Skip to content

馃攼 fix: Gate Shared Startup Config By Link Access - #13897

Merged
danny-avila merged 4 commits into
devfrom
danny-avila/share-scoped-startup-config
Jun 23, 2026
Merged

danny-avila merged 4 commits into
devfrom
danny-avila/share-scoped-startup-config

Conversation

@danny-avila

Copy link
Copy Markdown
Collaborator

Summary

Fixes #13881.

I routed shared-conversation startup config through the same shared-link access boundary as shared messages, so private/auth-required shares no longer rely on a loose context=share startup config path.

  • Added GET /api/share/:shareId/config behind optionalJwtAuth and canAccessSharedLink, returning private, no-store responses.
  • Added a shared-link startup payload builder that only exposes the share view allowlist: app title, analytics ID, custom footer, privacy/terms links, and Sandpack bundler URLs.
  • Updated ShareView and shared artifact previews to read startup config from the share-scoped endpoint, including Sandpack options for bundlerURL and staticBundlerURL.
  • Removed unauthenticated share-only field exposure from GET /api/config?context=share.
  • Added tests for the new route, tenant/base config resolution, the payload allowlist, and the generic config route negative case.

Change Type

  • Bug fix (non-breaking change which fixes an issue)

Testing

  • npm run smart-reinstall
  • cd packages/api && npx jest src/shared-links/config.test.ts --runInBand --coverage=false
  • cd api && npx jest server/routes/__tests__/config.spec.js server/routes/__tests__/share.spec.js --runInBand
  • cd api && npx jest server/routes/__tests__/share.spec.js --runInBand

Test Configuration:

  • Node.js v24.16.0
  • Local workspace install via npm ci from npm run smart-reinstall

Checklist

  • My code adheres to this project's style guidelines
  • I have performed a self-review of my own code
  • My changes do not introduce new warnings
  • I have written tests demonstrating that my changes are effective
  • Local unit tests pass with my changes

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@danny-avila
danny-avila changed the base branch from main to dev June 23, 2026 11:04
@danny-avila
danny-avila marked this pull request as ready for review June 23, 2026 11:04

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 23cf9a3e82

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

if (allowSharedLinks) {
router.get('/:shareId/config', optionalJwtAuth, canAccessSharedLink, async (_req, res) => {
try {
const payload = await getShareStartupPayload();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject expired shares before returning config

When a shared link has expired but its ACL entry has not yet been TTL-cleaned, canAccessSharedLink can still call next() because it looks up the raw SharedLink and checks ACL only; the existing message/file paths then re-check activeExpirationFilter in getSharedMessages/getSharedLinkFile, but this new config path immediately returns the payload. That lets /api/share/:shareId/config disclose the gated footer/analytics/bundler config for a link that /api/share/:shareId would 404, so please re-read the active share or add the expiration check before building the payload.

Useful? React with 馃憤聽/ 馃憥.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in f46c4bd. The shared-link access middleware now reads only active, non-expired shares with activeExpirationFilter before checking ACL/public access, so /api/share/:shareId/config cannot return config for expired links waiting on TTL cleanup. Added a regression test covering an expired shared link with a still-valid PUBLIC ACL. Verified with: cd packages/api && npx jest src/shared-links/access.test.ts --runInBand --coverage=false; cd api && npx jest server/routes/tests/share.spec.js --runInBand; npx tsc --noEmit -p packages/api/tsconfig.json; eslint/sort-imports/prettier checks for touched files.

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Another round soon, please!

Reviewed commit: f46c4bd9f3

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@danny-avila
danny-avila merged commit e807c63 into dev Jun 23, 2026
30 checks passed
@danny-avila
danny-avila deleted the danny-avila/share-scoped-startup-config branch June 23, 2026 12:28
fuuuzzy pushed a commit to fuuuzzy/LibreChat that referenced this pull request Jul 7, 2026
* fix: gate shared startup config by link access

* fix: satisfy shared config CI checks

* fix: align shared config client types

* fix: reject expired shared link access
ThomasVuNguyen pushed a commit to ThomasVuNguyen/LibreChat that referenced this pull request Jul 15, 2026
* fix: gate shared startup config by link access

* fix: satisfy shared config CI checks

* fix: align shared config client types

* fix: reject expired shared link access
LogicalAbsurd pushed a commit to LogicalAbsurd/LibreChat that referenced this pull request Aug 27, 2026
* fix: gate shared startup config by link access

* fix: satisfy shared config CI checks

* fix: align shared config client types

* fix: reject expired shared link access
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Shared-conversation artifacts ignore the configured Sandpack bundlerURL/staticBundlerURL (fall back to codesandbox.io)

1 participant