fix: generate_keys 补充 PROXY_HMAC_KEY 生成,CLI handler 增加 ReadError 容错

- generate_keys.py 新增 PROXY_HMAC_KEY 生成并输出 aether-proxy.toml 配置示例
- .env.example 完善 PROXY_HMAC_KEY 注释说明
- cli_handler_base.py 两处流式处理增加 httpx.ReadError 异常捕获,
  代理连接中断时与 RemoteProtocolError 保持一致的降级处理
This commit is contained in:
fawney19
2026-02-07 20:35:25 +08:00
parent 31bc452374
commit 10bd14c223
3 changed files with 45 additions and 3 deletions
+3 -1
View File
@@ -22,7 +22,9 @@ JWT_SECRET_KEY=change-this-to-a-secure-random-string
ENCRYPTION_KEY=change-this-to-another-secure-random-string ENCRYPTION_KEY=change-this-to-another-secure-random-string
# 代理节点 HMAC 密钥(用于 aether-proxy 认证) # 代理节点 HMAC 密钥(用于 aether-proxy 认证)
# 可选:不设置时会从 ENCRYPTION_KEY 派生(推荐生产环境显式设置) # 可选:不设置时会从 ENCRYPTION_KEY 自动派生
# 显式设置时,aether-proxy.toml 的 hmac_key 配置相同值即可
# 可通过 python generate_keys.py 生成
# PROXY_HMAC_KEY=change-this-to-a-proxy-hmac-key # PROXY_HMAC_KEY=change-this-to-a-proxy-hmac-key
# 管理员账号(仅首次初始化时使用, 创建完成后可在系统内修改密码) # 管理员账号(仅首次初始化时使用, 创建完成后可在系统内修改密码)
+10 -2
View File
@@ -16,15 +16,23 @@ def main():
# 生成 Redis 密码 # 生成 Redis 密码
redis_password = secrets.token_urlsafe(32) redis_password = secrets.token_urlsafe(32)
# 生成代理节点 HMAC 密钥(独立密钥,Aether 服务端和 aether-proxy 配置相同值)
proxy_hmac_key = secrets.token_urlsafe(32)
print("\n将以下内容添加到 .env 文件:\n") print("\n将以下内容添加到 .env 文件:\n")
print(f"JWT_SECRET_KEY={jwt_key}") print(f"JWT_SECRET_KEY={jwt_key}")
print(f"ENCRYPTION_KEY={encryption_key}") print(f"ENCRYPTION_KEY={encryption_key}")
print(f"REDIS_PASSWORD={redis_password}") print(f"REDIS_PASSWORD={redis_password}")
print(f"PROXY_HMAC_KEY={proxy_hmac_key}")
print()
print("将以下内容配置到 aether-proxy.toml:\n")
print(f'hmac_key = "{proxy_hmac_key}"')
print() print()
print("注意:") print("注意:")
print(" - JWT_SECRET_KEY 用于用户身份验证令牌") print(" - JWT_SECRET_KEY 用于用户登录 token 签名")
print(" - ENCRYPTION_KEY 用于敏感数据加密(如Provider API Keys)") print(" - ENCRYPTION_KEY 用于敏感数据加密(如 Provider API Keys)")
print(" - REDIS_PASSWORD 用于 Redis 连接认证(并发控制)") print(" - REDIS_PASSWORD 用于 Redis 连接认证(并发控制)")
print(" - PROXY_HMAC_KEY 用于 aether-proxy 代理请求认证(两端配置相同值)")
print(" - 这些密钥应该独立设置,避免相互耦合") print(" - 这些密钥应该独立设置,避免相互耦合")
print() print()
+32
View File
@@ -1421,6 +1421,22 @@ class CliMessageHandlerBase(BaseMessageHandler):
yield f"event: error\ndata: {json.dumps(error_event)}\n\n".encode() yield f"event: error\ndata: {json.dumps(error_event)}\n\n".encode()
else: else:
raise raise
except httpx.ReadError:
# 代理/上游连接读取失败(如 aether-proxy 中断),与 RemoteProtocolError 处理逻辑一致
self._flush_remaining_sse_data(
ctx, buffer, decoder, sse_parser, record_chunk=not needs_conversion
)
if ctx.data_count > 0:
error_event = {
"type": "error",
"error": {
"type": "connection_error",
"message": "代理或上游连接读取失败,部分响应已成功传输",
},
}
yield f"event: error\ndata: {json.dumps(error_event)}\n\n".encode()
else:
raise
finally: finally:
try: try:
await response_ctx.__aexit__(None, None, None) await response_ctx.__aexit__(None, None, None)
@@ -1962,6 +1978,22 @@ class CliMessageHandlerBase(BaseMessageHandler):
yield f"event: error\ndata: {json.dumps(error_event)}\n\n".encode() yield f"event: error\ndata: {json.dumps(error_event)}\n\n".encode()
else: else:
raise raise
except httpx.ReadError:
# 代理/上游连接读取失败(如 aether-proxy 中断),与 RemoteProtocolError 处理逻辑一致
self._flush_remaining_sse_data(
ctx, buffer, decoder, sse_parser, record_chunk=not needs_conversion
)
if ctx.data_count > 0:
error_event = {
"type": "error",
"error": {
"type": "connection_error",
"message": "代理或上游连接读取失败,部分响应已成功传输",
},
}
yield f"event: error\ndata: {json.dumps(error_event)}\n\n".encode()
else:
raise
finally: finally:
try: try:
await response_ctx.__aexit__(None, None, None) await response_ctx.__aexit__(None, None, None)