Files
dsh_ai1net_server/poc/im-connection-gateway/config.json
T
admin e6207aa691
build / build-and-scan (push) Canceled after 0s
chore(仓库对齐): 文档库结构治理 + IM/插件线落地
文档库:目录改为编号制(01-规范/02-架构设计/03-数据库/04-调整方案/
05-交接单/06-ops/07-scripts/08-skills/09-archive),顶层散文件归入 01-规范/;
INDEX.md 与 docs-manifest.json 重刷(档案 146 篇);旧目录名引用全量对齐。

IM 线:src/im/**(SDK / hub / store / presence / ws / gateway-token)、
src/web/routes/im.ts、src/db/plugin-data/**、src/supervisor/plugin-assembly.ts
及对应 test/**。

插件线:poc/{im-agent-bridge,im-connection-gateway,im-conversation-tabs,
business-plugins-im,carbon-mcp-probe}、src/web/routes/{sessions,overlay-device}.ts、
src/net/relay/{device-grant,instance-credential}.ts。

仓库卫生:清出 40 个历史误入库 / 已改名文件(34 个交接单归档 + 6 个旧结构,
本地均有副本);dsh-server-docs/.gitignore 补 tmp/;交接单不入库(政策)。
2026-09-24 07:25:16 +08:00

59 lines
4.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"_comment": "IM 线 · 第 12 棒 —— 外部连接层的参考部署配置(Centrifugo v6)。",
"_comment2": "键位以 E-2 实测可用的 /root/im-e2/config.json 为准(v6 已把密钥挪进 client.token / http_api)。",
"_comment3": "凭据一律用环境变量或密钥文件注入,⛔ 不要把这个文件里的占位串当真值提交到生产。",
"_comment4": "package.json 的运行时依赖**不含**本组件 —— 它是外部进程,不在 Node 依赖树里。",
"client": {
"allowed_origins": ["*"],
"_comment_ping": "🔻 第 15 棒部署实测修正:原值 `0s` 会让客户端保活帧被判 bad request —— 没有待回的 ping 时,协议里的 `{}` 是**空命令**而非 pong。三向实测(47 就地部署,240 连接):off(从不回帧)⇒ 80/80 被断开(code 3012 `no pong`);conn(**按每连接**收到 ping 才回 `{}`)⇒ **掉 0**;global(整进程一个节拍器给所有连接发 `{}`)⇒ 80/80 被断开(code 3501 `bad request`)。⇒ 网关**自己发协议级 ping**,客户端只需按连接回 `{}`。",
"ping_interval": "25s",
"token": {
"hmac_secret_key": "REPLACE_WITH_ROTATED_SECRET"
}
},
"http_api": {
"key": "REPLACE_WITH_ROTATED_SECRET"
},
"channel": {
"_comment_proxy": "🔻 第 16 棒新增(选型单 §十六):**订阅回检** —— 客户端订某个频道时,**由平台**回答「这个用户能不能读这个房」。⛔ 不加这一段的话,连接票据只回答「你是谁」,任何登录用户都能订 `im:<任意房间>` 并收到该房实时消息 ⇒ 「成员表判读房」这条会被破掉。`endpoint` 指平台回检面(回环即可:网关与平台同机);头里的密钥必须与 `http_api.key` / `client.token.hmac_secret_key` / 平台 drop-in 的 `DSH_IM_GATEWAY_KEY` **四者同值**。⚠️ 这个共享密钥必须放 `http.static_headers`(**固定值头**),⛔ **不能**放 `http_headers` —— `http_headers` 是 `array[string]` 且元素**只是头名**(转发客户端带来的同名头);拿它塞 `\"Name: value\"` 会变成「带名无值」,平台侧取不到密钥 ⇒ 回检 401(v6.9.6 实测 `error proxying subscribe: unexpected HTTP status code: 401`)。",
"proxy": {
"subscribe": {
"endpoint": "http://127.0.0.1:3080/api/im/gateway/subscribe",
"timeout": "2s",
"http": {
"static_headers": { "X-DSH-IM-Gateway-Key": "REPLACE_WITH_ROTATED_SECRET" }
}
}
},
"namespaces": [
{
"_comment": "命名空间 = 频道名里第一个 `:` 之前的部分 ⇒ 配合 DSH_IM_GATEWAY_CHANNEL_PREFIX=im: 使用。",
"name": "im",
"_comment2": "🔻 第 16 棒修正:`allow_subscribe_for_client` 只是「已认证连接可以不带 token 订阅」,**不是**权限判定;真正的授权走 `subscribe_proxy_enabled`(平台判成员表)或平台签发的订阅票据(带 token 时 token 优先,代理不参与)。两者都由**平台**裁决 ⇒ 保留 `true`。",
"allow_subscribe_for_client": true,
"_comment6": "🔻 第 16 棒新增:打开订阅回检。⚠️ 它不是「可选优化」—— 关掉它,任何登录用户都能订任意 `im:*` 频道。",
"subscribe_proxy_enabled": true,
"_comment3": "presence / join_leave 是**在线态取数**的候选来源(第 15 棒已接线平台侧;⚠️ 网关侧尚无 join/leave 回调调用方,见 §六 已知限)。",
"presence": true,
"join_leave": true,
"_comment4": "history 只作断线**加速**,⛔ 不是游标权威 —— 权威在平台 GET /api/im/rooms/:id/messages。",
"history_size": 100,
"history_ttl": "300s",
"_comment5": "🔻 第 15 棒修正(原文:⛔ 不启用服务端 WS ping):网关**要**发协议级 ping(见上方 `_comment_ping`);「不发 WS ping」这条实测本身没错(`wsPingRecv=0` 数的是 **WS 控制帧**),错的是由它推出的结论 —— 协议级 ping 照样存在,且客户端必须按连接回 `{}`。",
"force_push_join_leave": false
}
]
},
"prometheus": {
"enabled": true
},
"log": {
"level": "info"
}
}