mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-04 10:13:06 +00:00
Source access control --------------------- `active_docs` is client-supplied and reached the retriever unchecked, and the retriever queries `WHERE source_id = <id>` with no owner predicate — so any caller could pass any source id to /stream or /api/answer and have another tenant's documents quoted back, while /api/sources/<id>/search correctly refused the same id. Gate it through `can_access`, the helper the guarded endpoints already use, and filter `self.source` down to the authorized set. Fails closed: no principal, or a check that errors, drops the source. Three sibling paths had the same gap: - workflow agent nodes: `AgentNodeConfig.sources` is written verbatim from client JSON at save time and nothing validated it, so a node could name any tenant's source. Gate against the workflow owner, so shared workflows keep reading their owner's sources like shared agents do. - /api/share: `_resolve_source_pg_id` resolved any id with no ownership predicate and baked it into the agent the share creates; /api/search then searched it. Authorize before attaching. - search_service: re-resolve the ids stored on an agent row instead of trusting them, so a row written by any future path with the same gap cannot be read back. Team grantees previously lost their source's retrieval config: the post-check read was still owner-scoped, so it missed and fell back to defaults (an `agentic_tool` source was bulk-prefetched for every grantee). Read unscoped after `can_access` passes. Retrieval --------- `PGVectorStore._ensure_table_exists` created an IVFFlat index on the empty table it had just created. IVFFlat computes centroids at build time, so those centroids were random, and combined with the `source_id` post-filter a source with hundreds of embedded chunks returned zero rows — retrieval reported no documents, the model answered from memory, and nothing was logged. Stop creating the index (exact search is correct and fast well past the sizes most deployments reach); raise `ivfflat.probes` to sqrt(lists) where an index still exists; and re-run a short indexed search exactly, since post-filtering means no index setting can guarantee a full result. `graphrag` had the same empty-table index with no fallback at all. Also: bound `chunks` to 0-500 on both the request and agent paths (0 still means "skip retrieval"), let a source's configured `retrieval.chunks` outrank the request body, and cap ClassicRAG's per-source floor at max(top_k, n_sources) so attaching sources cannot inflate the result set. Silent failures --------------- An empty retrieval was invisible to both the model and the client: the `source` event was suppressed when the list was empty, so "searched and found nothing" looked identical to "no source attached", and the prompt said nothing at all. Emit the event always, and tell the model when a search ran and returned nothing. A file that parses to nothing now fails ingest with a message naming the cause instead of storing an embedding of the empty string. `score_threshold` returns warnings when the active store or retriever cannot honour it. Prompt structure ---------------- Retrieved documents move from the system prompt into the user turn, with the injection guard restated next to them: they change every turn (defeating prefix caching), they are third-party text that should not carry system authority, and routing them through the query budget makes them truncatable rather than silently crowding it out. Documents are shed lowest-ranked-first before the question is touched. The six chat presets (3 tones x 2 retrieval modes) differed only in their Answering section; they are now composed from single-source fragments at load time, not through Jinja inheritance, which would have opened a file-read surface in the template sandbox and broken the tool-prefetch parser. Per-tool guidance moves out of the prompt into tool schemas, so it travels with the tool and cannot render when the tool is absent. A plain-text custom prompt is staged as a persona value inside the skeleton instead of replacing it wholesale — it used to silently lose the injection guard, platform block, memory and attachments, and its braces are now inert. Other fixes ----------- - agents/base: an oversized system prompt drove the query budget negative and dispatched a full-price request with an empty question; raise instead. - llm/anthropic: migrate off the retired Text Completions API. It flattened history to first+last message and ignored tools entirely. Adds the missing Anthropic handler, without which every tool call was silently dropped. - sources/upload: `sitemap` had no branch, so every sitemap ingest died on a TypeError; `validate_url` now rejects a falsy URL cleanly. - workflow nodes: retrieved documents never reached the node agent, so a classic node with a source and an ordinary prompt answered "I have no documents" while the run reported completed. - parser/bulk: copy the metadata dict, or every chunk reports the last chunk's token_count. - crawler_loader: carry the page title, or citations render the whole chunk body as the label.
191 lines
7.1 KiB
Python
191 lines
7.1 KiB
Python
import logging
|
|
from typing import Any, Dict, Optional
|
|
|
|
from application.templates.namespaces import NamespaceManager
|
|
|
|
from application.templates.template_engine import TemplateEngine, TemplateRenderError
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
# Legacy prompts that interpolate the retrieved documents into the system
|
|
# prompt themselves. Documents now travel with the user turn, so a prompt
|
|
# using any of these keeps its old behaviour and suppresses the new block
|
|
# rather than receiving the documents twice.
|
|
# ``SourceNamespace.build`` exposes five document-bearing keys; ``documents``
|
|
# is the documented way to write a custom citation loop, so it must be here
|
|
# too. Subscript/alias forms (``source['summaries']``) are not detectable by
|
|
# substring and fall through to the user-turn block — that degrades to sending
|
|
# the documents twice, never to sending them nowhere.
|
|
_DOCUMENT_EMBEDDING_MARKERS = (
|
|
"source.summaries",
|
|
"source.content",
|
|
"source.docs_together",
|
|
"source.documents",
|
|
"{summaries}",
|
|
)
|
|
|
|
|
|
def prompt_embeds_documents(prompt_content: Optional[str]) -> bool:
|
|
"""Return True when the prompt injects the retrieved documents itself.
|
|
|
|
Args:
|
|
prompt_content: The raw (unrendered) prompt template.
|
|
|
|
Returns:
|
|
bool: True if the template references a document-bearing variable.
|
|
"""
|
|
if not prompt_content:
|
|
return False
|
|
return any(marker in prompt_content for marker in _DOCUMENT_EMBEDDING_MARKERS)
|
|
|
|
|
|
def format_docs_for_prompt(docs: Optional[list]) -> Optional[str]:
|
|
"""Format retrieved chunks as XML-tagged documents for prompt injection.
|
|
|
|
Each chunk is wrapped in a ``<document index="n">`` block with a
|
|
``<source>`` subtag (when a filename/title is known) so the model can
|
|
tell chunks apart and cite them by name.
|
|
"""
|
|
if not docs:
|
|
return None
|
|
parts = []
|
|
for i, doc in enumerate(docs, start=1):
|
|
source = doc.get("filename") or doc.get("title") or doc.get("source")
|
|
lines = [f'<document index="{i}">']
|
|
if source:
|
|
lines.append(f"<source>{source}</source>")
|
|
lines.append(f"<content>\n{doc.get('text', '')}\n</content>")
|
|
lines.append("</document>")
|
|
parts.append("\n".join(lines))
|
|
return "\n\n".join(parts)
|
|
|
|
|
|
def resolve_prompt_skeleton(
|
|
content: Optional[str], prompt_id: str, agent_type: Optional[str] = None
|
|
) -> tuple[Optional[str], Optional[str]]:
|
|
"""Split a resolved prompt into a template and an optional persona value.
|
|
|
|
A custom prompt with no template syntax used to take a legacy path that
|
|
substituted ``{summaries}`` and nothing else — so it silently shipped
|
|
without the Boundaries rule (the prompt-injection guard), the platform
|
|
block, the memory section or the attachment list. Staging it as a *value*
|
|
inside the composed skeleton keeps all of those, and braces in the
|
|
operator's text stay literal instead of being evaluated.
|
|
|
|
Templated custom prompts are left alone: their authors opted into the
|
|
namespaces and rely on them.
|
|
|
|
Args:
|
|
content: The raw prompt text resolved for this agent.
|
|
prompt_id: The id it was resolved from.
|
|
agent_type: Selects the classic or agentic skeleton.
|
|
|
|
Returns:
|
|
tuple: ``(template, persona)`` — ``persona`` is None when ``content``
|
|
is already a usable template.
|
|
"""
|
|
from application.prompts.composer import compose_preset, is_composed_preset
|
|
|
|
if not content or is_composed_preset(prompt_id) or prompt_id == "reduce":
|
|
return content, None
|
|
if "{{" in content and "}}" in content:
|
|
return content, None
|
|
# A legacy prompt whose only marker is ``{summaries}`` still needs the
|
|
# legacy substitution; as a persona value it would ship verbatim.
|
|
if prompt_embeds_documents(content):
|
|
return content, None
|
|
skeleton = (
|
|
"agentic_default" if agent_type in ("agentic", "research") else "default"
|
|
)
|
|
return compose_preset(skeleton), content
|
|
|
|
|
|
class PromptRenderer:
|
|
"""Service for rendering prompts with dynamic context using namespaces"""
|
|
|
|
def __init__(self):
|
|
self.template_engine = TemplateEngine()
|
|
self.namespace_manager = NamespaceManager()
|
|
|
|
def render_prompt(
|
|
self,
|
|
prompt_content: str,
|
|
user_id: Optional[str] = None,
|
|
request_id: Optional[str] = None,
|
|
passthrough_data: Optional[Dict[str, Any]] = None,
|
|
docs: Optional[list] = None,
|
|
docs_together: Optional[str] = None,
|
|
tools_data: Optional[Dict[str, Any]] = None,
|
|
**kwargs,
|
|
) -> str:
|
|
"""
|
|
Render prompt with full context from all namespaces.
|
|
|
|
Args:
|
|
prompt_content: Raw prompt template string
|
|
user_id: Current user identifier
|
|
request_id: Unique request identifier
|
|
passthrough_data: Parameters from web request
|
|
docs: RAG retrieved documents
|
|
docs_together: Concatenated document content
|
|
tools_data: Pre-fetched tool results organized by tool name
|
|
**kwargs: Additional parameters for namespace builders
|
|
|
|
Returns:
|
|
Rendered prompt string with all variables substituted
|
|
|
|
Raises:
|
|
TemplateRenderError: If template rendering fails
|
|
"""
|
|
if not prompt_content:
|
|
return ""
|
|
|
|
uses_template = self._uses_template_syntax(prompt_content)
|
|
|
|
if not uses_template:
|
|
return self._apply_legacy_substitutions(prompt_content, docs_together)
|
|
|
|
try:
|
|
context = self.namespace_manager.build_context(
|
|
user_id=user_id,
|
|
request_id=request_id,
|
|
passthrough_data=passthrough_data,
|
|
docs=docs,
|
|
docs_together=docs_together,
|
|
tools_data=tools_data,
|
|
**kwargs,
|
|
)
|
|
|
|
return self.template_engine.render(prompt_content, context)
|
|
except TemplateRenderError:
|
|
raise
|
|
except Exception as e:
|
|
error_msg = f"Prompt rendering failed: {str(e)}"
|
|
logger.error(error_msg)
|
|
raise TemplateRenderError(error_msg) from e
|
|
|
|
def _uses_template_syntax(self, prompt_content: str) -> bool:
|
|
"""Check if prompt uses Jinja2 template syntax"""
|
|
return "{{" in prompt_content and "}}" in prompt_content
|
|
|
|
def _apply_legacy_substitutions(
|
|
self, prompt_content: str, docs_together: Optional[str] = None
|
|
) -> str:
|
|
"""
|
|
Apply backward-compatible substitutions for old prompt format.
|
|
|
|
Handles the legacy {summaries} placeholder. When no documents were
|
|
retrieved the placeholder is removed so the model never sees the
|
|
raw template artifact.
|
|
"""
|
|
return prompt_content.replace("{summaries}", docs_together or "")
|
|
|
|
def validate_template(self, prompt_content: str) -> bool:
|
|
"""Validate prompt template syntax"""
|
|
return self.template_engine.validate_template(prompt_content)
|
|
|
|
def extract_variables(self, prompt_content: str) -> set[str]:
|
|
"""Extract all variable names from prompt template"""
|
|
return self.template_engine.extract_variables(prompt_content)
|