mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix(coderd): allow non-admin users to list chat model configs (#22407)
## Problem Non-admin users of the Agents (chat) feature send `model_config_id: "00000000-0000-0000-0000-000000000000"` (nil UUID) when creating chats, because the `GET /api/experimental/chats/model-configs` endpoint requires `policy.ActionRead` on `rbac.ResourceDeploymentConfig`, which is only granted to admins. The flow: 1. `AgentsPage.tsx` calls `useQuery(chatModelConfigs())` → hits `listChatModelConfigs` 2. Non-admin users get a **403 Forbidden** response 3. `chatModelConfigsQuery.data` is `undefined`, so the `modelConfigIDByModelID` map is empty 4. `handleCreateChat` falls back to `nilUUID` for `model_config_id` 5. The backend rejects the nil UUID: `"Invalid model config ID."` ## Fix Changed `listChatModelConfigs` to allow all authenticated users to read model configs: - **Admin users** continue to see all configs (including disabled ones) for management via `GetChatModelConfigs` - **Non-admin users** now see only enabled configs via `GetEnabledChatModelConfigs` with a system context, which is sufficient for using the chat feature This follows the same pattern as `listChatModels`, which already uses `dbauthz.AsSystemRestricted(ctx)` to allow all authenticated users to see available models. Write endpoints (create/update/delete) retain their existing `ResourceDeploymentConfig` authorization. ## Testing - Updated `TestListChatModelConfigs/ForbiddenForOrganizationMember` → `SuccessForOrganizationMember` to verify non-admin users can list enabled model configs - All existing chat tests continue to pass
This commit is contained in:
+13
-5
@@ -2444,12 +2444,20 @@ func (api *API) deleteChatProvider(rw http.ResponseWriter, r *http.Request) {
|
||||
|
||||
func (api *API) listChatModelConfigs(rw http.ResponseWriter, r *http.Request) {
|
||||
ctx := r.Context()
|
||||
if !api.Authorize(r, policy.ActionRead, rbac.ResourceDeploymentConfig) {
|
||||
httpapi.Forbidden(rw)
|
||||
return
|
||||
}
|
||||
|
||||
configs, err := api.Database.GetChatModelConfigs(ctx)
|
||||
// Admin users can see all model configs (including disabled ones)
|
||||
// for management purposes. Non-admin users see only enabled
|
||||
// configs, which is sufficient for using the chat feature.
|
||||
isAdmin := api.Authorize(r, policy.ActionRead, rbac.ResourceDeploymentConfig)
|
||||
|
||||
var configs []database.ChatModelConfig
|
||||
var err error
|
||||
if isAdmin {
|
||||
configs, err = api.Database.GetChatModelConfigs(ctx)
|
||||
} else {
|
||||
//nolint:gocritic // All authenticated users need to read enabled model configs to use the chat feature.
|
||||
configs, err = api.Database.GetEnabledChatModelConfigs(dbauthz.AsSystemRestricted(ctx))
|
||||
}
|
||||
if err != nil {
|
||||
httpapi.Write(ctx, rw, http.StatusInternalServerError, codersdk.Response{
|
||||
Message: "Failed to list chat model configs.",
|
||||
|
||||
Reference in New Issue
Block a user