mirror of
https://github.com/danny-avila/LibreChat.git
synced 2025-12-16 16:30:15 +01:00
🛡️ : Security Enhancements (#1681)
* fix: sanitize HTTP params and do not send whole error objects backs * fix: prevent path traversal * fix: send custom error message for tokenizer route * chore: handle info exposure vector * chore(oauth): skip check due to false positive as oauth routes are rate-limited * chore(app): disable `x-powered-by` * chore: disable false positives or flagging of hardcoded secrets when they are fake values * chore: add path traversal safety check
This commit is contained in:
parent
9fad1b2cae
commit
972402e029
23 changed files with 72 additions and 28 deletions
|
|
@ -36,7 +36,7 @@ router.put('/:conversationId/:messageId', validateMessageReq, async (req, res) =
|
|||
const { messageId, model } = req.params;
|
||||
const { text } = req.body;
|
||||
const tokenCount = await countTokens(text, model);
|
||||
res.status(201).send(await updateMessage({ messageId, text, tokenCount }));
|
||||
res.status(201).json(await updateMessage({ messageId, text, tokenCount }));
|
||||
});
|
||||
|
||||
// DELETE
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue