diff --git a/main/xiaozhi-server/core/connection.py b/main/xiaozhi-server/core/connection.py index fbd3569e..a8259e34 100644 --- a/main/xiaozhi-server/core/connection.py +++ b/main/xiaozhi-server/core/connection.py @@ -222,19 +222,8 @@ class ConnectionHandler: async def handle_config_update(self, message): """处理配置更新请求""" content = message.get("content", {}) - secret = content.pop("secret", None) new_config = content - # 密钥验证 - if secret != "43c716ae-37c4-49ba-84ab-2f0fbfcd7115": - self.logger.bind(tag=TAG).warning("配置更新请求的密钥不正确") - await self.websocket.send(json.dumps({ - "type": "config_update_response", - "status": "error", - "message": "密钥不正确" - })) - return - # 遍历所有支持的配置模块 updated_modules = [] for config_model in ["tts", "llm", "vad", "asr", "memory", "intent"]: diff --git a/main/xiaozhi-server/core/handle/textHandle.py b/main/xiaozhi-server/core/handle/textHandle.py index a26f5bd9..9afe7b62 100644 --- a/main/xiaozhi-server/core/handle/textHandle.py +++ b/main/xiaozhi-server/core/handle/textHandle.py @@ -64,6 +64,22 @@ async def handleTextMessage(conn, message): if "states" in msg_json: asyncio.create_task(handleIotStatus(conn, msg_json["states"])) elif msg_json["type"] == "server": + # 如果配置是从API读取的,则需要验证secret + read_config_from_api = conn.config.get("read_config_from_api", False) + if not read_config_from_api: + return + # 获取post请求的secret + post_secret = msg_json.get("content", {}).get("secret", "") + secret = conn.config["manager-api"].get("secret", "") + # 如果secret不匹配,则返回 + if post_secret != secret: + await conn.websocket.send(json.dumps({ + "type": "config_update_response", + "status": "error", + "message": "服务器密钥验证失败" + })) + return + # 动态更新配置 if msg_json["action"] == "update_config": await conn.handle_config_update(msg_json) except json.JSONDecodeError: