Files
DocsGPT/docsgpt/api/user
arc53-machine 4f5cd68771 Keep fixed values, tool type and connected servers out of editors' tool saves
/api/update_tool now checks submitted actions against the stored ones the
same way /api/update_tool_actions does: nothing can be added, and only the
tool's owner can change a fixed value. The tool type (name) can no longer
be changed after creation by anyone.

For API tools, changing who fills an existing header, query or body
parameter, its value, or clearing a stored value is now owner-only on both
/api/update_tool and /api/update_tool_config. Before, an editor could hand
a stored secret query value to the model and read it back in the chat.
The chat now masks every value that came from the stored action rather
than from the model.

A connection-backed MCP tool can no longer be moved to another server or
sign-in method through /api/update_tool or /api/update_tool_config (400,
pointing to /api/mcp_server/save), and a new key saved through
/api/update_tool_config goes to its connection, owner only.
2026-09-29 14:11:36 +01:00
..
2026-09-29 10:42:39 +04:00
2026-09-29 10:42:39 +04:00
2026-09-29 10:42:39 +04:00
2026-09-29 10:42:39 +04:00
2026-09-29 14:48:18 +04:00
2026-09-29 14:48:18 +04:00
2026-09-29 10:42:39 +04:00
2026-09-29 10:42:39 +04:00