From 2eaa5bfdd9eb86895a617d9c09f1dd1cd6f06709 Mon Sep 17 00:00:00 2001 From: npmrun <1549469775@qq.com> Date: Sun, 9 Aug 2026 15:22:10 +0800 Subject: [PATCH] fix: filter tool chips by public whitelist for guests in /api/llm/chat/tools getEnabledToolInfos now accepts userId and filters by agentPublicToolSlugs for unauthenticated users, so document and other non-public tools no longer show as chips above the input box for guests. Co-authored-by: CodeFree --- server/api/llm/chat/tools.get.ts | 2 +- server/service/agent-tool/index.ts | 12 +++++++++++- 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/server/api/llm/chat/tools.get.ts b/server/api/llm/chat/tools.get.ts index 0241436..7174013 100644 --- a/server/api/llm/chat/tools.get.ts +++ b/server/api/llm/chat/tools.get.ts @@ -3,6 +3,6 @@ import { getEnabledToolInfos } from "#server/service/agent-tool"; export default defineWrappedResponseHandler(async (event) => { const user = await getCurrentUser(event); - const result = await getEnabledToolInfos(user?.role ?? null); + const result = await getEnabledToolInfos(user?.role ?? null, user?.id ?? null); return R.success(result); }); diff --git a/server/service/agent-tool/index.ts b/server/service/agent-tool/index.ts index 2e42f88..7865305 100644 --- a/server/service/agent-tool/index.ts +++ b/server/service/agent-tool/index.ts @@ -362,7 +362,10 @@ export interface EnabledToolInfo { description: string; } -export async function getEnabledToolInfos(userRole: UserRole | null = null): Promise { +export async function getEnabledToolInfos( + userRole: UserRole | null = null, + userId: number | null = null, +): Promise { const tools = await dbGlobal .select() .from(agentTools) @@ -370,10 +373,17 @@ export async function getEnabledToolInfos(userRole: UserRole | null = null): Pro .orderBy(asc(agentTools.sortOrder)); const isAdmin = userRole === "admin"; + const isGuest = !userId; + + let publicToolSlugs: string[] = []; + if (isGuest) { + publicToolSlugs = await getConfigGlobal("agentPublicToolSlugs"); + } const result: EnabledToolInfo[] = []; for (const agentTool of tools) { if (!isAdmin && agentTool.adminOnly) continue; + if (isGuest && !publicToolSlugs.includes(agentTool.slug)) continue; const executor = getExecutor(agentTool.type); if (!executor) continue; let config: unknown;