Skip to content

Commit 23dc7bc

Browse files
fix(web): auth gate Ask APIs for Public SaaS (#1679)
* fix(web): require auth for public SaaS Ask APIs Co-authored-by: Michael Sukkarieh <msukkari@users.noreply.github.com> * docs: add Ask API auth changelog entry Co-authored-by: Michael Sukkarieh <msukkari@users.noreply.github.com> * refactor(web): generalize auth override helper Co-authored-by: Michael Sukkarieh <msukkari@users.noreply.github.com> * refactor(web): make auth override a boolean gate Co-authored-by: Michael Sukkarieh <msukkari@users.noreply.github.com> * refactor(web): inline Ask auth override checks Co-authored-by: Michael Sukkarieh <msukkari@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Michael Sukkarieh <msukkari@users.noreply.github.com>
1 parent d12a32e commit 23dc7bc

3 files changed

Lines changed: 11 additions & 2 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
1212

1313
### Fixed
1414
- Removed suggested example queries from the Ask landing page. [#1674](https://github.com/sourcebot-dev/sourcebot/pull/1674)
15+
- Require authentication for the streaming and blocking Ask APIs in Public SaaS deployments. [#1679](https://github.com/sourcebot-dev/sourcebot/pull/1679)
1516

1617
## [5.1.14] - 2026-09-17
1718

‎packages/web/src/app/api/(server)/ee/chat/route.ts‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ import { getAskSkillAvailabilityAnalytics, getAskSkillTurnCompletedAnalytics } f
1515
import { apiHandler } from "@/lib/apiHandler";
1616
import { ErrorCode } from "@/lib/errorCodes";
1717
import { captureEvent } from "@/lib/posthog";
18-
import { notFound, requestBodySchemaValidationError, ServiceError, serviceErrorResponse } from "@/lib/serviceError";
18+
import { notAuthenticated, notFound, requestBodySchemaValidationError, ServiceError, serviceErrorResponse } from "@/lib/serviceError";
1919
import { isServiceError } from "@/lib/utils";
2020
import { withOptionalAuth } from "@/middleware/withAuth";
2121
import * as Sentry from "@sentry/nextjs";
@@ -50,6 +50,10 @@ export const POST = apiHandler(async (req: NextRequest) => {
5050

5151
const response = await sew(() =>
5252
withOptionalAuth(async ({ org, user, prisma }) => {
53+
if (env.EXPERIMENT_ASK_GH_ENABLED === 'true' && !user) {
54+
return notAuthenticated();
55+
}
56+
5357
// Gate the generative path behind the `ask` entitlement. The client
5458
// also gates this, but server-side enforcement can't be bypassed.
5559
const askError = await checkAskEntitlement();

‎packages/web/src/ee/features/mcp/askCodebase.ts‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ import { LanguageModelInfo, SBChatMessage, SearchScope } from "@/features/chat/t
77
import { convertLLMOutputToPortableMarkdown, getAnswerPartFromAssistantMessage, getLanguageModelKey } from "@/features/chat/utils";
88
import { resolveModelCapabilities } from "@/features/chat/modelCapabilities.server";
99
import { ErrorCode } from "@/lib/errorCodes";
10-
import { ServiceError, ServiceErrorException } from "@/lib/serviceError";
10+
import { notAuthenticated, ServiceError, ServiceErrorException } from "@/lib/serviceError";
1111
import { withOptionalAuth } from "@/middleware/withAuth";
1212
import { ChatVisibility, Prisma } from "@sourcebot/db";
1313
import { createLogger, env } from "@sourcebot/shared";
@@ -49,6 +49,10 @@ const blockStreamUntilFinish = async <T extends UIMessage<unknown, UIDataTypes,
4949
export const askCodebase = (params: AskCodebaseParams): Promise<AskCodebaseResult | ServiceError> =>
5050
sew(() =>
5151
withOptionalAuth(async ({ org, user, prisma }) => {
52+
if (env.EXPERIMENT_ASK_GH_ENABLED === 'true' && !user) {
53+
return notAuthenticated();
54+
}
55+
5256
// Ask Sourcebot is a paid feature. askCodebase() is the single choke point
5357
// for the programmatic ask path (the MCP `ask_codebase` tool and the
5458
// /api/chat/blocking route both wrap it), so gating here covers both without

0 commit comments

Comments
 (0)