Files
DocsGPT/tests
Alex cdc0a0220d Harden the Jupyter sandbox runner against env-secret exposure
Run each kernel under a scrubbed environment so untrusted code can never read
the host's secrets. A custom 'docsgpt-python' kernelspec launches ipykernel
through a wrapper that keeps only what the kernel needs (PATH, HOME, LANG, and
the Jupyter runtime/data dirs), dropping API keys, tokens, the database URL, and
the gateway token. The app selects this kernel by name via SANDBOX_KERNEL_NAME,
so the distinct name is never shadowed by the stock python3 spec. Per-session
workspaces are created mode 0700 (defense in depth under the shared uid). The
README documents the runner as a single trust domain and points to the Daytona
backend for per-tenant isolation.
2026-06-24 23:13:58 +01:00
..
2026-06-08 15:07:31 +01:00
2026-06-12 18:19:15 +04:00
2026-06-14 21:36:07 +01:00
2026-04-18 13:13:57 +01:00
2026-03-30 16:13:08 +01:00
2026-06-23 20:10:41 +01:00
2026-03-12 14:46:26 +00:00
2026-05-15 12:23:31 +01:00
2026-04-18 13:13:57 +01:00
2026-04-18 13:13:57 +01:00
2026-04-27 22:09:33 +01:00
2026-06-14 21:36:07 +01:00
2026-05-15 12:23:31 +01:00
2026-03-30 16:13:08 +01:00
2026-01-22 13:11:24 +02:00
2026-04-18 13:13:57 +01:00
2026-06-16 09:21:21 +01:00
2026-04-18 13:13:57 +01:00
2026-04-18 13:13:57 +01:00
2026-06-16 18:08:04 +01:00
2026-04-21 14:22:32 +01:00
2026-04-18 13:13:57 +01:00