From 53e5dd954db2c663ff5b4cb3e4ae6c13538456f3 Mon Sep 17 00:00:00 2001 From: Brace Sproul Date: Thu, 21 Aug 2025 11:40:36 -0700 Subject: [PATCH] fix: Make the allowed users list an env var (#789) * fix: Make the allowed users list an env var * cr --- apps/docs/setup/development.mdx | 12 +++ apps/docs/usage/pr-tagging.mdx | 12 ++- apps/open-swe/.env.example | 4 + apps/web/.env.example | 5 ++ packages/shared/src/github/allowed-users.ts | 82 ++++++--------------- 5 files changed, 48 insertions(+), 67 deletions(-) diff --git a/apps/docs/setup/development.mdx b/apps/docs/setup/development.mdx index 8911d162..f6d933e5 100644 --- a/apps/docs/setup/development.mdx +++ b/apps/docs/setup/development.mdx @@ -80,6 +80,11 @@ Before starting, ensure you have the following installed: ...add your private key here... -----END RSA PRIVATE KEY----- " + + # List of GitHub usernames that are allowed to use Open SWE without providing API keys + # This is only used in production. In development every user is an "allowed user". + # Must be a valid JSON array of strings. + NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]' ``` ### Agent Environment Variables (`apps/open-swe/.env`) @@ -120,8 +125,15 @@ Before starting, ensure you have the following installed: # CI/CD. See the /labs/swe/setup/ci for more information SKIP_CI_UNTIL_LAST_COMMIT="true" + + # List of GitHub usernames that are allowed to use Open SWE without providing API keys + # This is only used in production. In development every user is an "allowed user". + # Must be a valid JSON array of strings. + NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]' ``` + If you don't set the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable, every user will be required to set their own LLM API keys to use the agent. Additionally, none of the webhook features (triggering new runs by adding labels to GitHub issues, tagging the agent in PR reviews, etc.) will work unless you include the username's of the GitHub users you want to allow access to in the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable (in both web and agent deployments). + Generate the `SECRETS_ENCRYPTION_KEY` using: `openssl rand -hex 32`. This key must be identical in both environment files. diff --git a/apps/docs/usage/pr-tagging.mdx b/apps/docs/usage/pr-tagging.mdx index d411718a..cfe0391b 100644 --- a/apps/docs/usage/pr-tagging.mdx +++ b/apps/docs/usage/pr-tagging.mdx @@ -152,16 +152,14 @@ This should match the username from Step 1 (without the @ symbol). ### Step 4: Update Allowed Users -Add the GitHub usernames who should be allowed to trigger runs to the `ALLOWED_USERS` list in `packages/shared/src/github/allowed-users.ts`: +Add the GitHub usernames who should be allowed to trigger runs to the `NEXT_PUBLIC_ALLOWED_USERS_LIST` environment variable in your agent's deployment environment (include in the production deployments for both the web app and agent to take advantage of the allowed users functionality). -```typescript -export const ALLOWED_USERS = [ - "your-github-username", - "teammate-username", - // ... other allowed users -]; +```bash +NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]' ``` +When running locally, every user is an "allowed user". It's also recommended to set this environment variable in your web app's production environment variables so your users won't need to set their own API keys when invoking Open SWE via the web app. + After making these configuration changes, restart your Open SWE instance to ensure the new settings take effect. You can then test the functionality by tagging your custom username in a PR comment. diff --git a/apps/open-swe/.env.example b/apps/open-swe/.env.example index b863ea0c..1be9127e 100644 --- a/apps/open-swe/.env.example +++ b/apps/open-swe/.env.example @@ -58,3 +58,7 @@ SKIP_CI_UNTIL_LAST_COMMIT="true" # OPEN_SWE_LOCAL_MODE=false # OPEN_SWE_LOCAL_PROJECT_PATH="" +# List of GitHub usernames that are allowed to use Open SWE without providing API keys +# This is only used in production. In development every user is an "allowed user". +# Must be a valid JSON array of strings. +NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]' diff --git a/apps/web/.env.example b/apps/web/.env.example index 9ba4e23d..f85441cc 100644 --- a/apps/web/.env.example +++ b/apps/web/.env.example @@ -27,3 +27,8 @@ LANGGRAPH_API_URL="http://localhost:2024" # Should be the same value as the one used in the web app, so that secrets # encrypted in the web app can be decrypted in the agent. SECRETS_ENCRYPTION_KEY="" + +# List of GitHub usernames that are allowed to use Open SWE without providing API keys +# This is only used in production. In development every user is an "allowed user". +# Must be a valid JSON array of strings. +NEXT_PUBLIC_ALLOWED_USERS_LIST='["your-github-username", "teammate-username"]' \ No newline at end of file diff --git a/packages/shared/src/github/allowed-users.ts b/packages/shared/src/github/allowed-users.ts index 926b39b6..ae5ac921 100644 --- a/packages/shared/src/github/allowed-users.ts +++ b/packages/shared/src/github/allowed-users.ts @@ -1,69 +1,31 @@ -export const ALLOWED_USERS = [ - "agola11", - "akira", - "aliyanishfaq", - "andrewnguonly", - "angus-langchain", - "bracesproul", - "ArthurLangChain", - "baskaryan", - "bvs-langchain", - "catherine-langchain", - "ccurme", - "crystalro0", - "dqbd", - "emily-langchain", - "eric-langchain", - "EugeneJinXin", - "eyurtsev", - "gladwig2", - "hari-dhanushkodi", - "hinthornw", - "hntrl", - "hwchase17", - "iakshay", - "isahers1", - "j-broekhuizen", - "jacoblee93", - "jdrogers940", - "joaquin-borggio-lc", - "katmayb", - "keshivtandon", - "langchain-infra", - "lc-arjun", - "lc-chad", - "lnhsingh", - "madams0013", - "mdrxy", - "mhk197", - "nfcampos", - "nhuang-lc", - "nitboss", - "PeriniM", - "phvash", - "QuentinBrosse", - "rlancemartin", - "romain-priour-lc", - "samecrowder", - "samnoyes", - "starmorph", - "suraj-langchain", - "sydney-runkle", - "tanushree-sharma", - "victorm-lc", - "xornivore", - "xuro-langchain", - "Palashio", - "ads2280", -]; - // HACK: Until we setup proper support for API credits, we will only allow users to self host Open SWE export function isAllowedUser(username: string): boolean { + const nodeEnv = process.env.NODE_ENV; + // Allow all users in non-production environments + if (nodeEnv !== "production") { + return true; + } + const restrictToLangChainAuth = process.env.RESTRICT_TO_LANGCHAIN_AUTH === "true" || process.env.NEXT_PUBLIC_RESTRICT_TO_LANGCHAIN_AUTH === "true"; if (!restrictToLangChainAuth) { return true; } - return ALLOWED_USERS.some((u) => u === username); + + let allowedUsers: string[] = []; + try { + allowedUsers = process.env.NEXT_PUBLIC_ALLOWED_USERS_LIST + ? JSON.parse(process.env.NEXT_PUBLIC_ALLOWED_USERS_LIST) + : []; + if (!allowedUsers.length) { + return false; + } + } catch (error) { + // eslint-disable-next-line no-console + console.error("Failed to parse allowed users list", error); + return false; + } + + return allowedUsers.some((u) => u === username); }