mirror of
https://github.com/danny-avila/LibreChat.git
synced 2025-12-17 00:40:14 +01:00
* 🔒 fix: `iconURL` in conversation parsing - Updated the `buildEndpointOption` middleware to derive `iconURL` from model specs when not provided by the client, improving security by preventing malicious URLs. - Modified the `parseCompactConvo` function to strip `iconURL` from conversation inputs, ensuring it is only set server-side. - Added comprehensive tests to validate the stripping of `iconURL` across various endpoint types, enhancing overall input sanitization. * ✨ feat: Add ESLint rule for unused variables - Introduced a new ESLint rule to warn about unused variables, allowing for better code quality and maintainability. - Configured the rule to ignore variables and arguments that start with an underscore, accommodating common coding practices.
108 lines
3.9 KiB
JavaScript
108 lines
3.9 KiB
JavaScript
const { handleError } = require('@librechat/api');
|
|
const { logger } = require('@librechat/data-schemas');
|
|
const {
|
|
EndpointURLs,
|
|
EModelEndpoint,
|
|
isAgentsEndpoint,
|
|
parseCompactConvo,
|
|
} = require('librechat-data-provider');
|
|
const azureAssistants = require('~/server/services/Endpoints/azureAssistants');
|
|
const assistants = require('~/server/services/Endpoints/assistants');
|
|
const { processFiles } = require('~/server/services/Files/process');
|
|
const anthropic = require('~/server/services/Endpoints/anthropic');
|
|
const bedrock = require('~/server/services/Endpoints/bedrock');
|
|
const openAI = require('~/server/services/Endpoints/openAI');
|
|
const agents = require('~/server/services/Endpoints/agents');
|
|
const custom = require('~/server/services/Endpoints/custom');
|
|
const google = require('~/server/services/Endpoints/google');
|
|
|
|
const buildFunction = {
|
|
[EModelEndpoint.openAI]: openAI.buildOptions,
|
|
[EModelEndpoint.google]: google.buildOptions,
|
|
[EModelEndpoint.custom]: custom.buildOptions,
|
|
[EModelEndpoint.agents]: agents.buildOptions,
|
|
[EModelEndpoint.bedrock]: bedrock.buildOptions,
|
|
[EModelEndpoint.azureOpenAI]: openAI.buildOptions,
|
|
[EModelEndpoint.anthropic]: anthropic.buildOptions,
|
|
[EModelEndpoint.assistants]: assistants.buildOptions,
|
|
[EModelEndpoint.azureAssistants]: azureAssistants.buildOptions,
|
|
};
|
|
|
|
async function buildEndpointOption(req, res, next) {
|
|
const { endpoint, endpointType } = req.body;
|
|
let parsedBody;
|
|
try {
|
|
parsedBody = parseCompactConvo({ endpoint, endpointType, conversation: req.body });
|
|
} catch (error) {
|
|
logger.warn(
|
|
`Error parsing conversation for endpoint ${endpoint}${error?.message ? `: ${error.message}` : ''}`,
|
|
);
|
|
return handleError(res, { text: 'Error parsing conversation' });
|
|
}
|
|
|
|
const appConfig = req.config;
|
|
if (appConfig.modelSpecs?.list && appConfig.modelSpecs?.enforce) {
|
|
/** @type {{ list: TModelSpec[] }}*/
|
|
const { list } = appConfig.modelSpecs;
|
|
const { spec } = parsedBody;
|
|
|
|
if (!spec) {
|
|
return handleError(res, { text: 'No model spec selected' });
|
|
}
|
|
|
|
const currentModelSpec = list.find((s) => s.name === spec);
|
|
if (!currentModelSpec) {
|
|
return handleError(res, { text: 'Invalid model spec' });
|
|
}
|
|
|
|
if (endpoint !== currentModelSpec.preset.endpoint) {
|
|
return handleError(res, { text: 'Model spec mismatch' });
|
|
}
|
|
|
|
try {
|
|
currentModelSpec.preset.spec = spec;
|
|
parsedBody = parseCompactConvo({
|
|
endpoint,
|
|
endpointType,
|
|
conversation: currentModelSpec.preset,
|
|
});
|
|
if (currentModelSpec.iconURL != null && currentModelSpec.iconURL !== '') {
|
|
parsedBody.iconURL = currentModelSpec.iconURL;
|
|
}
|
|
} catch (error) {
|
|
logger.error(`Error parsing model spec for endpoint ${endpoint}`, error);
|
|
return handleError(res, { text: 'Error parsing model spec' });
|
|
}
|
|
} else if (parsedBody.spec && appConfig.modelSpecs?.list) {
|
|
// Non-enforced mode: if spec is selected, derive iconURL from model spec
|
|
const modelSpec = appConfig.modelSpecs.list.find((s) => s.name === parsedBody.spec);
|
|
if (modelSpec?.iconURL) {
|
|
parsedBody.iconURL = modelSpec.iconURL;
|
|
}
|
|
}
|
|
|
|
try {
|
|
const isAgents =
|
|
isAgentsEndpoint(endpoint) || req.baseUrl.startsWith(EndpointURLs[EModelEndpoint.agents]);
|
|
const builder = isAgents
|
|
? (...args) => buildFunction[EModelEndpoint.agents](req, ...args)
|
|
: buildFunction[endpointType ?? endpoint];
|
|
|
|
// TODO: use object params
|
|
req.body.endpointOption = await builder(endpoint, parsedBody, endpointType);
|
|
|
|
if (req.body.files && !isAgents) {
|
|
req.body.endpointOption.attachments = processFiles(req.body.files);
|
|
}
|
|
|
|
next();
|
|
} catch (error) {
|
|
logger.error(
|
|
`Error building endpoint option for endpoint ${endpoint} with type ${endpointType}`,
|
|
error,
|
|
);
|
|
return handleError(res, { text: 'Error building endpoint option' });
|
|
}
|
|
}
|
|
|
|
module.exports = buildEndpointOption;
|