mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-05 04:13:25 +00:00
An agent called with its API key (widget, API) runs as its owner, and nobody can approve an action there, so a write set to Always allow ran on the owner's account for anyone holding the key. A caller is external when the request carries the key and is not signed in as the owner (an owner previewing their agent keeps full access). For external callers, write actions on connection-backed tools are refused unless listed in the agent config's new api_write_allowlist (tool_id:action), and a missing connection is refused instead of pausing on a Connect card the widget cannot show. The flag and list survive a paused-and-resumed stream. Owners pick the allowed actions under Access details; a team editor's update keeps the stored list.