mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 15:03:16 +00:00
fix: Make the allowed users list an env var (#789)
* fix: Make the allowed users list an env var * cr
This commit is contained in:
parent
f246c811ea
commit
53e5dd954d
5 changed files with 48 additions and 67 deletions
|
|
@ -80,6 +80,11 @@ Before starting, ensure you have the following installed:
|
|||
...add your private key here...
|
||||
-----END RSA PRIVATE KEY-----
|
||||
"
|
||||
|
||||
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
|
||||
# This is only used in production. In development every user is an "allowed user".
|
||||
# Must be a valid JSON array of strings.
|
||||
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
|
||||
```
|
||||
|
||||
### Agent Environment Variables (`apps/open-swe/.env`)
|
||||
|
|
@ -120,8 +125,15 @@ Before starting, ensure you have the following installed:
|
|||
|
||||
# CI/CD. See the /labs/swe/setup/ci for more information
|
||||
SKIP_CI_UNTIL_LAST_COMMIT="true"
|
||||
|
||||
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
|
||||
# This is only used in production. In development every user is an "allowed user".
|
||||
# Must be a valid JSON array of strings.
|
||||
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
|
||||
```
|
||||
|
||||
If you don't set the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable, every user will be required to set their own LLM API keys to use the agent. Additionally, none of the webhook features (triggering new runs by adding labels to GitHub issues, tagging the agent in PR reviews, etc.) will work unless you include the username's of the GitHub users you want to allow access to in the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable (in both web and agent deployments).
|
||||
|
||||
<Tip>
|
||||
Generate the `SECRETS_ENCRYPTION_KEY` using: `openssl rand -hex 32`. This key must be identical in both environment files.
|
||||
</Tip>
|
||||
|
|
|
|||
|
|
@ -152,16 +152,14 @@ This should match the username from Step 1 (without the @ symbol).
|
|||
|
||||
### Step 4: Update Allowed Users
|
||||
|
||||
Add the GitHub usernames who should be allowed to trigger runs to the `ALLOWED_USERS` list in `packages/shared/src/github/allowed-users.ts`:
|
||||
Add the GitHub usernames who should be allowed to trigger runs to the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable in your agent's deployment environment (include in the production deployments for both the web app and agent to take advantage of the allowed users functionality).
|
||||
|
||||
```typescript
|
||||
export const ALLOWED_USERS = [
|
||||
"your-github-username",
|
||||
"teammate-username",
|
||||
// ... other allowed users
|
||||
];
|
||||
```bash
|
||||
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
|
||||
```
|
||||
|
||||
When running locally, every user is an "allowed user". It's also recommended to set this environment variable in your web app's production environment variables so your users won't need to set their own API keys when invoking Open SWE via the web app.
|
||||
|
||||
<Tip>
|
||||
After making these configuration changes, restart your Open SWE instance to ensure the new settings take effect. You can then test the functionality by tagging your custom username in a PR comment.
|
||||
</Tip>
|
||||
|
|
|
|||
|
|
@ -58,3 +58,7 @@ SKIP_CI_UNTIL_LAST_COMMIT="true"
|
|||
# OPEN_SWE_LOCAL_MODE=false
|
||||
# OPEN_SWE_LOCAL_PROJECT_PATH=""
|
||||
|
||||
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
|
||||
# This is only used in production. In development every user is an "allowed user".
|
||||
# Must be a valid JSON array of strings.
|
||||
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
|
||||
|
|
|
|||
|
|
@ -27,3 +27,8 @@ LANGGRAPH_API_URL="http://localhost:2024"
|
|||
# Should be the same value as the one used in the web app, so that secrets
|
||||
# encrypted in the web app can be decrypted in the agent.
|
||||
SECRETS_ENCRYPTION_KEY=""
|
||||
|
||||
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
|
||||
# This is only used in production. In development every user is an "allowed user".
|
||||
# Must be a valid JSON array of strings.
|
||||
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
|
||||
|
|
@ -1,69 +1,31 @@
|
|||
export const ALLOWED_USERS = [
|
||||
"agola11",
|
||||
"akira",
|
||||
"aliyanishfaq",
|
||||
"andrewnguonly",
|
||||
"angus-langchain",
|
||||
"bracesproul",
|
||||
"ArthurLangChain",
|
||||
"baskaryan",
|
||||
"bvs-langchain",
|
||||
"catherine-langchain",
|
||||
"ccurme",
|
||||
"crystalro0",
|
||||
"dqbd",
|
||||
"emily-langchain",
|
||||
"eric-langchain",
|
||||
"EugeneJinXin",
|
||||
"eyurtsev",
|
||||
"gladwig2",
|
||||
"hari-dhanushkodi",
|
||||
"hinthornw",
|
||||
"hntrl",
|
||||
"hwchase17",
|
||||
"iakshay",
|
||||
"isahers1",
|
||||
"j-broekhuizen",
|
||||
"jacoblee93",
|
||||
"jdrogers940",
|
||||
"joaquin-borggio-lc",
|
||||
"katmayb",
|
||||
"keshivtandon",
|
||||
"langchain-infra",
|
||||
"lc-arjun",
|
||||
"lc-chad",
|
||||
"lnhsingh",
|
||||
"madams0013",
|
||||
"mdrxy",
|
||||
"mhk197",
|
||||
"nfcampos",
|
||||
"nhuang-lc",
|
||||
"nitboss",
|
||||
"PeriniM",
|
||||
"phvash",
|
||||
"QuentinBrosse",
|
||||
"rlancemartin",
|
||||
"romain-priour-lc",
|
||||
"samecrowder",
|
||||
"samnoyes",
|
||||
"starmorph",
|
||||
"suraj-langchain",
|
||||
"sydney-runkle",
|
||||
"tanushree-sharma",
|
||||
"victorm-lc",
|
||||
"xornivore",
|
||||
"xuro-langchain",
|
||||
"Palashio",
|
||||
"ads2280",
|
||||
];
|
||||
|
||||
// HACK: Until we setup proper support for API credits, we will only allow users to self host Open SWE
|
||||
export function isAllowedUser(username: string): boolean {
|
||||
const nodeEnv = process.env.NODE_ENV;
|
||||
// Allow all users in non-production environments
|
||||
if (nodeEnv !== "production") {
|
||||
return true;
|
||||
}
|
||||
|
||||
const restrictToLangChainAuth =
|
||||
process.env.RESTRICT_TO_LANGCHAIN_AUTH === "true" ||
|
||||
process.env.NEXT_PUBLIC_RESTRICT_TO_LANGCHAIN_AUTH === "true";
|
||||
if (!restrictToLangChainAuth) {
|
||||
return true;
|
||||
}
|
||||
return ALLOWED_USERS.some((u) => u === username);
|
||||
|
||||
let allowedUsers: string[] = [];
|
||||
try {
|
||||
allowedUsers = process.env.NEXT_PUBLIC_ALLOWED_USERS_LIST
|
||||
? JSON.parse(process.env.NEXT_PUBLIC_ALLOWED_USERS_LIST)
|
||||
: [];
|
||||
if (!allowedUsers.length) {
|
||||
return false;
|
||||
}
|
||||
} catch (error) {
|
||||
// eslint-disable-next-line no-console
|
||||
console.error("Failed to parse allowed users list", error);
|
||||
return false;
|
||||
}
|
||||
|
||||
return allowedUsers.some((u) => u === username);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue