Files
DocsGPT/docsgpt/agents/tools
arc53-machine daf6af57ae Keep outside callers' write limits in scheduled and webhook runs
A scheduled or webhook run acts as the agent's owner with no one to
approve, so a public-link user or API-key caller could have the agent
schedule a write and have it run on the owner's accounts. Runs now keep
the caller's rules: a schedule set by someone who reaches the agent only
by its public link runs as a public-link caller, one set through the API
(recorded as created_via 'api', migration 0042) and every webhook run as
an external caller, each with the agent's API write allowlist.
2026-09-29 15:44:24 +01:00
..
2026-09-28 17:03:09 +01:00
2026-09-28 17:03:09 +01:00
2026-09-28 17:03:09 +01:00
2026-09-29 10:42:39 +04:00