mirror of
https://github.com/MindWorkAI/AI-Studio.git
synced 2026-10-04 18:29:40 +00:00
Improved data security for chat threads (#317)
This commit is contained in:
1 parent
371731ac13
commit
030990ee90
8 files changed
+154
-3
No files matched your search
@@ -1,6 +1,7 @@
|
||||
using AIStudio.Chat;
|
||||
using AIStudio.Provider;
|
||||
using AIStudio.Settings;
|
||||
using AIStudio.Settings.DataModel;
|
||||
using AIStudio.Tools.RAG.AugmentationProcesses;
|
||||
using AIStudio.Tools.RAG.DataSourceSelectionProcesses;
|
||||
using AIStudio.Tools.Services;
|
||||
@@ -96,6 +97,56 @@ public sealed class AISrcSelWithRetCtxVal : IRagProcess
|
||||
logger.LogWarning("No data sources are selected. The RAG process is skipped.");
|
||||
proceedWithRAG = false;
|
||||
}
|
||||
else
|
||||
{
|
||||
var previousDataSecurity = chatThread.DataSecurity;
|
||||
|
||||
//
|
||||
// Update the data security of the chat thread. We consider the current data security
|
||||
// of the chat thread and the data security of the selected data sources:
|
||||
//
|
||||
var dataSecurityRestrictedToSelfHosted = selectedDataSources.Any(x => x.SecurityPolicy is DataSourceSecurity.SELF_HOSTED);
|
||||
chatThread.DataSecurity = dataSecurityRestrictedToSelfHosted switch
|
||||
{
|
||||
//
|
||||
//
|
||||
// Case: the data sources which are selected have a security policy
|
||||
// of SELF_HOSTED (at least one data source).
|
||||
//
|
||||
// When the policy was already set to ALLOW_ANY, we restrict it
|
||||
// to SELF_HOSTED.
|
||||
//
|
||||
true => DataSourceSecurity.SELF_HOSTED,
|
||||
|
||||
//
|
||||
// Case: the data sources which are selected have a security policy
|
||||
// of ALLOW_ANY (none of the data sources has a SELF_HOSTED policy).
|
||||
//
|
||||
// When the policy was already set to SELF_HOSTED, we must keep that.
|
||||
//
|
||||
false => chatThread.DataSecurity switch
|
||||
{
|
||||
//
|
||||
// When the policy was not specified yet, we set it to ALLOW_ANY.
|
||||
//
|
||||
DataSourceSecurity.NOT_SPECIFIED => DataSourceSecurity.ALLOW_ANY,
|
||||
DataSourceSecurity.ALLOW_ANY => DataSourceSecurity.ALLOW_ANY,
|
||||
|
||||
//
|
||||
// When the policy was already set to SELF_HOSTED, we must keep that.
|
||||
// This is important since the thread might already contain data
|
||||
// from a data source with a SELF_HOSTED policy.
|
||||
//
|
||||
DataSourceSecurity.SELF_HOSTED => DataSourceSecurity.SELF_HOSTED,
|
||||
|
||||
// Default case: we use the current data security of the chat thread.
|
||||
_ => chatThread.DataSecurity,
|
||||
}
|
||||
};
|
||||
|
||||
if (previousDataSecurity != chatThread.DataSecurity)
|
||||
logger.LogInformation($"The data security of the chat thread was updated from '{previousDataSecurity}' to '{chatThread.DataSecurity}'.");
|
||||
}
|
||||
|
||||
//
|
||||
// Trigger the retrieval part of the (R)AG process:
|
||||
|
||||
Reference in new issue
Block a user