Changeset 0.24.2 (#158)
This commit is contained in:
@@ -9,6 +9,7 @@ import (
|
||||
"github.com/gin-gonic/gin"
|
||||
|
||||
capspkg "git.gobha.me/xcaliber/chat-switchboard/capabilities"
|
||||
"git.gobha.me/xcaliber/chat-switchboard/auth"
|
||||
"git.gobha.me/xcaliber/chat-switchboard/database"
|
||||
"git.gobha.me/xcaliber/chat-switchboard/health"
|
||||
"git.gobha.me/xcaliber/chat-switchboard/models"
|
||||
@@ -56,6 +57,23 @@ func (h *ModelHandler) ListEnabledModels(c *gin.Context) {
|
||||
// Include admin default model so frontend can use it in resolution chain
|
||||
defaultModel, _ := h.stores.Policies.Get(c.Request.Context(), "default_model")
|
||||
|
||||
// Model allowlist filtering (v0.24.2) — non-admin users with group-level
|
||||
// model restrictions only see permitted models. Persona entries whose
|
||||
// underlying model is disallowed are also filtered.
|
||||
role, _ := c.Get("role")
|
||||
if role != "admin" {
|
||||
allowlist, err := auth.ResolveModelAllowlist(c.Request.Context(), h.stores, userID)
|
||||
if err == nil && allowlist != nil {
|
||||
filtered := make([]models.UserModel, 0, len(userModels))
|
||||
for _, m := range userModels {
|
||||
if allowlist[m.ModelID] {
|
||||
filtered = append(filtered, m)
|
||||
}
|
||||
}
|
||||
userModels = filtered
|
||||
}
|
||||
}
|
||||
|
||||
c.JSON(http.StatusOK, gin.H{"models": userModels, "default_model": defaultModel})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user