Harden Confluence search and return its sources and let trusted providers continue chats that hold confidential tool results

This commit is contained in:
Peer Hogeterp committed 2026-09-23 11:15:43 +02:00
1 parent 7d293c78c7
commit 5c867a9b23
10 files changed
+94 -19

No files matched your search

@@ -37,13 +37,20 @@ public static class ChatThreadExtensions
};
//
// The confidence axis is checked on its own: a provider trusted by configuration counts as
// self-hosted for data-source security, which is the check further down, but that trust
// says nothing about how confidential the provider is. An organization which wants its
// contractually covered cloud provider to pass here raises its level through the custom
// confidence scheme instead.
// A provider trusted by the organization's configuration may continue the thread whatever
// confidence it requires, the same as the tools which put that data into the thread treat
// it as equal to a High-confidence provider. Otherwise such a provider could run a tool
// and then be locked out of its own chat by the result.
//
if (providerConfidence < chatThread.RequiredProviderConfidence)
var isTrustedByConfiguration = provider switch
{
IProvider p => p.IsTrustedByConfiguration(settingsManager),
AIStudio.Settings.Provider p => p.IsTrustedByConfiguration(settingsManager),
_ => false,
};
if (providerConfidence < chatThread.RequiredProviderConfidence && !isTrustedByConfiguration)
return false;
// The chat thread is available, but the data security is not specified.