🛡️ fix: Enhance File Upload Security & Error Handling (#4705)

* fix: sanitize filename in multer storage callback

* fix: ensure temporary image upload file is deleted after processing

* fix: prevent cleanup flag from being set to false before actually deleted

* refactor: user avatar, typing, use 'file' for formData instead of 'input', add disk storage, use localization

* fix: update Avatar component to include image dimensions in formData and refactor editor reference type

* fix: refactor avatar upload handling to use fs for file reading and enhance file validation

* fix: ensure temporary image upload file is deleted after processing

* fix: refactor avatar upload routes and handlers for agents and assistants, improve file handling and validation

* fix: improve audio file validation and cleanup

* fix: add filename sanitization utility and integrate it into multer storage configuration

* fix: update group project ID check for null and refactor delete prompt group response type

* fix: invalid access control for deleting prompt groups

* fix: add error handling and logging to checkBan middleware

* fix: catch conversation parsing errors

* chore: revert unnecessary height and width parameters from avatar upload

* chore: update librechat-data-provider version to 0.7.55

* style: ensure KaTeX can spread across visible space
This commit is contained in:
Danny Avila 2024-11-12 16:41:04 -05:00 committed by GitHub
parent 3c94ff2c04
commit d012da0065
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
33 changed files with 373 additions and 186 deletions

View file

@ -92,7 +92,7 @@ const createAllGroupsPipeline = (
/** /**
* Get all prompt groups with filters * Get all prompt groups with filters
* @param {Object} req * @param {ServerRequest} req
* @param {TPromptGroupsWithFilterRequest} filter * @param {TPromptGroupsWithFilterRequest} filter
* @returns {Promise<PromptGroupListResponse>} * @returns {Promise<PromptGroupListResponse>}
*/ */
@ -142,7 +142,7 @@ const getAllPromptGroups = async (req, filter) => {
/** /**
* Get prompt groups with filters * Get prompt groups with filters
* @param {Object} req * @param {ServerRequest} req
* @param {TPromptGroupsWithFilterRequest} filter * @param {TPromptGroupsWithFilterRequest} filter
* @returns {Promise<PromptGroupListResponse>} * @returns {Promise<PromptGroupListResponse>}
*/ */
@ -213,8 +213,34 @@ const getPromptGroups = async (req, filter) => {
} }
}; };
/**
* @param {Object} fields
* @param {string} fields._id
* @param {string} fields.author
* @param {string} fields.role
* @returns {Promise<TDeletePromptGroupResponse>}
*/
const deletePromptGroup = async ({ _id, author, role }) => {
const query = { _id, author };
const groupQuery = { groupId: new ObjectId(_id), author };
if (role === SystemRoles.ADMIN) {
delete query.author;
delete groupQuery.author;
}
const response = await PromptGroup.deleteOne(query);
if (!response || response.deletedCount === 0) {
throw new Error('Prompt group not found');
}
await Prompt.deleteMany(groupQuery);
await removeGroupFromAllProjects(_id);
return { message: 'Prompt group deleted successfully' };
};
module.exports = { module.exports = {
getPromptGroups, getPromptGroups,
deletePromptGroup,
getAllPromptGroups, getAllPromptGroups,
/** /**
* Create a prompt and its respective group * Create a prompt and its respective group
@ -510,20 +536,4 @@ module.exports = {
return { message: 'Error updating prompt labels' }; return { message: 'Error updating prompt labels' };
} }
}, },
deletePromptGroup: async (_id) => {
try {
const response = await PromptGroup.deleteOne({ _id });
if (response.deletedCount === 0) {
return { promptGroup: 'Prompt group not found' };
}
await Prompt.deleteMany({ groupId: new ObjectId(_id) });
await removeGroupFromAllProjects(_id);
return { promptGroup: 'Prompt group deleted successfully' };
} catch (error) {
logger.error('Error deleting prompt group', error);
return { message: 'Error deleting prompt group' };
}
},
}; };

View file

@ -1,3 +1,4 @@
const fs = require('fs').promises;
const { nanoid } = require('nanoid'); const { nanoid } = require('nanoid');
const { FileContext, Constants, Tools, SystemRoles } = require('librechat-data-provider'); const { FileContext, Constants, Tools, SystemRoles } = require('librechat-data-provider');
const { const {
@ -7,8 +8,8 @@ const {
deleteAgent, deleteAgent,
getListAgents, getListAgents,
} = require('~/models/Agent'); } = require('~/models/Agent');
const { uploadImageBuffer, filterFile } = require('~/server/services/Files/process');
const { getStrategyFunctions } = require('~/server/services/Files/strategies'); const { getStrategyFunctions } = require('~/server/services/Files/strategies');
const { uploadImageBuffer } = require('~/server/services/Files/process');
const { getProjectByName } = require('~/models/Project'); const { getProjectByName } = require('~/models/Project');
const { updateAgentProjects } = require('~/models/Agent'); const { updateAgentProjects } = require('~/models/Agent');
const { deleteFileByFilter } = require('~/models/File'); const { deleteFileByFilter } = require('~/models/File');
@ -210,7 +211,7 @@ const getListAgentsHandler = async (req, res) => {
/** /**
* Uploads and updates an avatar for a specific agent. * Uploads and updates an avatar for a specific agent.
* @route POST /avatar/:agent_id * @route POST /:agent_id/avatar
* @param {object} req - Express Request * @param {object} req - Express Request
* @param {object} req.params - Request params * @param {object} req.params - Request params
* @param {string} req.params.agent_id - The ID of the agent. * @param {string} req.params.agent_id - The ID of the agent.
@ -221,17 +222,17 @@ const getListAgentsHandler = async (req, res) => {
*/ */
const uploadAgentAvatarHandler = async (req, res) => { const uploadAgentAvatarHandler = async (req, res) => {
try { try {
filterFile({ req, file: req.file, image: true, isAvatar: true });
const { agent_id } = req.params; const { agent_id } = req.params;
if (!agent_id) { if (!agent_id) {
return res.status(400).json({ message: 'Agent ID is required' }); return res.status(400).json({ message: 'Agent ID is required' });
} }
const buffer = await fs.readFile(req.file.path);
const image = await uploadImageBuffer({ const image = await uploadImageBuffer({
req, req,
context: FileContext.avatar, context: FileContext.avatar,
metadata: { metadata: { buffer },
buffer: req.file.buffer,
},
}); });
let _avatar; let _avatar;
@ -239,7 +240,7 @@ const uploadAgentAvatarHandler = async (req, res) => {
const agent = await getAgent({ id: agent_id }); const agent = await getAgent({ id: agent_id });
_avatar = agent.avatar; _avatar = agent.avatar;
} catch (error) { } catch (error) {
logger.error('[/avatar/:agent_id] Error fetching agent', error); logger.error('[/:agent_id/avatar] Error fetching agent', error);
_avatar = {}; _avatar = {};
} }
@ -249,7 +250,7 @@ const uploadAgentAvatarHandler = async (req, res) => {
await deleteFile(req, { filepath: _avatar.filepath }); await deleteFile(req, { filepath: _avatar.filepath });
await deleteFileByFilter({ user: req.user.id, filepath: _avatar.filepath }); await deleteFileByFilter({ user: req.user.id, filepath: _avatar.filepath });
} catch (error) { } catch (error) {
logger.error('[/avatar/:agent_id] Error deleting old avatar', error); logger.error('[/:agent_id/avatar] Error deleting old avatar', error);
} }
} }
@ -270,6 +271,13 @@ const uploadAgentAvatarHandler = async (req, res) => {
const message = 'An error occurred while updating the Agent Avatar'; const message = 'An error occurred while updating the Agent Avatar';
logger.error(message, error); logger.error(message, error);
res.status(500).json({ message }); res.status(500).json({ message });
} finally {
try {
await fs.unlink(req.file.path);
logger.debug('[/:agent_id/avatar] Temp. image upload file deleted');
} catch (error) {
logger.debug('[/:agent_id/avatar] Temp. image upload file already deleted');
}
} }
}; };

View file

@ -1,9 +1,10 @@
const fs = require('fs').promises;
const { FileContext } = require('librechat-data-provider'); const { FileContext } = require('librechat-data-provider');
const { uploadImageBuffer, filterFile } = require('~/server/services/Files/process');
const validateAuthor = require('~/server/middleware/assistants/validateAuthor'); const validateAuthor = require('~/server/middleware/assistants/validateAuthor');
const { getStrategyFunctions } = require('~/server/services/Files/strategies'); const { getStrategyFunctions } = require('~/server/services/Files/strategies');
const { deleteAssistantActions } = require('~/server/services/ActionService'); const { deleteAssistantActions } = require('~/server/services/ActionService');
const { updateAssistantDoc, getAssistants } = require('~/models/Assistant'); const { updateAssistantDoc, getAssistants } = require('~/models/Assistant');
const { uploadImageBuffer } = require('~/server/services/Files/process');
const { getOpenAIClient, fetchAssistants } = require('./helpers'); const { getOpenAIClient, fetchAssistants } = require('./helpers');
const { deleteFileByFilter } = require('~/models/File'); const { deleteFileByFilter } = require('~/models/File');
const { logger } = require('~/config'); const { logger } = require('~/config');
@ -235,7 +236,7 @@ const getAssistantDocuments = async (req, res) => {
/** /**
* Uploads and updates an avatar for a specific assistant. * Uploads and updates an avatar for a specific assistant.
* @route POST /avatar/:assistant_id * @route POST /:assistant_id/avatar
* @param {object} req - Express Request * @param {object} req - Express Request
* @param {object} req.params - Request params * @param {object} req.params - Request params
* @param {string} req.params.assistant_id - The ID of the assistant. * @param {string} req.params.assistant_id - The ID of the assistant.
@ -245,6 +246,7 @@ const getAssistantDocuments = async (req, res) => {
*/ */
const uploadAssistantAvatar = async (req, res) => { const uploadAssistantAvatar = async (req, res) => {
try { try {
filterFile({ req, file: req.file, image: true, isAvatar: true });
const { assistant_id } = req.params; const { assistant_id } = req.params;
if (!assistant_id) { if (!assistant_id) {
return res.status(400).json({ message: 'Assistant ID is required' }); return res.status(400).json({ message: 'Assistant ID is required' });
@ -253,12 +255,11 @@ const uploadAssistantAvatar = async (req, res) => {
const { openai } = await getOpenAIClient({ req, res }); const { openai } = await getOpenAIClient({ req, res });
await validateAuthor({ req, openai }); await validateAuthor({ req, openai });
const buffer = await fs.readFile(req.file.path);
const image = await uploadImageBuffer({ const image = await uploadImageBuffer({
req, req,
context: FileContext.avatar, context: FileContext.avatar,
metadata: { metadata: { buffer },
buffer: req.file.buffer,
},
}); });
let _metadata; let _metadata;
@ -269,7 +270,7 @@ const uploadAssistantAvatar = async (req, res) => {
_metadata = assistant.metadata; _metadata = assistant.metadata;
} }
} catch (error) { } catch (error) {
logger.error('[/avatar/:assistant_id] Error fetching assistant', error); logger.error('[/:assistant_id/avatar] Error fetching assistant', error);
_metadata = {}; _metadata = {};
} }
@ -279,7 +280,7 @@ const uploadAssistantAvatar = async (req, res) => {
await deleteFile(req, { filepath: _metadata.avatar }); await deleteFile(req, { filepath: _metadata.avatar });
await deleteFileByFilter({ user: req.user.id, filepath: _metadata.avatar }); await deleteFileByFilter({ user: req.user.id, filepath: _metadata.avatar });
} catch (error) { } catch (error) {
logger.error('[/avatar/:assistant_id] Error deleting old avatar', error); logger.error('[/:assistant_id/avatar] Error deleting old avatar', error);
} }
} }
@ -310,6 +311,13 @@ const uploadAssistantAvatar = async (req, res) => {
const message = 'An error occurred while updating the Assistant Avatar'; const message = 'An error occurred while updating the Assistant Avatar';
logger.error(message, error); logger.error(message, error);
res.status(500).json({ message }); res.status(500).json({ message });
} finally {
try {
await fs.unlink(req.file.path);
logger.debug('[/:agent_id/avatar] Temp. image upload file deleted');
} catch (error) {
logger.debug('[/:agent_id/avatar] Temp. image upload file already deleted');
}
} }
}; };

View file

@ -27,7 +27,12 @@ const buildFunction = {
async function buildEndpointOption(req, res, next) { async function buildEndpointOption(req, res, next) {
const { endpoint, endpointType } = req.body; const { endpoint, endpointType } = req.body;
let parsedBody = parseCompactConvo({ endpoint, endpointType, conversation: req.body }); let parsedBody;
try {
parsedBody = parseCompactConvo({ endpoint, endpointType, conversation: req.body });
} catch (error) {
return handleError(res, { text: 'Error parsing conversation' });
}
if (req.app.locals.modelSpecs?.list && req.app.locals.modelSpecs?.enforce) { if (req.app.locals.modelSpecs?.list && req.app.locals.modelSpecs?.enforce) {
/** @type {{ list: TModelSpec[] }}*/ /** @type {{ list: TModelSpec[] }}*/
@ -56,11 +61,15 @@ async function buildEndpointOption(req, res, next) {
}); });
} }
try {
parsedBody = parseCompactConvo({ parsedBody = parseCompactConvo({
endpoint, endpoint,
endpointType, endpointType,
conversation: currentModelSpec.preset, conversation: currentModelSpec.preset,
}); });
} catch (error) {
return handleError(res, { text: 'Error parsing model spec' });
}
} }
const endpointFn = buildFunction[endpointType ?? endpoint]; const endpointFn = buildFunction[endpointType ?? endpoint];

View file

@ -6,6 +6,7 @@ const keyvMongo = require('~/cache/keyvMongo');
const denyRequest = require('./denyRequest'); const denyRequest = require('./denyRequest');
const { getLogStores } = require('~/cache'); const { getLogStores } = require('~/cache');
const { findUser } = require('~/models'); const { findUser } = require('~/models');
const { logger } = require('~/config');
const banCache = new Keyv({ store: keyvMongo, namespace: ViolationTypes.BAN, ttl: 0 }); const banCache = new Keyv({ store: keyvMongo, namespace: ViolationTypes.BAN, ttl: 0 });
const message = 'Your account has been temporarily banned due to violations of our service.'; const message = 'Your account has been temporarily banned due to violations of our service.';
@ -45,6 +46,7 @@ const banResponse = async (req, res) => {
* @returns {Promise<function|Object>} - Returns a Promise which when resolved calls next middleware if user or source IP is not banned. Otherwise calls `banResponse()` and sets ban details in `banCache`. * @returns {Promise<function|Object>} - Returns a Promise which when resolved calls next middleware if user or source IP is not banned. Otherwise calls `banResponse()` and sets ban details in `banCache`.
*/ */
const checkBan = async (req, res, next = () => {}) => { const checkBan = async (req, res, next = () => {}) => {
try {
const { BAN_VIOLATIONS } = process.env ?? {}; const { BAN_VIOLATIONS } = process.env ?? {};
if (!isEnabled(BAN_VIOLATIONS)) { if (!isEnabled(BAN_VIOLATIONS)) {
@ -131,6 +133,9 @@ const checkBan = async (req, res, next = () => {}) => {
req.banned = true; req.banned = true;
return await banResponse(req, res); return await banResponse(req, res);
} catch (error) {
logger.error('Error in checkBan middleware:', error);
}
}; };
module.exports = checkBan; module.exports = checkBan;

View file

@ -9,7 +9,7 @@ const {
// messageUserLimiter, // messageUserLimiter,
} = require('~/server/middleware'); } = require('~/server/middleware');
const v1 = require('./v1'); const { v1 } = require('./v1');
const chat = require('./chat'); const chat = require('./chat');
router.use(requireJwtAuth); router.use(requireJwtAuth);

View file

@ -1,4 +1,3 @@
const multer = require('multer');
const express = require('express'); const express = require('express');
const { PermissionTypes, Permissions } = require('librechat-data-provider'); const { PermissionTypes, Permissions } = require('librechat-data-provider');
const { requireJwtAuth, generateCheckAccess } = require('~/server/middleware'); const { requireJwtAuth, generateCheckAccess } = require('~/server/middleware');
@ -6,8 +5,8 @@ const v1 = require('~/server/controllers/agents/v1');
const actions = require('./actions'); const actions = require('./actions');
const tools = require('./tools'); const tools = require('./tools');
const upload = multer();
const router = express.Router(); const router = express.Router();
const avatar = express.Router();
const checkAgentAccess = generateCheckAccess(PermissionTypes.AGENTS, [Permissions.USE]); const checkAgentAccess = generateCheckAccess(PermissionTypes.AGENTS, [Permissions.USE]);
const checkAgentCreate = generateCheckAccess(PermissionTypes.AGENTS, [ const checkAgentCreate = generateCheckAccess(PermissionTypes.AGENTS, [
@ -81,12 +80,12 @@ router.get('/', checkAgentAccess, v1.getListAgents);
/** /**
* Uploads and updates an avatar for a specific agent. * Uploads and updates an avatar for a specific agent.
* @route POST /avatar/:agent_id * @route POST /agents/:agent_id/avatar
* @param {string} req.params.agent_id - The ID of the agent. * @param {string} req.params.agent_id - The ID of the agent.
* @param {Express.Multer.File} req.file - The avatar image file. * @param {Express.Multer.File} req.file - The avatar image file.
* @param {string} [req.body.metadata] - Optional metadata for the agent's avatar. * @param {string} [req.body.metadata] - Optional metadata for the agent's avatar.
* @returns {Object} 200 - success response - application/json * @returns {Object} 200 - success response - application/json
*/ */
router.post('/avatar/:agent_id', checkAgentAccess, upload.single('file'), v1.uploadAgentAvatar); avatar.post('/:agent_id/avatar/', checkAgentAccess, v1.uploadAgentAvatar);
module.exports = router; module.exports = { v1: router, avatar };

View file

@ -2,7 +2,7 @@ const express = require('express');
const router = express.Router(); const router = express.Router();
const { uaParser, checkBan, requireJwtAuth } = require('~/server/middleware'); const { uaParser, checkBan, requireJwtAuth } = require('~/server/middleware');
const v1 = require('./v1'); const { v1 } = require('./v1');
const chatV1 = require('./chatV1'); const chatV1 = require('./chatV1');
const v2 = require('./v2'); const v2 = require('./v2');
const chatV2 = require('./chatV2'); const chatV2 = require('./chatV2');

View file

@ -1,12 +1,11 @@
const multer = require('multer');
const express = require('express'); const express = require('express');
const controllers = require('~/server/controllers/assistants/v1'); const controllers = require('~/server/controllers/assistants/v1');
const documents = require('./documents'); const documents = require('./documents');
const actions = require('./actions'); const actions = require('./actions');
const tools = require('./tools'); const tools = require('./tools');
const upload = multer();
const router = express.Router(); const router = express.Router();
const avatar = express.Router();
/** /**
* Assistant actions route. * Assistant actions route.
@ -71,12 +70,12 @@ router.get('/', controllers.listAssistants);
/** /**
* Uploads and updates an avatar for a specific assistant. * Uploads and updates an avatar for a specific assistant.
* @route POST /avatar/:assistant_id * @route POST /assistants/:assistant_id/avatar/
* @param {string} req.params.assistant_id - The ID of the assistant. * @param {string} req.params.assistant_id - The ID of the assistant.
* @param {Express.Multer.File} req.file - The avatar image file. * @param {Express.Multer.File} req.file - The avatar image file.
* @param {string} [req.body.metadata] - Optional metadata for the assistant's avatar. * @param {string} [req.body.metadata] - Optional metadata for the assistant's avatar.
* @returns {Object} 200 - success response - application/json * @returns {Object} 200 - success response - application/json
*/ */
router.post('/avatar/:assistant_id', upload.single('file'), controllers.uploadAssistantAvatar); avatar.post('/:assistant_id/avatar/', controllers.uploadAssistantAvatar);
module.exports = router; module.exports = { v1: router, avatar };

View file

@ -1,4 +1,3 @@
const multer = require('multer');
const express = require('express'); const express = require('express');
const v1 = require('~/server/controllers/assistants/v1'); const v1 = require('~/server/controllers/assistants/v1');
const v2 = require('~/server/controllers/assistants/v2'); const v2 = require('~/server/controllers/assistants/v2');
@ -6,7 +5,6 @@ const documents = require('./documents');
const actions = require('./actions'); const actions = require('./actions');
const tools = require('./tools'); const tools = require('./tools');
const upload = multer();
const router = express.Router(); const router = express.Router();
/** /**
@ -78,6 +76,6 @@ router.get('/', v1.listAssistants);
* @param {string} [req.body.metadata] - Optional metadata for the assistant's avatar. * @param {string} [req.body.metadata] - Optional metadata for the assistant's avatar.
* @returns {Object} 200 - success response - application/json * @returns {Object} 200 - success response - application/json
*/ */
router.post('/avatar/:assistant_id', upload.single('file'), v1.uploadAssistantAvatar); router.post('/avatar/:assistant_id', v1.uploadAssistantAvatar);
module.exports = router; module.exports = router;

View file

@ -1,17 +1,18 @@
const multer = require('multer'); const fs = require('fs').promises;
const express = require('express'); const express = require('express');
const { getStrategyFunctions } = require('~/server/services/Files/strategies'); const { getStrategyFunctions } = require('~/server/services/Files/strategies');
const { resizeAvatar } = require('~/server/services/Files/images/avatar'); const { resizeAvatar } = require('~/server/services/Files/images/avatar');
const { filterFile } = require('~/server/services/Files/process');
const { logger } = require('~/config'); const { logger } = require('~/config');
const upload = multer();
const router = express.Router(); const router = express.Router();
router.post('/', upload.single('input'), async (req, res) => { router.post('/', async (req, res) => {
try { try {
filterFile({ req, file: req.file, image: true, isAvatar: true });
const userId = req.user.id; const userId = req.user.id;
const { manual } = req.body; const { manual } = req.body;
const input = req.file.buffer; const input = await fs.readFile(req.file.path);
if (!userId) { if (!userId) {
throw new Error('User ID is undefined'); throw new Error('User ID is undefined');
@ -33,6 +34,13 @@ router.post('/', upload.single('input'), async (req, res) => {
const message = 'An error occurred while uploading the profile picture'; const message = 'An error occurred while uploading the profile picture';
logger.error(message, error); logger.error(message, error);
res.status(500).json({ message }); res.status(500).json({ message });
} finally {
try {
await fs.unlink(req.file.path);
logger.debug('[/files/images/avatar] Temp. image upload file deleted');
} catch (error) {
logger.debug('[/files/images/avatar] Temp. image upload file already deleted');
}
} }
}); });

View file

@ -231,7 +231,6 @@ router.post('/', async (req, res) => {
} catch (error) { } catch (error) {
let message = 'Error processing file'; let message = 'Error processing file';
logger.error('[/files] Error processing file:', error); logger.error('[/files] Error processing file:', error);
cleanup = false;
if (error.message?.includes('file_ids')) { if (error.message?.includes('file_ids')) {
message += ': ' + error.message; message += ': ' + error.message;
@ -240,6 +239,7 @@ router.post('/', async (req, res) => {
// TODO: delete remote file if it exists // TODO: delete remote file if it exists
try { try {
await fs.unlink(file.path); await fs.unlink(file.path);
cleanup = false;
} catch (error) { } catch (error) {
logger.error('[/files] Error deleting file:', error); logger.error('[/files] Error deleting file:', error);
} }

View file

@ -30,6 +30,13 @@ router.post('/', async (req, res) => {
logger.error('[/files/images] Error deleting file:', error); logger.error('[/files/images] Error deleting file:', error);
} }
res.status(500).json({ message: 'Error processing file' }); res.status(500).json({ message: 'Error processing file' });
} finally {
try {
await fs.unlink(req.file.path);
logger.debug('[/files/images] Temp. image upload file deleted');
} catch (error) {
logger.debug('[/files/images] Temp. image upload file already deleted');
}
} }
}); });

View file

@ -1,5 +1,7 @@
const express = require('express'); const express = require('express');
const { uaParser, checkBan, requireJwtAuth, createFileLimiters } = require('~/server/middleware'); const { uaParser, checkBan, requireJwtAuth, createFileLimiters } = require('~/server/middleware');
const { avatar: asstAvatarRouter } = require('~/server/routes/assistants/v1');
const { avatar: agentAvatarRouter } = require('~/server/routes/agents/v1');
const { createMulterInstance } = require('./multer'); const { createMulterInstance } = require('./multer');
const files = require('./files'); const files = require('./files');
@ -13,18 +15,25 @@ const initialize = async () => {
router.use(checkBan); router.use(checkBan);
router.use(uaParser); router.use(uaParser);
const upload = await createMulterInstance();
router.post('/speech/stt', upload.single('audio'));
/* Important: speech route must be added before the upload limiters */ /* Important: speech route must be added before the upload limiters */
router.use('/speech', speech); router.use('/speech', speech);
const upload = await createMulterInstance();
const { fileUploadIpLimiter, fileUploadUserLimiter } = createFileLimiters(); const { fileUploadIpLimiter, fileUploadUserLimiter } = createFileLimiters();
router.post('*', fileUploadIpLimiter, fileUploadUserLimiter); router.post('*', fileUploadIpLimiter, fileUploadUserLimiter);
router.post('/', upload.single('file')); router.post('/', upload.single('file'));
router.post('/images', upload.single('file')); router.post('/images', upload.single('file'));
router.post('/images/avatar', upload.single('file'));
router.post('/images/agents/:agent_id/avatar', upload.single('file'));
router.post('/images/assistants/:assistant_id/avatar', upload.single('file'));
router.use('/', files); router.use('/', files);
router.use('/images', images); router.use('/images', images);
router.use('/images/avatar', avatar); router.use('/images/avatar', avatar);
router.use('/images/agents', agentAvatarRouter);
router.use('/images/assistants', asstAvatarRouter);
return router; return router;
}; };

View file

@ -3,6 +3,7 @@ const path = require('path');
const crypto = require('crypto'); const crypto = require('crypto');
const multer = require('multer'); const multer = require('multer');
const { fileConfig: defaultFileConfig, mergeFileConfig } = require('librechat-data-provider'); const { fileConfig: defaultFileConfig, mergeFileConfig } = require('librechat-data-provider');
const { sanitizeFilename } = require('~/server/utils/handleText');
const { getCustomConfig } = require('~/server/services/Config'); const { getCustomConfig } = require('~/server/services/Config');
const storage = multer.diskStorage({ const storage = multer.diskStorage({
@ -16,7 +17,8 @@ const storage = multer.diskStorage({
filename: function (req, file, cb) { filename: function (req, file, cb) {
req.file_id = crypto.randomUUID(); req.file_id = crypto.randomUUID();
file.originalname = decodeURIComponent(file.originalname); file.originalname = decodeURIComponent(file.originalname);
cb(null, `${file.originalname}`); const sanitizedFilename = sanitizeFilename(file.originalname);
cb(null, sanitizedFilename);
}, },
}); });
@ -45,6 +47,10 @@ const createFileFilter = (customFileConfig) => {
return cb(new Error('No file provided'), false); return cb(new Error('No file provided'), false);
} }
if (req.originalUrl.endsWith('/speech/stt') && file.mimetype.startsWith('audio/')) {
return cb(null, true);
}
const endpoint = req.body.endpoint; const endpoint = req.body.endpoint;
const supportedTypes = const supportedTypes =
customFileConfig?.endpoints?.[endpoint]?.supportedMimeTypes ?? customFileConfig?.endpoints?.[endpoint]?.supportedMimeTypes ??

View file

@ -1,13 +1,8 @@
const express = require('express'); const express = require('express');
const router = express.Router();
const multer = require('multer');
const { requireJwtAuth } = require('~/server/middleware/');
const { speechToText } = require('~/server/services/Files/Audio'); const { speechToText } = require('~/server/services/Files/Audio');
const upload = multer(); const router = express.Router();
router.post('/', requireJwtAuth, upload.single('audio'), async (req, res) => { router.post('/', speechToText);
await speechToText(req, res);
});
module.exports = router; module.exports = router;

View file

@ -214,7 +214,7 @@ const deletePromptController = async (req, res) => {
const { promptId } = req.params; const { promptId } = req.params;
const { groupId } = req.query; const { groupId } = req.query;
const author = req.user.id; const author = req.user.id;
const query = { promptId, groupId, author, role: req.user.role }; const query = { promptId, groupId, author };
if (req.user.role === SystemRoles.ADMIN) { if (req.user.role === SystemRoles.ADMIN) {
delete query.author; delete query.author;
} }
@ -226,11 +226,24 @@ const deletePromptController = async (req, res) => {
} }
}; };
router.delete('/:promptId', checkPromptCreate, deletePromptController); /**
* Delete a prompt group
* @param {ServerRequest} req
* @param {ServerResponse} res
* @returns {Promise<TDeletePromptGroupResponse>}
*/
const deletePromptGroupController = async (req, res) => {
try {
const { groupId: _id } = req.params;
const message = await deletePromptGroup({ _id, author: req.user.id, role: req.user.role });
res.send(message);
} catch (error) {
logger.error('Error deleting prompt group', error);
res.status(500).send({ message: 'Error deleting prompt group' });
}
};
router.delete('/groups/:groupId', checkPromptCreate, async (req, res) => { router.delete('/:promptId', checkPromptCreate, deletePromptController);
const { groupId } = req.params; router.delete('/groups/:groupId', checkPromptCreate, deletePromptGroupController);
res.status(200).send(await deletePromptGroup(groupId));
});
module.exports = router; module.exports = router;

View file

@ -1,4 +1,5 @@
const axios = require('axios'); const axios = require('axios');
const fs = require('fs').promises;
const FormData = require('form-data'); const FormData = require('form-data');
const { Readable } = require('stream'); const { Readable } = require('stream');
const { extractEnvVariable, STTProviders } = require('librechat-data-provider'); const { extractEnvVariable, STTProviders } = require('librechat-data-provider');
@ -200,11 +201,11 @@ class STTService {
* @returns {Promise<void>} * @returns {Promise<void>}
*/ */
async processTextToSpeech(req, res) { async processTextToSpeech(req, res) {
if (!req.file || !req.file.buffer) { if (!req.file) {
return res.status(400).json({ message: 'No audio file provided in the FormData' }); return res.status(400).json({ message: 'No audio file provided in the FormData' });
} }
const audioBuffer = req.file.buffer; const audioBuffer = await fs.readFile(req.file.path);
const audioFile = { const audioFile = {
originalname: req.file.originalname, originalname: req.file.originalname,
mimetype: req.file.mimetype, mimetype: req.file.mimetype,
@ -218,6 +219,13 @@ class STTService {
} catch (error) { } catch (error) {
logger.error('An error occurred while processing the audio:', error); logger.error('An error occurred while processing the audio:', error);
res.sendStatus(500); res.sendStatus(500);
} finally {
try {
await fs.unlink(req.file.path);
logger.debug('[/speech/stt] Temp. audio upload file deleted');
} catch (error) {
logger.debug('[/speech/stt] Temp. audio upload file already deleted');
}
} }
} }
} }

View file

@ -716,14 +716,15 @@ async function retrieveAndProcessFile({
* @param {number} [params.req.version] * @param {number} [params.req.version]
* @param {Express.Multer.File} params.file - The file uploaded to the server via multer. * @param {Express.Multer.File} params.file - The file uploaded to the server via multer.
* @param {boolean} [params.image] - Whether the file expected is an image. * @param {boolean} [params.image] - Whether the file expected is an image.
* @param {boolean} [params.isAvatar] - Whether the file expected is a user or entity avatar.
* @returns {void} * @returns {void}
* *
* @throws {Error} If a file exception is caught (invalid file size or type, lack of metadata). * @throws {Error} If a file exception is caught (invalid file size or type, lack of metadata).
*/ */
function filterFile({ req, file, image }) { function filterFile({ req, file, image, isAvatar }) {
const { endpoint, file_id, width, height } = req.body; const { endpoint, file_id, width, height } = req.body;
if (!file_id) { if (!file_id && !isAvatar) {
throw new Error('No file_id provided'); throw new Error('No file_id provided');
} }
@ -732,20 +733,25 @@ function filterFile({ req, file, image }) {
} }
/* parse to validate api call, throws error on fail */ /* parse to validate api call, throws error on fail */
if (!isAvatar) {
isUUID.parse(file_id); isUUID.parse(file_id);
}
if (!endpoint) { if (!endpoint && !isAvatar) {
throw new Error('No endpoint provided'); throw new Error('No endpoint provided');
} }
const fileConfig = mergeFileConfig(req.app.locals.fileConfig); const fileConfig = mergeFileConfig(req.app.locals.fileConfig);
const { fileSizeLimit, supportedMimeTypes } = const { fileSizeLimit: sizeLimit, supportedMimeTypes } =
fileConfig.endpoints[endpoint] ?? fileConfig.endpoints.default; fileConfig.endpoints[endpoint] ?? fileConfig.endpoints.default;
const fileSizeLimit = isAvatar === true ? fileConfig.avatarSizeLimit : sizeLimit;
if (file.size > fileSizeLimit) { if (file.size > fileSizeLimit) {
throw new Error( throw new Error(
`File size limit of ${fileSizeLimit / megabyte} MB exceeded for ${endpoint} endpoint`, `File size limit of ${fileSizeLimit / megabyte} MB exceeded for ${
isAvatar ? 'avatar upload' : `${endpoint} endpoint`
}`,
); );
} }
@ -755,7 +761,7 @@ function filterFile({ req, file, image }) {
throw new Error('Unsupported file type'); throw new Error('Unsupported file type');
} }
if (!image) { if (!image || isAvatar === true) {
return; return;
} }

View file

@ -1,3 +1,5 @@
const path = require('path');
const crypto = require('crypto');
const { const {
Capabilities, Capabilities,
EModelEndpoint, EModelEndpoint,
@ -222,6 +224,38 @@ function normalizeEndpointName(name = '') {
return name.toLowerCase() === Providers.OLLAMA ? Providers.OLLAMA : name; return name.toLowerCase() === Providers.OLLAMA ? Providers.OLLAMA : name;
} }
/**
* Sanitize a filename by removing any directory components, replacing non-alphanumeric characters
* @param {string} inputName
* @returns {string}
*/
function sanitizeFilename(inputName) {
// Remove any directory components
let name = path.basename(inputName);
// Replace any non-alphanumeric characters except for '.' and '-'
name = name.replace(/[^a-zA-Z0-9.-]/g, '_');
// Ensure the name doesn't start with a dot (hidden file in Unix-like systems)
if (name.startsWith('.') || name === '') {
name = '_' + name;
}
// Limit the length of the filename
const MAX_LENGTH = 255;
if (name.length > MAX_LENGTH) {
const ext = path.extname(name);
const nameWithoutExt = path.basename(name, ext);
name =
nameWithoutExt.slice(0, MAX_LENGTH - ext.length - 7) +
'-' +
crypto.randomBytes(3).toString('hex') +
ext;
}
return name;
}
module.exports = { module.exports = {
isEnabled, isEnabled,
handleText, handleText,
@ -231,5 +265,6 @@ module.exports = {
generateConfig, generateConfig,
addSpaceIfNeeded, addSpaceIfNeeded,
createOnProgress, createOnProgress,
sanitizeFilename,
normalizeEndpointName, normalizeEndpointName,
}; };

View file

@ -1,4 +1,4 @@
const { isEnabled } = require('./handleText'); const { isEnabled, sanitizeFilename } = require('./handleText');
describe('isEnabled', () => { describe('isEnabled', () => {
test('should return true when input is "true"', () => { test('should return true when input is "true"', () => {
@ -49,3 +49,51 @@ describe('isEnabled', () => {
expect(isEnabled([])).toBe(false); expect(isEnabled([])).toBe(false);
}); });
}); });
jest.mock('crypto', () => ({
randomBytes: jest.fn().mockReturnValue(Buffer.from('abc123', 'hex')),
}));
describe('sanitizeFilename', () => {
test('removes directory components (1/2)', () => {
expect(sanitizeFilename('/path/to/file.txt')).toBe('file.txt');
});
test('removes directory components (2/2)', () => {
expect(sanitizeFilename('../../../../file.txt')).toBe('file.txt');
});
test('replaces non-alphanumeric characters', () => {
expect(sanitizeFilename('file name@#$.txt')).toBe('file_name___.txt');
});
test('preserves dots and hyphens', () => {
expect(sanitizeFilename('file-name.with.dots.txt')).toBe('file-name.with.dots.txt');
});
test('prepends underscore to filenames starting with a dot', () => {
expect(sanitizeFilename('.hiddenfile')).toBe('_.hiddenfile');
});
test('truncates long filenames', () => {
const longName = 'a'.repeat(300) + '.txt';
const result = sanitizeFilename(longName);
expect(result.length).toBe(255);
expect(result).toMatch(/^a+-abc123\.txt$/);
});
test('handles filenames with no extension', () => {
const longName = 'a'.repeat(300);
const result = sanitizeFilename(longName);
expect(result.length).toBe(255);
expect(result).toMatch(/^a+-abc123$/);
});
test('handles empty input', () => {
expect(sanitizeFilename('')).toBe('_');
});
test('handles input with only special characters', () => {
expect(sanitizeFilename('@#$%^&*')).toBe('_______');
});
});

View file

@ -3,7 +3,7 @@ import Files from './Files';
const Container = ({ children, message }: { children: React.ReactNode; message?: TMessage }) => ( const Container = ({ children, message }: { children: React.ReactNode; message?: TMessage }) => (
<div <div
className="text-message flex min-h-[20px] flex-col items-start gap-3 overflow-x-auto [.text-message+&]:mt-5" className="text-message flex min-h-[20px] flex-col items-start gap-3 overflow-visible [.text-message+&]:mt-5"
dir="auto" dir="auto"
> >
{message?.isCreatedByUser === true && <Files message={message} />} {message?.isCreatedByUser === true && <Files message={message} />}

View file

@ -27,7 +27,7 @@ export const ErrorMessage = ({
return ( return (
<Suspense <Suspense
fallback={ fallback={
<div className="text-message mb-[0.625rem] flex min-h-[20px] flex-col items-start gap-3 overflow-x-auto"> <div className="text-message mb-[0.625rem] flex min-h-[20px] flex-col items-start gap-3 overflow-visible">
<div className="markdown prose dark:prose-invert light w-full break-words dark:text-gray-100"> <div className="markdown prose dark:prose-invert light w-full break-words dark:text-gray-100">
<div className="absolute"> <div className="absolute">
<p className="submitting relative"> <p className="submitting relative">

View file

@ -1,7 +1,7 @@
import React, { useState, useRef, useCallback } from 'react'; import React, { useState, useRef, useCallback } from 'react';
import { FileImage, RotateCw, Upload } from 'lucide-react';
import { useSetRecoilState } from 'recoil'; import { useSetRecoilState } from 'recoil';
import AvatarEditor from 'react-avatar-editor'; import AvatarEditor from 'react-avatar-editor';
import { FileImage, RotateCw, Upload } from 'lucide-react';
import { fileConfig as defaultFileConfig, mergeFileConfig } from 'librechat-data-provider'; import { fileConfig as defaultFileConfig, mergeFileConfig } from 'librechat-data-provider';
import type { TUser } from 'librechat-data-provider'; import type { TUser } from 'librechat-data-provider';
import { import {
@ -20,16 +20,23 @@ import { cn, formatBytes } from '~/utils';
import { useLocalize } from '~/hooks'; import { useLocalize } from '~/hooks';
import store from '~/store'; import store from '~/store';
interface AvatarEditorRef {
getImageScaledToCanvas: () => HTMLCanvasElement;
getImage: () => HTMLImageElement;
}
function Avatar() { function Avatar() {
const setUser = useSetRecoilState(store.user); const setUser = useSetRecoilState(store.user);
const [image, setImage] = useState<string | File | null>(null);
const [isDialogOpen, setDialogOpen] = useState<boolean>(false);
const [scale, setScale] = useState<number>(1); const [scale, setScale] = useState<number>(1);
const [rotation, setRotation] = useState<number>(0); const [rotation, setRotation] = useState<number>(0);
const editorRef = useRef<AvatarEditor | null>(null); const editorRef = useRef<AvatarEditorRef | null>(null);
const fileInputRef = useRef<HTMLInputElement>(null); const fileInputRef = useRef<HTMLInputElement>(null);
const openButtonRef = useRef<HTMLButtonElement>(null); const openButtonRef = useRef<HTMLButtonElement>(null);
const [image, setImage] = useState<string | File | null>(null);
const [isDialogOpen, setDialogOpen] = useState<boolean>(false);
const { data: fileConfig = defaultFileConfig } = useGetFileConfig({ const { data: fileConfig = defaultFileConfig } = useGetFileConfig({
select: (data) => mergeFileConfig(data), select: (data) => mergeFileConfig(data),
}); });
@ -55,12 +62,13 @@ function Avatar() {
}; };
const handleFile = (file: File | undefined) => { const handleFile = (file: File | undefined) => {
if (fileConfig.avatarSizeLimit && file && file.size <= fileConfig.avatarSizeLimit) { if (fileConfig.avatarSizeLimit != null && file && file.size <= fileConfig.avatarSizeLimit) {
setImage(file); setImage(file);
setScale(1); setScale(1);
setRotation(0); setRotation(0);
} else { } else {
const megabytes = fileConfig.avatarSizeLimit ? formatBytes(fileConfig.avatarSizeLimit) : 2; const megabytes =
fileConfig.avatarSizeLimit != null ? formatBytes(fileConfig.avatarSizeLimit) : 2;
showToast({ showToast({
message: localize('com_ui_upload_invalid_var', megabytes + ''), message: localize('com_ui_upload_invalid_var', megabytes + ''),
status: 'error', status: 'error',
@ -82,7 +90,7 @@ function Avatar() {
canvas.toBlob((blob) => { canvas.toBlob((blob) => {
if (blob) { if (blob) {
const formData = new FormData(); const formData = new FormData();
formData.append('input', blob, 'avatar.png'); formData.append('file', blob, 'avatar.png');
formData.append('manual', 'true'); formData.append('manual', 'true');
uploadAvatar(formData); uploadAvatar(formData);
} }
@ -134,11 +142,11 @@ function Avatar() {
<OGDialogContent className="w-11/12 max-w-sm" style={{ borderRadius: '12px' }}> <OGDialogContent className="w-11/12 max-w-sm" style={{ borderRadius: '12px' }}>
<OGDialogHeader> <OGDialogHeader>
<OGDialogTitle className="text-lg font-medium leading-6 text-text-primary"> <OGDialogTitle className="text-lg font-medium leading-6 text-text-primary">
{image ? localize('com_ui_preview') : localize('com_ui_upload_image')} {image != null ? localize('com_ui_preview') : localize('com_ui_upload_image')}
</OGDialogTitle> </OGDialogTitle>
</OGDialogHeader> </OGDialogHeader>
<div className="flex flex-col items-center justify-center"> <div className="flex flex-col items-center justify-center">
{image ? ( {image != null ? (
<> <>
<div className="relative overflow-hidden rounded-full"> <div className="relative overflow-hidden rounded-full">
<AvatarEditor <AvatarEditor
@ -155,7 +163,7 @@ function Avatar() {
</div> </div>
<div className="mt-4 flex w-full flex-col items-center space-y-4"> <div className="mt-4 flex w-full flex-col items-center space-y-4">
<div className="flex w-full items-center justify-center space-x-4"> <div className="flex w-full items-center justify-center space-x-4">
<span className="text-sm">Zoom:</span> <span className="text-sm">{localize('com_ui_zoom')}</span>
<Slider <Slider
value={[scale]} value={[scale]}
min={1} min={1}

View file

@ -38,7 +38,7 @@ export default function DashGroupItem({
const [nameInputField, setNameInputField] = useState(group.name); const [nameInputField, setNameInputField] = useState(group.name);
const isOwner = useMemo(() => user?.id === group.author, [user, group]); const isOwner = useMemo(() => user?.id === group.author, [user, group]);
const groupIsGlobal = useMemo( const groupIsGlobal = useMemo(
() => instanceProjectId && group.projectIds?.includes(instanceProjectId), () => instanceProjectId != null && group.projectIds?.includes(instanceProjectId),
[group, instanceProjectId], [group, instanceProjectId],
); );

View file

@ -222,6 +222,7 @@ export default {
com_ui_latest_footer: 'Every AI for Everyone.', com_ui_latest_footer: 'Every AI for Everyone.',
com_ui_enter: 'Enter', com_ui_enter: 'Enter',
com_ui_submit: 'Submit', com_ui_submit: 'Submit',
com_ui_zoom: 'Zoom',
com_ui_none_selected: 'None selected', com_ui_none_selected: 'None selected',
com_ui_upload_success: 'Successfully uploaded file', com_ui_upload_success: 'Successfully uploaded file',
com_ui_upload_error: 'There was an error uploading your file', com_ui_upload_error: 'There was an error uploading your file',

View file

@ -2399,3 +2399,10 @@ button.scroll-convo {
scale: 1; scale: 1;
translate: 0; translate: 0;
} }
/** Note: ensure KaTeX can spread across visible space */
.message-content pre:has(> span.katex) {
overflow: visible !important;
height: auto !important;
max-height: none !important;
}

2
package-lock.json generated
View file

@ -36283,7 +36283,7 @@
}, },
"packages/data-provider": { "packages/data-provider": {
"name": "librechat-data-provider", "name": "librechat-data-provider",
"version": "0.7.54", "version": "0.7.55",
"license": "ISC", "license": "ISC",
"dependencies": { "dependencies": {
"@types/js-yaml": "^4.0.9", "@types/js-yaml": "^4.0.9",

View file

@ -1,6 +1,6 @@
{ {
"name": "librechat-data-provider", "name": "librechat-data-provider",
"version": "0.7.54", "version": "0.7.55",
"description": "data services for librechat apps", "description": "data services for librechat apps",
"main": "dist/index.js", "main": "dist/index.js",
"module": "dist/index.es.js", "module": "dist/index.es.js",

View file

@ -34,9 +34,9 @@ export const abortRequest = (endpoint: string) => `/api/ask/${endpoint}/abort`;
export const conversationsRoot = '/api/convos'; export const conversationsRoot = '/api/convos';
export const conversations = (pageNumber: string, isArchived?: boolean, tags?: string[]) => export const conversations = (pageNumber: string, isArchived?: boolean, tags?: string[]) =>
`${conversationsRoot}?pageNumber=${pageNumber}${isArchived ? '&isArchived=true' : ''}${tags `${conversationsRoot}?pageNumber=${pageNumber}${
?.map((tag) => `&tags=${tag}`) isArchived === true ? '&isArchived=true' : ''
.join('')}`; }${tags?.map((tag) => `&tags=${tag}`).join('')}`;
export const conversationById = (id: string) => `${conversationsRoot}/${id}`; export const conversationById = (id: string) => `${conversationsRoot}/${id}`;
@ -77,7 +77,8 @@ export const loginFacebook = () => '/api/auth/facebook';
export const loginGoogle = () => '/api/auth/google'; export const loginGoogle = () => '/api/auth/google';
export const refreshToken = (retry?: boolean) => `/api/auth/refresh${retry ? '?retry=true' : ''}`; export const refreshToken = (retry?: boolean) =>
`/api/auth/refresh${retry === true ? '?retry=true' : ''}`;
export const requestPasswordReset = () => '/api/auth/requestPasswordReset'; export const requestPasswordReset = () => '/api/auth/requestPasswordReset';
@ -94,19 +95,21 @@ export const config = () => '/api/config';
export const prompts = () => '/api/prompts'; export const prompts = () => '/api/prompts';
export const assistants = ({ export const assistants = ({
path, path = '',
options, options,
version, version,
endpoint, endpoint,
isAvatar,
}: { }: {
path?: string; path?: string;
options?: object; options?: object;
endpoint?: AssistantsEndpoint; endpoint?: AssistantsEndpoint;
version: number | string; version: number | string;
isAvatar?: boolean;
}) => { }) => {
let url = `/api/assistants/v${version}`; let url = isAvatar === true ? `${images()}/assistants` : `/api/assistants/v${version}`;
if (path) { if (path && path !== '') {
url += `/${path}`; url += `/${path}`;
} }

View file

@ -471,7 +471,8 @@ export const uploadAvatar = (data: FormData): Promise<f.AvatarUploadResponse> =>
export const uploadAssistantAvatar = (data: m.AssistantAvatarVariables): Promise<a.Assistant> => { export const uploadAssistantAvatar = (data: m.AssistantAvatarVariables): Promise<a.Assistant> => {
return request.postMultiPart( return request.postMultiPart(
endpoints.assistants({ endpoints.assistants({
path: `avatar/${data.assistant_id}`, isAvatar: true,
path: `${data.assistant_id}/avatar`,
options: { model: data.model, endpoint: data.endpoint }, options: { model: data.model, endpoint: data.endpoint },
version: data.version, version: data.version,
}), }),
@ -481,9 +482,7 @@ export const uploadAssistantAvatar = (data: m.AssistantAvatarVariables): Promise
export const uploadAgentAvatar = (data: m.AgentAvatarVariables): Promise<a.Agent> => { export const uploadAgentAvatar = (data: m.AgentAvatarVariables): Promise<a.Agent> => {
return request.postMultiPart( return request.postMultiPart(
endpoints.agents({ `${endpoints.images()}/agents/${data.agent_id}/avatar`,
path: `avatar/${data.agent_id}`,
}),
data.formData, data.formData,
); );
}; };

View file

@ -491,9 +491,7 @@ export type TUpdatePromptLabelsResponse = {
message: string; message: string;
}; };
export type TDeletePromptGroupResponse = { export type TDeletePromptGroupResponse = TUpdatePromptLabelsResponse;
promptGroup: string;
};
export type TDeletePromptGroupRequest = { export type TDeletePromptGroupRequest = {
id: string; id: string;