feat: bind explicitly authorized HTTP text extraction channel

This commit is contained in:
2026-10-10 10:28:28 +08:00
parent 73be0ecedf
commit 228d93ac3b
6 changed files with 86 additions and 7 deletions
@@ -23,7 +23,7 @@ final class FollowupAudioPipeline
{
if (($this->provider['driver'] ?? '') !== 'asr_then_llm') { throw new FollowupAudioException('CONFIG_INVALID'); }
foreach (['asr', 'extraction'] as $stage) {
if (!FollowupAudioProviderConfig::secureEndpoint($this->provider[$stage]['base_url'], $this->provider['allow_loopback_tunnel'])) {
if (!FollowupAudioProviderConfig::stageEndpointAllowed($this->provider, $stage)) {
throw new FollowupAudioException('HTTPS_REQUIRED');
}
}
@@ -301,6 +301,10 @@ final class FollowupAudioPipeline
: ($protocol === 'dify_chat' ? '/chat-messages' : '/chat/completions');
$spec = ['url' => $part['base_url'] . $endpoint,
'api_key' => $part['api_key'], 'timeout' => $timeout, 'stage' => $stage] + $payload;
if ($stage === 'extraction' && isset($part['http_base_opt_in'])) {
$spec['http_extraction_url'] = $part['http_base_opt_in'] . '/chat/completions';
$spec['extraction_protocol'] = $protocol;
}
try {
$response = $this->transport ? ($this->transport)($spec, $heartbeat)
: (($this->provider['http_transport'] ?? 'curl') === 'openssl_stream'