Security release candidate for 1.2.0. It fixes three vulnerabilities reported privately; see the advisories below.
Upgrade notes
- Providers that use server credentials now need an explicit model list (
*_MODELSormodels); without one only default/fallback models are usable. See the breaking-change section below.- Upgrade the render-service together with or before the app.
Thanks to @13ob0 and @Duang777 for the reports and fixes.
Advisories
- GHSA-r2xp-m5r2-g7xj (High): missing model authorization for server-managed provider credentials. Reported by @13ob0.
- GHSA-x3gm-gw9m-94h9 (Medium): MP4 render jobs not bound to the requesting owner. Reported by @Duang777.
- GHSA-6jrw-cp5x-j8jc (Low): deleted courses did not revoke legacy classroom media URLs. Reported by @Duang777.
Security
- Enforce model authorization for server-managed providers across chat, media, speech, model-based web search and workspace model assignments. Unauthorized and unknown model ids return the same HTTP 403 response before provider access. Users' own credentials continue to work. #1879 (with @13ob0)
- Render jobs are bound to the requesting owner. The render-service and app must be upgraded together; upgrade every service instance (or drain old instances) together with or before the app. Old/new version mixes fail closed through a dedicated owner-bound job namespace. #1884 (by @Duang777)
- Deleted courses no longer serve their legacy classroom media:
/api/classroom-media/<id>/...checks the course lifecycle before touching the filesystem and answers a tombstoned course with the same 404 as a missing file. Successful responses areprivate, max-age=300, must-revalidateinstead ofpublic, immutable. #1883 (by @Duang777)
Breaking change: server-managed model authorization
- Set
*_MODELSfor every provider with server-managed credentials, or setmodelsunder each provider inopenmaic.yml/server-providers.yml. Without a list, only deployment default/fallback and capability slot references authorize models; preset catalogues and workspace assignments do not. Provider-only media slots authorize a single adapter default. Services without model ids need no list. Providers configured without credentials (local Ollama, Lemonade) are not restricted; a keyless gateway that adds its own upstream credential should be given a key and a model list. - Migration: list the model ids users should be able to select (including voice compatibility models), restart the server, then update workspace selections that are no longer authorized. A startup warning names the configuration setting for each provider with credentials but no explicit list.
Bug Fixes
- S3 asset storage:
@openmaic/storage0.37.3 supports path-style addressing for S3-compatible object stores such as MinIO and Ceph. SetAWS_S3_FORCE_PATH_STYLE=true(or1) together withAWS_ENDPOINT_URL_S3so objects are addressed asendpoint/bucket/key; leaving it unset keeps the existing behaviour for Amazon S3 (#1686). - Server persistence:
@openmaic/storage0.37.2 boundsHttpDocumentStorerequests with a deadline (requestTimeoutMs, default 30s,<= 0disables) covering the request round trip — sending the body and receiving the response headers — so a persistence endpoint that stops answering fails like any other transport error instead of holding its caller forever. The stage autosave keeps at most one save in flight and starts the next only once that promise settles, so a request that never settled silently stranded every later save for the life of the page while the editor went on rendering the in-memory document; the reload showed what had actually reached the server. A request aborted at the deadline rejects withHTTP_REQUEST_TIMEOUT, which the autosave's existing backoff retries. The budget is the floor plus an allowance proportional to the request body (sized at a fixed 100 KiB/s) and is capped at 10 minutes, so a large document on a slow link is not mistaken for a stall; reading the response body stays outside the bound. This mirrors the budgetHttpAssetStorealready applies throughprobeTimeoutMs/startBoundedOperation. - Synchronous scene previews and video exports no longer block each other; each uses its own execution lane. #1830
- Preview concurrency is capped by the render resource profile and reported by
/health. Cancelling a preview during Chromium startup retains its execution slot until launch and browser cleanup settle.