θΏ™ζ˜―indexlocζδΎ›ηš„ζœεŠ‘οΌŒδΈθ¦θΎ“ε…₯任何密码
Skip to content

Conversation

@timothycarambat
Copy link
Member

Pull Request Type

  • ✨ feat
  • πŸ› fix
  • ♻️ refactor
  • πŸ’„ style
  • πŸ”¨ chore
  • πŸ“ docs

What is in this change?

Managers could in theory send and HTTP request to update the LLM,Embedder, etc with their token and still update the envs. This was originally just a UI hide until we decided manager role should be fully scoped to stop this. Now it is just enforced in the backend as well.

Developer Validations

  • I ran yarn lint from the root of the repo & committed changes
  • Relevant documentation has been updated
  • I have tested my code functionality
  • Docker build succeeds locally

@timothycarambat timothycarambat merged commit 7200a06 into master Jan 11, 2024
@timothycarambat timothycarambat deleted the security/manager-perm-env-check branch January 11, 2024 20:11
AStevensTaylor pushed a commit to PacktDev/anything-llm that referenced this pull request Jan 12, 2024
…s#576)

* prevent manager in multi-user from updatingENV via HTTP

* remove unneeded args
cabwds pushed a commit to cabwds/anything-llm that referenced this pull request Jul 3, 2025
…s#576)

* prevent manager in multi-user from updatingENV via HTTP

* remove unneeded args
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants