/import-links)。 @@ -51,7 +55,7 @@ API 密钥和请求头的值可以写成 `${变量名}`,读取系统环境变 安全页有五项防护,对所有上游和所有密钥统一生效,各有「关闭」「观察」「拦截」三档,其中「观察」只检测和记录,不做任何改动。输出长度出厂为「关闭」,其余四项出厂为「观察」,因此默认不会改动或拦截任何请求。 -- **出站脱敏**:请求发出之前查找其中的凭据,包括 Anthropic、OpenAI、GitHub、Slack、AWS、Google、GitLab、Stripe、npm、DigitalOcean、SendGrid 的 API 密钥与令牌,以及私钥、JWT 和连接串中的口令。「拦截」档下把它们替换为占位符,响应中回显时再还原。内网 IP 地址和内网域名两条规则出厂为停用,可以按需启用。 +- **出站脱敏**:请求发出之前查找其中的凭据,包括 Anthropic、OpenAI、GitHub、Slack、AWS、Google、GitLab、Stripe、npm、DigitalOcean、SendGrid 的 API 密钥与令牌,以及私钥、JWT 和连接串中的口令,还有身份证号与银行卡号(号码结构与校验位都正确才算)。「拦截」档下把它们替换为占位符,响应中回显时再还原。内网 IP 地址和内网域名两条规则出厂为停用,可以按需启用。 - **工具调用审查**:检查模型返回的工具调用中是否含有下载或解码后执行代码、外发环境变量或凭据文件、读取私钥或云服务凭据、写入启动项或定时任务等命令。「拦截」档下命中即切断响应,客户端收不到一个完整、可执行的调用。删除主目录或根目录、设置全员可写权限两条规则出厂只记录。 - **隐藏字符**:检查客户端发送的内容(含工具结果)中的 Unicode 标签字符和双向控制符,「拦截」档下拒绝发出请求。 - **内容过滤**:用关键词或正则表达式匹配客户端发送的消息(含工具结果),「拦截」档下拒绝命中拒绝类规则的请求。内置规则中,出厂只启用三条明确要求「忽略先前指令」的规则;越狱、身份操纵、套取提示词等规则及其中文版本可以按需启用。 @@ -63,15 +67,15 @@ API 密钥和请求头的值可以写成 `${变量名}`,读取系统环境变 MCP 页管理客户端从自己的配置文件中加载的内容,这些内容不经过网关。 -- **服务器**:并排列出 Claude Code、Claude Desktop、Cursor、Codex、opencode、Antigravity CLI、Zed 与 DeepSeek Harness 配置的 MCP 服务器。可以把一个服务器从一个客户端复制到另一个客户端,或从某个客户端移除;写入前先显示改动,并备份原文件。复制与移除支持 Claude Code、Claude Desktop、Cursor 与 Codex,opencode、Antigravity CLI、Zed 与 DeepSeek Harness 只列出、不写入。位于其他主机的远程服务器标为「第三方」,使用它会把相关上下文发送到该地址;同名服务器在各客户端中配置不同时标为「配置不一致」,可以并排比较。 -- **技能与钩子**:列出已安装的技能和配置的钩子,以及各自所属的客户端。 +- **服务器**:并排列出 Claude Code、Claude Desktop、Cursor、Codex、opencode、Antigravity CLI、Zed、Pi、oh-my-pi、Grok Build、Qwen Code、Hermes Agent 与 DeepSeek Harness 配置的 MCP 服务器。可以把一个服务器从一个客户端复制到另一个客户端,或从某个客户端移除;写入前先显示改动,并备份原文件。复制与移除支持 Claude Code、Claude Desktop、Cursor 与 Codex,其余客户端只列出、不写入。位于其他主机的远程服务器标为「第三方」,使用它会把相关上下文发送到该地址;同名服务器在各客户端中配置不同时标为「配置不一致」,可以并排比较。 +- **技能与钩子**:列出已安装的技能和配置的钩子,以及各自所属的客户端;共用的 `~/.agents/skills` 目录中的技能单独标为共用目录。 - **发现**:扫描客户端配置、技能、钩子、斜杠命令、subagent 与项目指令文件,检查隐藏字符、提示注入、危险命令与过宽权限四类问题,每项发现按高、中、低分级。扫描只报告,不修改任何文件。 应用运行期间会监视这些文件,出现新的发现时发送系统通知。 ## 设置 -设置页分为六节。「连接」列出本机 core 和已保存的远程 core,详见[连接远程 core](/zh-CN/docs/lite/remote-core)。「通用」设置语言、外观、菜单栏显示的内容(仅 macOS)、开机启动,以及提醒以系统通知发送、仅在应用内显示还是关闭。「网关监听」设置网关的访问范围(仅本机、所选网卡所在的局域网或所有网卡)、端口和放行网段。「日志保留」分别设置请求报文与请求记录的保留天数,以及报文的空间上限。「关于」显示版本、检查更新,并可生成诊断包,其中的密钥与地址均已脱敏。「卸载」还原所有已接管的客户端并取消开机启动,应在删除应用之前执行。 +设置页分为六节。「连接」列出本机 core 和已保存的远程 core,详见[连接远程 core](/zh-CN/docs/lite/remote-core)。「通用」设置语言、外观、菜单栏显示的内容(仅 macOS)、开机启动、提醒以系统通知发送、仅在应用内显示还是关闭,并可让设为不再显示的引导提示重新显示。「网关监听」设置网关的访问范围(仅本机、所选网卡所在的局域网或所有网卡)、端口和放行网段。「日志保留」分别设置请求报文与请求记录的保留天数,以及报文的空间上限。「关于」显示版本、检查更新,并可生成诊断包,其中的密钥与地址均已脱敏。「卸载」还原所有已接管的客户端并取消开机启动,应在删除应用之前执行。 ## 菜单栏、系统托盘与通知 diff --git a/src/content/docs-lite/zh-CN/overview.md b/src/content/docs-lite/zh-CN/overview.md index 5e47928..bb3279a 100644 --- a/src/content/docs-lite/zh-CN/overview.md +++ b/src/content/docs-lite/zh-CN/overview.md @@ -6,10 +6,10 @@ ThinkWatch Lite 是 Claude Code、Codex 等 AI 客户端的本地网关,支持 ## 要点 -- **一次接入,随时切换。** 七款客户端可一键指向网关,写入前预览改动并备份原文件;Cursor、Continue 与 Antigravity CLI 提供配置说明。 -- **防范中转站。** 中转站能看到每个请求,也能改写每一次回答。出站脱敏可在请求发出前替换其中的凭据;回答中出现下载即执行、外发凭据文件之类的危险工具调用时,工具调用审查可在客户端执行前切断回答。另有隐藏字符检测、内容过滤与输出长度限制,共五项防护,每项可设为关闭、观察或拦截。 -- **扫描 MCP、技能与钩子。** 八款客户端的 MCP 服务器并列显示,并扫描客户端配置中的隐藏字符、提示注入、危险命令与过宽权限。 -- **每个请求都可追溯。** 命中的规则、每一次尝试、格式转换与费用都有记录,也可以重放到另一个上游对比。 +- **一次接入,随时切换。** 十二款客户端可一键指向网关,写入前预览改动并备份原文件;Cursor、Continue 与 Antigravity CLI 提供配置说明。 +- **防范中转站。** 中转站能看到每个请求,也能改写每一次回答。出站脱敏可在请求发出前替换其中的凭据、身份证号与银行卡号;回答中出现下载即执行、外发凭据文件之类的危险工具调用时,工具调用审查可在客户端执行前切断回答。另有隐藏字符检测、内容过滤与输出长度限制,共五项防护,每项可设为关闭、观察或拦截。 +- **扫描 MCP、技能与钩子。** 十三款客户端的 MCP 服务器并列显示,并扫描客户端配置中的隐藏字符、提示注入、危险命令与过宽权限。 +- **每个请求都可追溯。** 命中的规则、每一次尝试、格式转换与费用都有记录,也可以重放到另一个上游对比;全部请求记录都可以搜索,包括请求与回答的内容。 - **路由与故障转移。** 按模型、工具、图片等条件分流;回答开始前上游出错时换用下一个,同一会话固定使用同一上游。 - **多种上游。** API 密钥、Amazon Bedrock、ChatGPT 与 Z.ai 账号、中转服务与本机模型,Anthropic、OpenAI、Gemini 接口之间自动转换。 - **费用如实计算。** 估算的金额单独标注,无法计价的请求单独计数,不按零计入。 diff --git a/src/i18n/pages/lite.ts b/src/i18n/pages/lite.ts index 71eeb00..384e2f3 100644 --- a/src/i18n/pages/lite.ts +++ b/src/i18n/pages/lite.ts @@ -78,7 +78,7 @@ export const liteCopy = { bento: { titleA: "And the rest,", titleB: " all in one app.", - clientsCount: "7", + clientsCount: "12", clientsCountSub: "set up in one step · 3 more by instructions", noticesTitle: "System notifications", notices: [ @@ -116,25 +116,25 @@ export const liteCopy = { { id: "clients", title: "Connect once, switch freely", - body: "Claude Code, Codex, opencode and four other clients are pointed at the gateway in one step, with the change previewed, the original file backed up and a restore always available; on Windows, Claude Code and Codex inside WSL as well. From then on, switching upstreams happens in the gateway, with no client to reconfigure or restart.", + body: "Claude Code, Codex, opencode and nine other clients are pointed at the gateway in one step, with the change previewed, the original file backed up and a restore always available; on Windows, Claude Code and Codex inside WSL as well. From then on, switching upstreams happens in the gateway, with no client to reconfigure or restart.", alt: "The Clients page: Claude Code and Codex connected, each with its own key and its requests over the last 24 hours; opencode not connected; Cursor set up by hand and in use; Continue and Antigravity CLI not yet set up; Zed and Aider not detected", }, { id: "security", title: "Protection against relays: keys replaced, malicious tool calls cut off", - body: "A relay sees every request in full and can rewrite every answer. Outbound redaction swaps API keys, private keys, JWTs and connection-string passwords for placeholders before a request leaves and restores them in the response, so the relay never holds the real values. When an answer carries a tool call that downloads and runs code, sends out environment variables or credential files, reads private keys or installs a startup item or scheduled job, tool-call inspection cuts the answer off before the client can run it; hidden characters and prompt injection can be refused as well. The five protections start in Observe, recording without changing anything, and each switches to Enforce on its own.", + body: "A relay sees every request in full and can rewrite every answer. Outbound redaction swaps API keys, private keys, JWTs, connection-string passwords, Chinese resident ID numbers and bank card numbers for placeholders before a request leaves and restores them in the response, so the relay never holds the real values. When an answer carries a tool call that downloads and runs code, sends out environment variables or credential files, reads private keys or installs a startup item or scheduled job, tool-call inspection cuts the answer off before the client can run it; hidden characters and prompt injection can be refused as well. The five protections start in Observe, recording without changing anything, and each switches to Enforce on its own.", alt: "The Security page log: credentials replaced before a request left, one of them matched by a custom rule; a download-and-run tool call cut off; and hidden characters, a delete command and an injected instruction recorded, each with the key, client, model and upstream of its request", }, { id: "mcp", title: "MCP servers, skills and hooks, scanned", - body: "The MCP servers of eight clients appear side by side, with third-party remote servers and inconsistent configurations marked, and can be copied or removed between clients. Client configuration, skills, hooks and project instructions are scanned for hidden characters, prompt injection, dangerous commands and overly broad permissions, and a new finding raises a notification.", + body: "The MCP servers of thirteen clients appear side by side, with third-party remote servers and inconsistent configurations marked, and can be copied or removed between clients. Client configuration, skills, hooks and project instructions are scanned for hidden characters, prompt injection, dangerous commands and overly broad permissions, and a new finding raises a notification.", alt: "The MCP page: the MCP servers configured in Claude Code, Claude Desktop, Cursor, Codex, opencode, Antigravity CLI and Zed side by side, with remote third-party servers and a server configured differently in two clients marked; one high, one medium and one low finding in 11 scanned files", }, { id: "traffic", title: "Every request, traceable", - body: "A request shows the rule it matched, each upstream it tried, any conversion between API formats and how its cost was calculated. A finished request can be replayed against another upstream and the two answers compared side by side.", + body: "A request shows the rule it matched, each upstream it tried, any conversion between API formats and how its cost was calculated. A finished request can be replayed against another upstream and the two answers compared side by side, and the whole history can be searched, including the text of requests and answers.", alt: "The Traffic page: each request with its key, model, upstream, time to first token, total time, tokens and cost, with marks for converted formats, redacted keys and a blocked request, and one request answered locally by the gateway", }, { @@ -322,7 +322,7 @@ export const liteCopy = { bento: { titleA: "还有这些,", titleB: "都在一个应用里。", - clientsCount: "7", + clientsCount: "12", clientsCountSub: "款一键接入 · 另有 3 款按说明配置", noticesTitle: "系统通知", notices: [ @@ -351,25 +351,25 @@ export const liteCopy = { { id: "clients", title: "一次接入,随时切换", - body: "一键接入 Claude Code、Codex、opencode 等七款客户端,写入前预览改动、备份原文件,随时可以还原;Windows 上 WSL 中的 Claude Code 与 Codex 同样支持。此后切换上游只在网关中完成,客户端无需改配置或重启。", + body: "一键接入 Claude Code、Codex、opencode 等十二款客户端,写入前预览改动、备份原文件,随时可以还原;Windows 上 WSL 中的 Claude Code 与 Codex 同样支持。此后切换上游只在网关中完成,客户端无需改配置或重启。", alt: "客户端页:Claude Code 与 Codex 已接管,各用一把密钥,并列出最近 24 小时的请求;opencode 尚未接管;Cursor 已手动配置并在使用;Continue 与 Antigravity CLI 尚未配置;Zed 与 Aider 未检测到", }, { id: "security", title: "防范中转站:替换密钥,拦截恶意工具调用", - body: "中转站能看到请求的全部内容,也能改写每一次回答。出站脱敏在请求发出前把 API 密钥、私钥、JWT 与连接串口令换成占位符,并在响应中还原,中转站拿不到原值。回答中若出现下载即执行、外发环境变量或凭据文件、读取私钥、写入开机启动项或定时任务之类的工具调用,工具调用审查会在客户端执行之前切断回答;隐藏字符与提示注入也可以直接拒绝。五项防护出厂只记录、不改动请求,逐项切换到拦截即可生效。", + body: "中转站能看到请求的全部内容,也能改写每一次回答。出站脱敏在请求发出前把 API 密钥、私钥、JWT、连接串口令、身份证号与银行卡号换成占位符,并在响应中还原,中转站拿不到原值。回答中若出现下载即执行、外发环境变量或凭据文件、读取私钥、写入开机启动项或定时任务之类的工具调用,工具调用审查会在客户端执行之前切断回答;隐藏字符与提示注入也可以直接拒绝。五项防护出厂只记录、不改动请求,逐项切换到拦截即可生效。", alt: "安全页日志:请求发出前替换的凭据(其中一条由自定义规则命中)、被切断的下载即执行工具调用,以及记录在案的隐藏字符、删除命令与注入指令,每条都注明所属请求的密钥、客户端、模型与上游", }, { id: "mcp", title: "扫描 MCP、技能与钩子", - body: "八款客户端的 MCP 服务器集中显示,标出第三方远程服务器与各客户端之间不一致的配置,可以在客户端之间复制或移除。客户端配置、技能、钩子与项目指令中的隐藏字符、提示注入、危险命令与过宽权限会被找出,出现新发现时发送通知。", + body: "十三款客户端的 MCP 服务器集中显示,标出第三方远程服务器与各客户端之间不一致的配置,可以在客户端之间复制或移除。客户端配置、技能、钩子与项目指令中的隐藏字符、提示注入、危险命令与过宽权限会被找出,出现新发现时发送通知。", alt: "MCP 页:Claude Code、Claude Desktop、Cursor、Codex、opencode、Antigravity CLI 与 Zed 中配置的 MCP 服务器并列显示,标出第三方远程服务器与两个客户端间配置不一致的服务器;共扫描 11 个文件,发现高、中、低风险各一项", }, { id: "traffic", title: "每个请求都可追溯", - body: "请求详情给出命中的规则、尝试过的每个上游、API 格式转换,以及费用的计算依据。已结束的请求可以重放到另一个上游,并排对比两次回答。", + body: "请求详情给出命中的规则、尝试过的每个上游、API 格式转换,以及费用的计算依据。已结束的请求可以重放到另一个上游,并排对比两次回答;全部请求记录都可以搜索,包括请求与回答的内容。", alt: "流量页:逐条列出请求的密钥、模型、上游、首 token 时间、总耗时、token 与费用,标出格式转换、密钥脱敏与被拦截的请求,其中一条由网关在本地应答", }, {