feat: bind explicitly authorized HTTP text extraction channel

This commit is contained in:
2026-10-10 10:28:28 +08:00
parent 73be0ecedf
commit 228d93ac3b
6 changed files with 86 additions and 7 deletions
+9 -1
View File
@@ -45,7 +45,7 @@ ASR_CHUNK_SECONDS = 120
ASR_REQUEST_TIMEOUT = 240
EXTRACTION_REQUEST_TIMEOUT = 240
# HTTPS required. Enable this only for an operator-established SSH tunnel on literal 127.0.0.1 or [::1].
# localhost, other hosts, external HTTP and HTTP redirects are never exceptions.
# This loopback switch never permits other hosts; redirects remain disabled.
QWEN_ALLOW_LOOPBACK_TUNNEL = false
QWEN_ASR_BASE_URL =
QWEN_ASR_API_KEY =
@@ -93,3 +93,11 @@ OPENAI_EXTRACTION_BINDING_REVISION =
# asr_then_llm only: curl (default) or openssl_stream (explicit verified-TLS child process).
# No automatic transport fallback; changing this requires new fingerprint readiness.
HTTP_TRANSPORT = curl
# Explicit operator authorization for a fixed plaintext text-extraction channel only.
# Copy the exact normalized http://HOST[/path]/v1 base here; no wildcards, encoded/dot paths or redirects.
# Only asr_then_llm + extraction protocol=openai accepts it. ASR and all HTTPS verification stay unchanged.
# HTTP carries transcript and API key without TLS. Leave empty unless that channel was expressly authorized.
# Changes bind a new provider fingerprint; preserve old profiles/tasks rather than replacing their identity.
QWEN_EXTRACTION_HTTP_BASE_OPT_IN =
OPENAI_EXTRACTION_HTTP_BASE_OPT_IN =