Repository navigation
fix(docs): update Telegram docs after .env hardening for allowed users (#70879) - #71038
Open
webtecnica wants to merge 2 commits into
Open
webtecnica wants to merge 2 commits into
webtecnica wants to merge 2 commits into
Conversation
…de (NousResearch#70867) When the dashboard is launched with --isolated, the API must reject ?profile= requests targeting any profile other than the one the server is scoped to. Without this guard, a user on an isolated dashboard could read/write another profile's config, sessions, skills, and env vars simply by passing ?profile=<other>. Changes: - Add _check_isolated_profile_access() helper that compares the requested profile directory against the server's own HERMES_HOME - Wire the check into _profile_scope(), _config_profile_scope(), and _open_session_db_for_profile() — the three gateways through which all profile-scoped API requests pass - Add 'isolated' parameter to start_server() and store it on app.state - Forward the CLI --isolated flag from cmd_dashboard to start_server() Closes: NousResearch#70867
webtecnica
force-pushed
the
fix/docs-telegram-env
branch
from
July 26, 2026 23:35
3698de4 to
6852da6
Compare
1 task
Collaborator
|
Thanks for addressing the Problems
Suggested changes
Automated hermes-sweeper review. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates Telegram documentation across 12 files to reflect .env hardening in v0.19. Non-secret settings moved from .env to config.yaml. Secrets (bot token) remain in .env.
Fixes #70879