Skip to content
Merged
Show file tree
Hide file tree
Changes from 49 commits
Commits
Show all changes
70 commits
Select commit Hold shift + click to select a range
294effc
fix(security): harden multi-tenant code-exec and env-var leak surfaces
jordanrfrazier Jun 6, 2026
2137de4
fix(security): close 4 multi-tenant secret-leak, SSRF, and file-read …
jordanrfrazier Jun 6, 2026
b0a6350
fix(security): close 5 multi-tenant RCE, code-exec, and SSRF holes
jordanrfrazier Jun 6, 2026
9f15a60
fix(security): harden review-found gaps in the multi-tenant security …
jordanrfrazier Jun 7, 2026
bc38345
fix(security): address review findings on security-hardening PR
jordanrfrazier Jun 7, 2026
f226c36
fix(security): clarify connector SSRF errors and document hardening t…
jordanrfrazier Jun 8, 2026
ee274f1
fix(security): deny server secrets/DB within the local-file-access bo…
jordanrfrazier Jun 8, 2026
c206127
fix(security): bind agentic MCP tools to the authenticated user; clos…
jordanrfrazier Jun 8, 2026
8b473e4
fix(security): serve download_image with nosniff + attachment
jordanrfrazier Jun 8, 2026
cf4dab7
docs(security): warn against shared SaaS tracing in multi-tenant depl…
jordanrfrazier Jun 8, 2026
2f44a77
fix(security): gate agentic assistant codegen behind agentic_experien…
jordanrfrazier Jun 8, 2026
a91b967
fix(security): escape LIKE wildcards and allowlist message order_by
jordanrfrazier Jun 8, 2026
d9e2ed7
fix(security): pin watsonx orchestrate run target to the deployment r…
jordanrfrazier Jun 8, 2026
2fa4731
refactor(security): cleanup pass on the multi-tenant hardening PR
jordanrfrazier Jun 8, 2026
a459b48
[autofix.ci] apply automated fixes
autofix-ci[bot] Jun 16, 2026
8f259a9
[autofix.ci] apply automated fixes (attempt 2/3)
autofix-ci[bot] Jun 16, 2026
a7bc0c5
[autofix.ci] apply automated fixes (attempt 3/3)
autofix-ci[bot] Jun 16, 2026
79fca45
fix(security): harden MCP docker args, vector-store paths, env-var leaks
jordanrfrazier Jun 22, 2026
babdbc1
refactor(security): dedupe the local-file-access restriction reader
jordanrfrazier Jun 23, 2026
3355be9
docs(security): tighten over-explained comments in the MCP/env-var gu…
jordanrfrazier Jun 24, 2026
513423c
fix(security): address hardening review feedback
erichare Jun 30, 2026
770deea
[autofix.ci] apply automated fixes
autofix-ci[bot] Jun 30, 2026
961ffe8
[autofix.ci] apply automated fixes (attempt 2/3)
autofix-ci[bot] Jun 30, 2026
0aafdbe
chore: update generated hash secrets baseline
erichare Jun 30, 2026
ad73cc7
test(lfx): expect resolved confined symlink path
erichare Jun 30, 2026
36c6d11
fix(security): enforce KB-root containment for username-derived paths…
erichare Jun 30, 2026
1f39a4b
fix(security): stop trusting X-Forwarded-For for the MCP install loca…
erichare Jun 30, 2026
331b637
fix(security): scrub stored secrets from public flow read (#13914)
erichare Jun 30, 2026
2121a7f
fix(security): allow loopback for connector/model-provider URLs by de…
erichare Jun 30, 2026
304a132
Merge branch 'release-1.11.0' into security-hardening
erichare Jun 30, 2026
c9b9b60
test(lfx): add connector_ssrf_allow_loopback to expected settings fields
erichare Jun 30, 2026
34318c0
Merge branch 'release-1.11.0' into security-hardening
erichare Jun 30, 2026
068c983
fix(security): run server-trusted component code on the restricted bu…
erichare Jun 30, 2026
a868152
test(mcp): use allowlisted commands + disable SSRF in mocked MCP unit…
erichare Jun 30, 2026
461e6f0
fix(security): stabilize backend tests broken by multi-tenant SSRF ha…
erichare Jul 1, 2026
15a7777
[autofix.ci] apply automated fixes
autofix-ci[bot] Jul 1, 2026
402e7bf
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 1, 2026
186e2a0
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 1, 2026
db276d6
chore: auto-bake note keys and regenerate backend locales/en.json [sk…
github-actions[bot] Jul 1, 2026
1a4505b
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 1, 2026
fc38da2
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 1, 2026
d9a5abc
test: mock OpenAI base URL SSRF validation
erichare Jul 1, 2026
9a7c325
Merge remote-tracking branch 'origin/release-1.11.0' into security-ha…
erichare Jul 1, 2026
d60f7d1
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 1, 2026
642907b
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 1, 2026
192d180
chore: update default secuirty toggles
Adam-Aghili Jun 30, 2026
93e1803
Chore: add bob to .gitignore
Adam-Aghili Jul 2, 2026
b321621
fix(security): scope chat-history retrieval to the owning user (#13922)
erichare Jul 2, 2026
742bf4e
Merge remote-tracking branch 'origin/release-1.11.0' into security-ha…
erichare Jul 2, 2026
62ac37d
Merge remote-tracking branch 'origin/release-1.11.0' into security-ha…
erichare Jul 7, 2026
b1b4fc8
[autofix.ci] apply automated fixes
autofix-ci[bot] Jul 7, 2026
c308f43
fix: merge release
erichare Jul 7, 2026
eabcc87
fix(migrations): merge chat-history-scope and span-enum alembic heads
erichare Jul 8, 2026
4d485c9
test(wxo): align run-payload test with owner-pinned agent_id hardening
erichare Jul 8, 2026
66cfe81
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 8, 2026
df26211
Merge branch 'release-1.11.0' into security-hardening
Adam-Aghili Jul 8, 2026
2e7bfba
fix: scrub nested nodes
Adam-Aghili Jul 8, 2026
c921024
chore: harden mcp command scrubing
Adam-Aghili Jul 8, 2026
38acb03
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 9, 2026
06e7c85
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 9, 2026
5e552d6
fix(ci): repair security hardening checks
erichare Jul 9, 2026
66c3280
fix(ci): align mcp security test expectations
erichare Jul 9, 2026
628acbd
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 9, 2026
a8b23ed
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 13, 2026
50c217d
fix: merge alembic heads 9d5e24d777bf and b7f91a2c4d6e
erichare Jul 13, 2026
ef86c48
fix(migrations): backfill legacy message ownership
erichare Jul 13, 2026
690c780
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 13, 2026
139a3a1
[autofix.ci] apply automated fixes
autofix-ci[bot] Jul 13, 2026
208dba6
Merge branch 'release-1.11.0' into security-hardening
erichare Jul 13, 2026
b72f5c2
Merge remote-tracking branch 'origin/release-1.11.0' into security-ha…
jordanrfrazier Jul 13, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -301,3 +301,6 @@ tmp_toolguard/
#whitesource
whitesource/
/.codex

#ai folders
.bob/
22 changes: 11 additions & 11 deletions .secrets.baseline
Original file line number Diff line number Diff line change
Expand Up @@ -2536,7 +2536,7 @@
{
"type": "Hex High Entropy String",
"filename": "src/backend/base/langflow/initial_setup/starter_projects/Content Aggregator.json",
"hashed_secret": "ae7a06338d3caf89988fc523f8e2bd91e9035802",
"hashed_secret": "e3577aee1763ce364f257400e0809b5751693f7e",
"is_verified": false,
"line_number": 497
},
Expand Down Expand Up @@ -2571,7 +2571,7 @@
{
"type": "Hex High Entropy String",
"filename": "src/backend/base/langflow/initial_setup/starter_projects/Content Aggregator.json",
"hashed_secret": "dad509dc603e1f49a3156ef6979c2bad11dd35e3",
"hashed_secret": "4bf74df3b725a0731d59f7dba36bad3495854f94",
"is_verified": false,
"line_number": 2484
}
Expand Down Expand Up @@ -3321,25 +3321,25 @@
{
"type": "Hex High Entropy String",
"filename": "src/backend/base/langflow/initial_setup/starter_projects/Structured Data Analysis Agent.json",
"hashed_secret": "54ed260e3bc31bc77ee06754dff850981d39a66c",
"hashed_secret": "f217ab8e7d9dca7e5b2d196a728036db0b0462fc",
"is_verified": false,
"line_number": 1800,
"is_secret": false
"line_number": 1088
},
{
"type": "Hex High Entropy String",
"filename": "src/backend/base/langflow/initial_setup/starter_projects/Structured Data Analysis Agent.json",
"hashed_secret": "d6e6d7b4b115cd3b9d172623199f8c403055fecc",
"hashed_secret": "54ed260e3bc31bc77ee06754dff850981d39a66c",
"is_verified": false,
"line_number": 2096,
"line_number": 1800,
"is_secret": false
},
{
"type": "Hex High Entropy String",
"filename": "src/backend/base/langflow/initial_setup/starter_projects/Structured Data Analysis Agent.json",
"hashed_secret": "1a9497447f324df66d5b34587222e6835bbbe3df",
"hashed_secret": "d6e6d7b4b115cd3b9d172623199f8c403055fecc",
"is_verified": false,
"line_number": 2555
"line_number": 2096,
"is_secret": false
},
{
"type": "Hex High Entropy String",
Expand All @@ -3360,7 +3360,7 @@
{
"type": "Hex High Entropy String",
"filename": "src/backend/base/langflow/initial_setup/starter_projects/Structured Data Analysis Agent.json",
"hashed_secret": "dad509dc603e1f49a3156ef6979c2bad11dd35e3",
"hashed_secret": "4bf74df3b725a0731d59f7dba36bad3495854f94",
"is_verified": false,
"line_number": 5219,
"is_secret": false
Expand Down Expand Up @@ -4037,7 +4037,7 @@
"filename": "src/backend/tests/unit/api/v1/test_projects.py",
"hashed_secret": "8bb6118f8fd6935ad0876a3be34a717d32708ffd",
"is_verified": false,
"line_number": 1829
"line_number": 1856
}
],
"src/backend/tests/unit/api/v1/test_transactions.py": [
Expand Down
6 changes: 6 additions & 0 deletions docker/build_and_push.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,12 @@ WORKDIR /app

ENV LANGFLOW_HOST=0.0.0.0
ENV LANGFLOW_PORT=7860

# secuirty options
ENV LANGFLOW_AUTO_LOGIN=false
ENV LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false
ENV LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true
ENV LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true
ENV LANGFLOW_MCP_SERVER_DOCKER_HARDENING=true

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.


CMD ["langflow", "run"]
5 changes: 5 additions & 0 deletions docker/build_and_push_backend.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -116,6 +116,11 @@ WORKDIR /app

ENV LANGFLOW_HOST=0.0.0.0
ENV LANGFLOW_PORT=7860

# secuirty options
ENV LANGFLOW_AUTO_LOGIN=false
ENV LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false
ENV LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true
ENV LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true

CMD ["python", "-m", "langflow", "run", "--backend-only"]
5 changes: 5 additions & 0 deletions docker/build_and_push_base.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,11 @@ WORKDIR /app

ENV LANGFLOW_HOST=0.0.0.0
ENV LANGFLOW_PORT=7860

# secuirty options
ENV LANGFLOW_AUTO_LOGIN=false
ENV LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false
ENV LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true
ENV LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true

CMD ["langflow-base", "run"]
5 changes: 5 additions & 0 deletions docker/build_and_push_ep.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -126,7 +126,12 @@ WORKDIR /app
ENV LANGFLOW_HOST=0.0.0.0
ENV LANGFLOW_PORT=7860
ENV LANGFLOW_EVENT_DELIVERY=polling

# secuirty options
ENV LANGFLOW_AUTO_LOGIN=false
ENV LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false
ENV LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true
ENV LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true

USER 1000
CMD ["python", "-m", "langflow", "run", "--host", "0.0.0.0", "--backend-only"]
5 changes: 5 additions & 0 deletions docker/build_and_push_with_extras.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,11 @@ WORKDIR /app

ENV LANGFLOW_HOST=0.0.0.0
ENV LANGFLOW_PORT=7860

# secuirty options
ENV LANGFLOW_AUTO_LOGIN=false
ENV LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false
ENV LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true
ENV LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true

CMD ["langflow", "run"]
37 changes: 36 additions & 1 deletion docs/docs/Develop/api-keys-and-authentication.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -457,8 +457,43 @@ SSRF protection prevents requests to internal or private network resources, such

| Variable | Format | Default | Description |
|----------|--------|---------|-------------|
| `LANGFLOW_SSRF_PROTECTION_ENABLED` | Boolean | `False` | Enable SSRF protection for the **API Request** component. When enabled, the component blocks requests to private IP addresses. When disabled, requests are not blocked. |
| `LANGFLOW_SSRF_PROTECTION_ENABLED` | Boolean | `True` | Enable SSRF protection for the **API Request** component. When enabled, the component blocks requests to private IP addresses. When disabled, requests are not blocked. |
| `LANGFLOW_SSRF_ALLOWED_HOSTS` | List[String] | Not set | A comma-separated list of allowed hosts, IP addresses, or CIDR ranges that can bypass SSRF protection checks. For example: `192.168.1.0/24,10.0.0.5,*.internal.company.local`.|
| `LANGFLOW_CONNECTOR_SSRF_VALIDATION_ENABLED` | Boolean | `True` | Apply SSRF host validation to connector components that take a tenant-controlled host or URL — vector stores (Chroma, Qdrant, Elasticsearch, OpenSearch, Milvus, Weaviate, Supabase, Upstash, ClickHouse), the SQL Database components, the Glean and AstraDB-CQL tools, model-provider model discovery (LiteLLM, HuggingFace, xAI, DeepSeek, Groq, watsonx), and the Ollama / LM Studio / Home Assistant base-URL fields. It defers to `LANGFLOW_SSRF_PROTECTION_ENABLED` and `LANGFLOW_SSRF_ALLOWED_HOSTS` for the host policy. Set to `false`, or allowlist specific hosts, only when a trusted single-tenant deployment intentionally connects to `localhost` or private-network services. |

:::note Multi-tenant recommendation
In a multi-tenant deployment where mutually-untrusted users build flows, keep `LANGFLOW_CONNECTOR_SSRF_VALIDATION_ENABLED=true` and `LANGFLOW_SSRF_PROTECTION_ENABLED=true` so a tenant cannot point a vector store, SQL database, model-provider proxy, Ollama/LM Studio/Home Assistant URL, or Glean/AstraDB tool at an internal service or the cloud-metadata endpoint. Allowlist your own internal hosts with `LANGFLOW_SSRF_ALLOWED_HOSTS`.
:::

### Multi-tenant component hardening {#multi-tenant-component-hardening}

The following environment variables close code-execution and local-file-read surfaces that remain reachable through *built-in* components even when user-authored custom components are disabled.
They are disabled by default to preserve single-tenant behavior, and are meant to be set together with [`LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false`](/deployment-block-custom-components) in deployments where mutually-untrusted users build flows.

| Variable | Format | Default | Description |
|----------|--------|---------|-------------|
| `LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS` | Boolean | `False` | When `true`, blocks execution of any flow containing a built-in arbitrary-code-execution component (Python Interpreter, Python REPL/Code tools, the Smart Transform / lambda evaluator, and the code-running agents). These components are official, so their class-code hash is valid and they pass the `LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false` policy — yet they execute arbitrary Python supplied through their input fields, which is equivalent to letting users author custom code. |
| `LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS` | Boolean | `False` | When `true`, built-in file-reading components (File, Directory, JSON/CSV-to-Data, and the CSV/JSON/OpenAPI agents) may only read paths that resolve *inside* the storage data directory where uploaded files live, and `save_file` writes are confined there too. With the default (`false`) a tenant can set a component's path field to an absolute server path (`/etc/passwd`, the SQLite DB, secrets), a traversal string, or a symlink and read arbitrary server files — or another tenant's uploads. This setting also blocks local-file database dialects (`sqlite`, `duckdb`) in the SQL Database components and local-filesystem Git clones. |

:::note Multi-tenant recommendation
For a deployment where mutually-untrusted users build flows, set `LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false`, `LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true`, and `LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true` together. The first blocks user-authored component code; the second blocks the built-in code-execution components that would otherwise be an equivalent escape hatch; the third confines built-in file access to the upload sandbox. Pair these with the SSRF settings above.
:::

:::warning Tracing in multi-tenant deployments
External tracing integrations (LangSmith, Langfuse, Phoenix, Arize, Opik, and similar) are configured **process-wide** from environment variables, not per user. When you enable one in a multi-tenant deployment, **every tenant's** flow inputs, outputs, and prompts are sent to that single external project, where anyone with access to the tracing account can read them — and a tenant's secret echoed into a component output may not be redacted. Do not enable a shared SaaS tracing backend in a deployment with mutually-untrusted tenants; rely on the built-in local tracing instead.
:::

### Session cookie hardening {#session-cookie-hardening}

For a multi-tenant deployment served over HTTPS, harden the access-token cookie. These default to permissive values for local/HTTP development and for the current frontend, which reads the access token in JavaScript.

| Variable | Format | Default | Description |
|----------|--------|---------|-------------|
| `LANGFLOW_ACCESS_SECURE` | Boolean | `False` | When `true`, the `access_token_lf` cookie is sent only over HTTPS. Recommended `true` for any HTTPS deployment. Leave `false` for plain-HTTP/localhost development, where a `Secure` cookie would not be sent. |
| `LANGFLOW_ACCESS_HTTPONLY` | Boolean | `False` | When `true`, the `access_token_lf` cookie is not readable by JavaScript (mitigates token theft via XSS). The default is `false` because the bundled frontend currently reads this cookie in JavaScript; enabling `HttpOnly` requires a frontend that does not read the token directly. |
| `LANGFLOW_ACCESS_SAME_SITE` | String | `lax` | The `SameSite` attribute of the access-token cookie (`lax`, `strict`, or `none`). |

The refresh-token cookie is already `HttpOnly` + `Secure` + `SameSite` by default.

### Login rate limiting {#login-rate-limiting}

Expand Down
23 changes: 23 additions & 0 deletions src/backend/base/langflow/agentic/api/deps.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
"""Shared dependencies for the agentic API.

Kept in a leaf module (only fastapi + lfx settings) so both the route definitions
(langflow.agentic.api.router) and the router-include site (langflow.api.router) can import it
without a circular import.
"""

from fastapi import HTTPException, status
from lfx.services.deps import get_settings_service


def require_agentic_experience() -> None:
"""Backend gate for the agentic assistant's code-generating/executing endpoints.

SECURITY: the assistant generates and EXECUTES component code in-process
(langflow.agentic.helpers.validation.validate_component_runtime and the user-components
overlay). ``agentic_experience`` was only a frontend/UX + MCP-provisioning flag, so the codegen
endpoints were live by default. Gate them here (404 when off), matching the per-endpoint
precedent in api/v1/endpoints.py. The read-only ``/agentic/check-config`` probe is intentionally
NOT gated so non-agentic deployments can still query provider configuration.
"""
if not get_settings_service().settings.agentic_experience:
raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="This endpoint is not available")
9 changes: 5 additions & 4 deletions src/backend/base/langflow/agentic/api/router.py
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
from dataclasses import dataclass
from uuid import UUID

from fastapi import APIRouter, HTTPException, Request
from fastapi import APIRouter, Depends, HTTPException, Request
from fastapi.responses import StreamingResponse
from lfx.base.models.unified_models import (
get_all_variables_for_provider,
Expand All @@ -19,6 +19,7 @@
from lfx.log.logger import logger
from sqlalchemy.ext.asyncio import AsyncSession

from langflow.agentic.api.deps import require_agentic_experience
from langflow.agentic.api.schemas import AssistantRequest
from langflow.agentic.services.assistant_service import (
execute_flow_with_validation,
Expand Down Expand Up @@ -154,7 +155,7 @@ async def _validate_flow_access(flow_id: str | None, user_id: UUID, session: Asy
raise HTTPException(status_code=404, detail="Flow not found.")


@router.post("/execute/{flow_name}")
@router.post("/execute/{flow_name}", dependencies=[Depends(require_agentic_experience)])
async def execute_named_flow(
flow_name: str,
request: AssistantRequest,
Expand Down Expand Up @@ -276,7 +277,7 @@ async def check_assistant_config(
}


@router.post("/assist")
@router.post("/assist", dependencies=[Depends(require_agentic_experience)])
async def assist(
request: AssistantRequest,
current_user: CurrentActiveUser,
Expand All @@ -301,7 +302,7 @@ async def assist(
)


@router.post("/assist/stream")
@router.post("/assist/stream", dependencies=[Depends(require_agentic_experience)])
async def assist_stream(
request: AssistantRequest,
http_request: Request,
Expand Down

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions src/backend/base/langflow/agentic/flows/SystemMessageGen.json

Large diffs are not rendered by default.

Large diffs are not rendered by default.

13 changes: 13 additions & 0 deletions src/backend/base/langflow/agentic/helpers/validation.py
Original file line number Diff line number Diff line change
Expand Up @@ -273,7 +273,20 @@ async def validate_component_runtime(code: str, user_id: str | None = None) -> s
reasons. Only pydantic-schema errors — which are almost always LLM-coding
mistakes — are surfaced so the retry loop can recover before the component
is handed to the user.

SECURITY: this "sandbox" only swallows exceptions; it does not constrain what the code can do
(it compiles+execs the module/class body and runs output methods in-process). When the operator
has disabled custom components (``allow_custom_components=false``), we must NOT execute
tenant-influenced generated code — otherwise the assistant becomes a code-execution path that
bypasses the platform-wide policy. Refuse before any instantiation in that case.
"""
from lfx.services.deps import get_settings_service

if not get_settings_service().settings.allow_custom_components:
return (
"Custom component execution is disabled on this server "
"(allow_custom_components=false); generated components cannot be validated or run."
)
try:
from lfx.custom.custom_component.component import Component as ComponentClass
from lfx.custom.utils import build_custom_component_template
Expand Down
Loading
Loading