mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-03 20:12:55 +00:00
PinAgent looked agents up with no ownership, share or team predicate, and PinnedAgents returned those rows through a hand-rolled dict that bypassed the blanking _format_agent_output applies. Anyone holding an agent id -- a share-link recipient learns the real UUID -- could pin it and keep reading its name, description, prompt, tools, type, status and masked key after the share was revoked. Add _user_may_pin: the owner, a team grantee, a recipient of a still-live share link, or a system template. PinAgent checks it before pinning and PinnedAgents re-checks every row on read, so a revoked grant drops out of the list instead of persisting. Unpinning stays open regardless of current access, or a revoked share would strand a pin the user cannot clear. The masked key is now owner-only, matching _format_agent_output. Adds the first cross-user pin tests: every existing one pinned the caller's own agent.