What's New
Security hardening across all HTTP-facing components.
Web UI (soup ui)
- Bearer token auth on all mutating endpoints (POST/DELETE) — token printed at startup
- CORS restricted to served origin (no more wildcard
*) - Path traversal protection on
/api/data/inspect— sandboxed to working directory - Config validation before writing to disk and spawning training
- Removed user-controlled
config_pathfrom train API (fixed temp path)
Inference Server (soup serve)
max_tokenscapped at 16,384 per request (prevents resource exhaustion)- Generic error messages in HTTP responses (no stack traces or internal details)
Data Generation (soup data generate)
- SSRF protection —
--api-baseblocks non-HTTPS for remote URLs (HTTP allowed for localhost) --api-keydeprecated — useOPENAI_API_KEYenv var instead- API error responses no longer echo response body (prevents potential key leak)
Export (soup export)
- llama.cpp cloned from pinned tag
b5270(not HEAD) for supply-chain safety
Other
soup push --tokendeprecated — useHF_TOKENenv var instead- Warning printed before executing custom
.pyreward files (arbitrary code awareness) - All 666 tests pass (40 UI tests updated with auth headers)
Install / Upgrade
pip install --upgrade soup-cli