feat: support gated/private Hugging Face repos via access token

Add a huggingface_api_key setting (Settings UI, HF_TOKEN /
HUGGING_FACE_HUB_TOKEN env override) and attach it as a Bearer token
to Hugging Face file listing, model card fetching and downloads, so
gated and private repositories can be downloaded once the user has
accepted the repo terms.

- fetch_json/fetch_text accept custom headers; ModelSource gains an
  auth_headers() hook so handlers stay platform-agnostic
- 401/403 from the tree API now explain how to fix (configure token /
  accept gated terms)
- aria2 pre-resolves huggingface.co redirects and strips credentials
  before handing the signed CDN URL to aria2, mirroring the CivitAI
  handling so the token never leaks to the CDN
- settings API exposes huggingface_api_key_set only; the raw key joins
  _NO_SYNC_KEYS
This commit is contained in:
Will Miao
2026-09-25 18:44:06 +08:00
parent 067e605e75
commit 8b7ba59263
23 changed files with 446 additions and 23 deletions
+6
View File
@@ -325,6 +325,12 @@
"civitaiApiKeyConfigured": "Настроен",
"civitaiApiKeyNotConfigured": "Не настроен",
"civitaiApiKeySet": "Настроить",
"huggingfaceApiKey": "[TODO: Translate] Hugging Face Access Token",
"huggingfaceApiKeyPlaceholder": "[TODO: Translate] Enter your Hugging Face access token",
"huggingfaceApiKeyHelp": "[TODO: Translate] Required to download from gated or private Hugging Face repositories. Create a read-only token at huggingface.co/settings/tokens, and accept the repository's terms on its page first.",
"huggingfaceApiKeyConfigured": "[TODO: Translate] Configured",
"huggingfaceApiKeyNotConfigured": "[TODO: Translate] Not configured",
"huggingfaceApiKeySet": "[TODO: Translate] Set up",
"civitaiHost": {
"label": "Хост CivitAI",
"help": "Выберите, какой сайт CivitAI будет открываться при использовании ссылок «View on CivitAI».",