Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Add password check for Public URL of published chatbots and agents. #8486

Closed
4 of 5 tasks
YuanfengZhang opened this issue Sep 16, 2024 · 0 comments
Closed
4 of 5 tasks
Labels
💪 enhancement New feature or request

Comments

@YuanfengZhang
Copy link

Self Checks

  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:)
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

While the development page is guarded by the administrator of workspace, the URLs of robots are not protected. If it's online, it will be surely prone to get abused or hacked. If it's embeded on a well-developed commerical website, it can be protected by the authorization systems of the website itself. However, in other cases, at least a password check with attempt limit for every IP address is necessary, to prevent abuse and other malicious behaviors.

2. Additional context or comments

There may be two approaches:

  1. Extend the list of roles of members: Admin, Editor, Normal, User
    The "User" account cannot login the development page, but only permitted to login a specific public URL to use one published robots.
  2. Create the ability to set an unique password for every robot when publishing.

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
@YuanfengZhang YuanfengZhang changed the title Add password check for Public URL of published chatbots and agents. [SECURITY] Add password check for Public URL of published chatbots and agents. Sep 16, 2024
@dosubot dosubot bot added the 💪 enhancement New feature or request label Sep 16, 2024
@crazywoola crazywoola closed this as not planned Won't fix, can't repro, duplicate, stale Sep 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
💪 enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants