fix: Make the allowed users list an env var (#789)

* fix: Make the allowed users list an env var

* cr
This commit is contained in:
Brace Sproul 2025-08-21 11:40:36 -07:00 • committed by GitHub
parent f246c811ea
commit 53e5dd954d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
5 changed files with 48 additions and 67 deletions

View file

@ -80,6 +80,11 @@ Before starting, ensure you have the following installed:
...add your private key here...
-----END RSA PRIVATE KEY-----
"
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
# This is only used in production. In development every user is an "allowed user".
# Must be a valid JSON array of strings.
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
```
### Agent Environment Variables (`apps/open-swe/.env`)
@ -120,8 +125,15 @@ Before starting, ensure you have the following installed:
# CI/CD. See the /labs/swe/setup/ci for more information
SKIP_CI_UNTIL_LAST_COMMIT="true"
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
# This is only used in production. In development every user is an "allowed user".
# Must be a valid JSON array of strings.
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
```
If you don't set the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable, every user will be required to set their own LLM API keys to use the agent. Additionally, none of the webhook features (triggering new runs by adding labels to GitHub issues, tagging the agent in PR reviews, etc.) will work unless you include the username's of the GitHub users you want to allow access to in the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable (in both web and agent deployments).
<Tip>
Generate the `SECRETS_ENCRYPTION_KEY` using: `openssl rand -hex 32`. This key must be identical in both environment files.
</Tip>

View file

@ -152,16 +152,14 @@ This should match the username from Step 1 (without the @ symbol).
### Step 4: Update Allowed Users
Add the GitHub usernames who should be allowed to trigger runs to the `ALLOWED_USERS` list in `packages/shared/src/github/allowed-users.ts`:
Add the GitHub usernames who should be allowed to trigger runs to the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable in your agent's deployment environment (include in the production deployments for both the web app and agent to take advantage of the allowed users functionality).
```typescript
export const ALLOWED_USERS = [
"your-github-username",
"teammate-username",
// ... other allowed users
];
```bash
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'
```
When running locally, every user is an "allowed user". It's also recommended to set this environment variable in your web app's production environment variables so your users won't need to set their own API keys when invoking Open SWE via the web app.
<Tip>
After making these configuration changes, restart your Open SWE instance to ensure the new settings take effect. You can then test the functionality by tagging your custom username in a PR comment.
</Tip>

View file

@ -58,3 +58,7 @@ SKIP_CI_UNTIL_LAST_COMMIT="true"
# OPEN_SWE_LOCAL_MODE=false
# OPEN_SWE_LOCAL_PROJECT_PATH=""
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
# This is only used in production. In development every user is an "allowed user".
# Must be a valid JSON array of strings.
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'

View file

@ -27,3 +27,8 @@ LANGGRAPH_API_URL="http://localhost:2024"
# Should be the same value as the one used in the web app, so that secrets
# encrypted in the web app can be decrypted in the agent.
SECRETS_ENCRYPTION_KEY=""
# List of GitHub usernames that are allowed to use Open SWE without providing API keys
# This is only used in production. In development every user is an "allowed user".
# Must be a valid JSON array of strings.
NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]'

View file

@ -1,69 +1,31 @@
export const ALLOWED_USERS = [
"agola11",
"akira",
"aliyanishfaq",
"andrewnguonly",
"angus-langchain",
"bracesproul",
"ArthurLangChain",
"baskaryan",
"bvs-langchain",
"catherine-langchain",
"ccurme",
"crystalro0",
"dqbd",
"emily-langchain",
"eric-langchain",
"EugeneJinXin",
"eyurtsev",
"gladwig2",
"hari-dhanushkodi",
"hinthornw",
"hntrl",
"hwchase17",
"iakshay",
"isahers1",
"j-broekhuizen",
"jacoblee93",
"jdrogers940",
"joaquin-borggio-lc",
"katmayb",
"keshivtandon",
"langchain-infra",
"lc-arjun",
"lc-chad",
"lnhsingh",
"madams0013",
"mdrxy",
"mhk197",
"nfcampos",
"nhuang-lc",
"nitboss",
"PeriniM",
"phvash",
"QuentinBrosse",
"rlancemartin",
"romain-priour-lc",
"samecrowder",
"samnoyes",
"starmorph",
"suraj-langchain",
"sydney-runkle",
"tanushree-sharma",
"victorm-lc",
"xornivore",
"xuro-langchain",
"Palashio",
"ads2280",
];
// HACK: Until we setup proper support for API credits, we will only allow users to self host Open SWE
export function isAllowedUser(username: string): boolean {
const nodeEnv = process.env.NODE_ENV;
// Allow all users in non-production environments
if (nodeEnv !== "production") {
return true;
}
const restrictToLangChainAuth =
process.env.RESTRICT_TO_LANGCHAIN_AUTH === "true" ||
process.env.NEXT_PUBLIC_RESTRICT_TO_LANGCHAIN_AUTH === "true";
if (!restrictToLangChainAuth) {
return true;
}
return ALLOWED_USERS.some((u) => u === username);
let allowedUsers: string[] = [];
try {
allowedUsers = process.env.NEXT_PUBLIC_ALLOWED_USERS_LIST
? JSON.parse(process.env.NEXT_PUBLIC_ALLOWED_USERS_LIST)
: [];
if (!allowedUsers.length) {
return false;
}
} catch (error) {
// eslint-disable-next-line no-console
console.error("Failed to parse allowed users list", error);
return false;
}
return allowedUsers.some((u) => u === username);
}