mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-04 22:13:08 +00:00
When code_executor or read_document is given an input that doesn't resolve to an existing artifact, it now falls back to the caller's own chat attachments, bridges the referenced one into a conversation-scoped artifact (idempotent, server-computed size/sha256, quota-respected), and stages it. This is lazy — plain chat uploads are never bridged, only a file a tool actually references — and conversation-scoped only (workflow nodes bridge attachments up front). The match is confined to the request's own attachments and re-verified against the user-scoped attachments repo, so a model-supplied name/id can only ever reach the caller's own files. Only the current request's attachments are reachable (the attachments table has no conversation column); prior-turn files are a follow-up.