A security release. Providers that use server credentials only send models the deployment authorizes, render jobs are bound to the requesting owner, and deleted courses stop serving their legacy media. Read Breaking change before upgrading, and upgrade the render-service together with or before the app. The same fixes ship in v1.2.0-rc.2. Thanks to @13ob0 and @Duang777 for the reports.
Advisories
- GHSA-r2xp-m5r2-g7xj (High): missing model authorization for server-managed provider credentials. Reported by @13ob0.
- GHSA-x3gm-gw9m-94h9 (Medium): MP4 render jobs not bound to the requesting owner. Reported by @Duang777.
- GHSA-6jrw-cp5x-j8jc (Low): deleted courses did not revoke legacy classroom media URLs. Reported by @Duang777.
Security
- Render jobs are bound to the requesting owner. Upgrade every render-service instance (or drain old instances) together with or before the app. Mixed service versions fail closed through a dedicated owner-bound job namespace.
- Legacy classroom media stops being served when its course is deleted. Media responses use private caching with revalidation, and lifecycle lookup failures fail closed.
- Providers using server credentials now authorize the selected model before provider access across chat, generation, media, voice, transcription, search and connection tests. Model authorization refusals return the same HTTP 403
PROVIDER_DISABLEDresponse. Users' own credentials and keyless providers are unaffected.
Breaking change: server-managed model authorization
- Configure
*_MODELSor each provider's YAMLmodelslist. Without a list, chat authorizes onlyDEFAULT_MODELand operatorMODEL_ROUTESreferences; other model-selecting capabilities authorize only their single default. Preset catalogues do not grant access. Services without model selection need no list. - With an explicit list, TTS, ASR, image, video and Claude web search use a listed client choice or substitute the first listed model for an unlisted or missing choice. Speech preview, narration and transcription send catalogue defaults on the 1.1.x client: put the desired pinned model first, without needing to list the client default. Unlisted models never reach the provider with server credentials.
- Qwen clone voices map the built-in clone sentinel to the configured
TTS_QWEN_VOICE_CLONE_MODELbefore authorization. Include the final clone target in the TTS model list; the override alone does not authorize it. - Migration: list all selectable model ids, including voice compatibility models, restart the server, and update saved chat selections and capability selections without explicit lists outside the authorized set. Startup warnings identify credentialed model-selecting providers without a list. Give a gateway that adds upstream credentials a key and a model list, or restrict models in the gateway itself.