LibreChat/api/server
Danny Avila f0978e7d70 🔒 fix: Keep generated code artifacts user-scoped when re-provisioning
Code outputs are recorded with kind: 'user' at generation time, but the
provisioning scope predicate treated any context other than message_attachment
as agent-scoped. An expired artifact re-provisioned on a later turn was
therefore uploaded into the agent's shared sandbox, exposing one user's private
conversation artifact to every user of a shared agent. Both the provisioning
writer and the tool-resource reconstruction now share one predicate that treats
execute_code outputs as user-scoped alongside chat attachments.
2026-08-31 08:38:05 -04:00
..
controllers 🧳 feat: Register Principal-Owned Code Environments (#15365) 2026-08-30 19:33:19 -04:00
middleware 🪢 feat: show Langfuse session link in shared chats (#15273) 2026-08-27 14:29:57 -04:00
routes 🧳 feat: Register Principal-Owned Code Environments (#15365) 2026-08-30 19:33:19 -04:00
services 🔒 fix: Keep generated code artifacts user-scoped when re-provisioning 2026-08-31 08:38:05 -04:00
utils 🎟️ refactor: Require Credentials for Local Image Access by Default (#15252) 2026-08-27 09:55:27 -04:00
cleanup.js
csp.spec.js 🔣 fix: Escape SPA Language Attribute (#15248) 2026-08-26 07:37:36 -04:00
experimental.js 🧳 feat: Register Principal-Owned Code Environments (#15365) 2026-08-30 19:33:19 -04:00
experimental.spec.js 🧾 feat: Store Durable Event Actor Receipts (#15265) 2026-08-27 06:00:43 -04:00
index.js 🔧 feat: Unified file upload — per-mime-type routing with lazy provisioning 2026-08-30 20:12:09 -04:00
index.metrics.spec.js ⏱️ feat: Run Scheduled Chats Through Durable Agent Triggers (#14939) 2026-08-20 11:51:30 -04:00
index.spec.js 🦺 feat: Configurable Baseline HTTP Security Headers (#14445) 2026-08-25 08:21:39 -04:00
socialLogins.js feat: Make OpenID Token Reuse Window Configurable (#13546) 2026-06-06 15:15:58 -04:00
socialLogins.spec.js feat: Make OpenID Token Reuse Window Configurable (#13546) 2026-06-06 15:15:58 -04:00
telemetry.js
telemetry.spec.js