diff --git a/content/docs/configuration/authentication/OAuth2-OIDC/azure.mdx b/content/docs/configuration/authentication/OAuth2-OIDC/azure.mdx index 901861fb0..dff50398e 100644 --- a/content/docs/configuration/authentication/OAuth2-OIDC/azure.mdx +++ b/content/docs/configuration/authentication/OAuth2-OIDC/azure.mdx @@ -184,7 +184,7 @@ SHAREPOINT_PICKER_GRAPH_SCOPE=Files.Read.All ### Usage When properly configured: -1. Users will see "From SharePoint" option in the file attachment menu +1. Users will see a **From SharePoint** option in the **Attach** section of the [composer's **+** palette](/docs/features/composer#add-files) 2. Clicking it opens the native SharePoint file picker 3. Users can browse and select files from any SharePoint site or OneDrive they have access to 4. Selected files are downloaded and attached to the conversation diff --git a/content/docs/configuration/authentication/email.mdx b/content/docs/configuration/authentication/email.mdx index 27e5eb49e..b1ae82ce9 100644 --- a/content/docs/configuration/authentication/email.mdx +++ b/content/docs/configuration/authentication/email.mdx @@ -203,6 +203,52 @@ EMAIL_FROM_NAME=LibreChat ALLOW_PASSWORD_RESET=true ``` +## Email Address Change + + + Newer than **v0.8.8**. Available now on LibreChat's `dev` and `canary` branches, and in the next release. + + +Users with a local (email and password) account can change their registered email address themselves from **Settings > Account**. The feature is on by default and needs working email delivery (Mailgun or SMTP, configured above): without it, the option is hidden. + +### User flow + +1. In **Settings > Account**, next to **Email address**, the user selects **Change**. +2. In the **Change email address** dialog, they enter the **New email address** and their **Current password**, then select **Send verification link**. +3. LibreChat first sends a security notice ("Email change requested") to the current address, with the requested address and the request IP. It sends this before checking the password, so the account owner hears about every attempt, including rejected ones. If the request passes the checks below, a verification link goes to the new address. +4. The address changes only when the link is opened. Both the old and new addresses then receive a "Your email address was changed" notice, and the new address is marked as verified. + +The request is rejected when the password is wrong, the new address equals the current one, the new address already belongs to another account, or its domain is not in [`registration.allowedDomains`](/docs/configuration/librechat_yaml/object_structure/registration#alloweddomains). Accounts that sign in through OAuth, OpenID Connect, SAML, or LDAP cannot use this flow. + +The verification link is single-use and expires after `tokenTTLSeconds` (15 minutes by default). It also stops working if the password or email of the account changes before it is opened. Completing a change invalidates any password reset links issued for the previous address. + +### Configuration + + + +In `librechat.yaml`, the `emailChange` block takes precedence over `ALLOW_EMAIL_CHANGE` and also sets the link lifetime: + +```yaml filename="librechat.yaml" +emailChange: + enabled: true + tokenTTLSeconds: 900 # 60 to 86400, default 900 (15 minutes) +``` + +Each field falls back independently: `enabled` to `ALLOW_EMAIL_CHANGE` and then `true`; `tokenTTLSeconds` to `900`. Rate limits for requesting a change and for opening links are set under [`rateLimits.emailChange` and `rateLimits.emailChangeConfirm`](/docs/configuration/librechat_yaml/object_structure/config#ratelimits), or with the matching [environment variables](/docs/configuration/dotenv#email-change-rate-limiting). + + +Set `ALLOW_EMAIL_CHANGE=false` (or `emailChange.enabled: false`) until every node runs a version that includes this feature. Older nodes issue and accept password reset links that are not bound to an address, so a link held by the previous owner of an address could outlive the change and reset the renamed account. + + ## Troubleshooting ### Mailgun Issues diff --git a/content/docs/configuration/authentication/index.mdx b/content/docs/configuration/authentication/index.mdx index 86e92576f..b9dae82aa 100644 --- a/content/docs/configuration/authentication/index.mdx +++ b/content/docs/configuration/authentication/index.mdx @@ -60,6 +60,68 @@ Quick Tips: alt="User registration screen" /> +Related sign-in options for local accounts: + +- [Passkeys](/docs/configuration/authentication/passkeys): passwordless sign-in with a device screen lock or security key (`ALLOW_PASSKEY_LOGIN`). +- [Email address change](/docs/configuration/authentication/email#email-address-change): lets users change their registered email from **Settings > Account** (`ALLOW_EMAIL_CHANGE`, on by default). + +## Required Two-Factor Authentication + + + Newer than **v0.8.8**. Available now on LibreChat's `dev` and `canary` branches, and in the next release. + + +Users can always turn on two-factor authentication (TOTP) themselves from **Settings > Account**. To make it mandatory, set: + +```bash filename=".env" +ENFORCE_TWO_FACTOR_AUTHENTICATION=true +``` + +**Who it applies to:** local (email and password) and LDAP accounts. Accounts that sign in through OAuth, OpenID Connect, or SAML are not affected, because their identity provider is responsible for MFA. A federated account that tries to sign in with a password while enforcement is on is told to use its identity provider instead. + +**What users see:** a user without 2FA who signs in (with a password, LDAP credentials, or a passkey) gets no session until setup is complete. They land on a **Two-Factor Authentication Required** screen ("Your administrator requires two-factor authentication. Set it up before continuing."), scan a QR code with an authenticator app, enter a code to verify, and save their backup codes. Users who are already signed in are moved into the same setup the next time their session is checked or refreshed, and access tokens issued before enrollment stop working. The setup session lasts 10 minutes; if it expires, the user returns to the login page and starts again. + +**After enrollment:** the **Disable 2FA** control in **Settings > Account** shows **Required by administrator**, and the server rejects attempts to disable 2FA while the policy is on. Users can still regenerate backup codes. + + + + +`ENFORCE_TWO_FACTOR_AUTHENTICATION` and the `TWO_FACTOR_TEMP_*` and `TWO_FACTOR_SETUP_*` limits are process-wide `.env` settings. They apply before a request or tenant configuration is available, so they cannot be set in `librechat.yaml` or per tenant. Set the same values on every replica. The separate budget for managing 2FA from settings is [`rateLimits.twoFactorManagement`](/docs/configuration/librechat_yaml/object_structure/config#ratelimits). + + ## Session Expiry and Refresh Token - Default values: session expiry: 15 minutes, refresh token expiry: 7 days diff --git a/content/docs/configuration/authentication/meta.json b/content/docs/configuration/authentication/meta.json index caf654b81..b8fdeaf7f 100644 --- a/content/docs/configuration/authentication/meta.json +++ b/content/docs/configuration/authentication/meta.json @@ -1,5 +1,5 @@ { "title": "Authentication", "icon": "Lock", - "pages": ["email", "ldap", "OAuth2-OIDC", "SAML"] + "pages": ["email", "passkeys", "ldap", "OAuth2-OIDC", "SAML"] } diff --git a/content/docs/configuration/authentication/passkeys.mdx b/content/docs/configuration/authentication/passkeys.mdx new file mode 100644 index 000000000..787e42d25 --- /dev/null +++ b/content/docs/configuration/authentication/passkeys.mdx @@ -0,0 +1,142 @@ +--- +title: Passkeys +icon: KeyRound +description: Let users sign in without a password using a device screen lock or a security key (WebAuthn). Covers enabling passkeys, the relying party settings, enrollment limits, and how passkeys interact with two-factor authentication. +--- + +Passkeys let users with a local (email and password) account sign in with their device screen lock, a password manager, or a hardware security key instead of typing a password. LibreChat implements them with WebAuthn. They are off by default. + + + Newer than **v0.8.8**. Available now on LibreChat's `dev` and `canary` branches, and in the next release. + + +Use passkeys when you want a phishing-resistant, passwordless sign-in for local accounts. Accounts that sign in through OAuth, OpenID Connect, SAML, or LDAP keep using their provider and cannot add passkeys. + +## Enable passkeys + + + + +**Serve LibreChat over HTTPS.** Browsers only allow WebAuthn in a secure context. `http://localhost` is exempt, so local testing works without TLS. + + + + +**Turn the feature on in `.env`.** For a standard deployment, this is the only required setting. The relying party ID and allowed origins are derived from `DOMAIN_CLIENT` and `DOMAIN_SERVER`. + +```bash filename=".env" +ALLOW_PASSKEY_LOGIN=true +``` + + + + +**Pin the relying party ID (recommended).** Each passkey is permanently bound to the RP ID it was created under. If `DOMAIN_CLIENT` might ever change, set `PASSKEY_RP_ID` now so existing passkeys keep working. + +```bash filename=".env" +PASSKEY_RP_ID=chat.example.com +``` + + + + +**Restart LibreChat.** The login page shows **Sign in with a passkey**, and **Settings > Account** shows a **Passkeys** section. + + + + +## Configuration reference + + + +### Per-user limit in `librechat.yaml` + +You can also set the enrollment cap in `librechat.yaml`: + +```yaml filename="librechat.yaml" +passkeys: + perUserMax: 10 +``` + +The cap resolves in this order: `passkeys.perUserMax` in `librechat.yaml`, then `MAX_PASSKEYS_PER_USER`, then the default of `20`. Values outside `1` to `100` are ignored and the next source is used. When a user reaches the cap, **Settings > Account** shows "You have reached the maximum number of passkeys". See [`passkeys`](/docs/configuration/librechat_yaml/object_structure/config#passkeys) in the config reference. + +## What users see + +**Adding a passkey** + +1. Open **Settings > Account**, find **Passkeys**, and select **Manage**. +2. Select **Add passkey**. +3. Enter the account password in the **Confirm your password** dialog. A passkey is a complete sign-in on its own, so LibreChat asks for the password before creating one. +4. Complete the browser or device prompt. The new passkey appears in the list with a default name such as **This device**, **Phone or tablet**, or **Security key**. + +Each entry shows when it was added and last used, and a **Synced** badge when the authenticator reports that the passkey is backed up (for example, by a password manager). Users can rename a passkey, and removing one (**Remove passkey**) also asks for the account password. + +**Signing in** + +On the login page, users select **Sign in with a passkey** and approve the device prompt. If the account has two-factor authentication enabled, LibreChat still asks for the 2FA code afterward, exactly as it does after a password sign-in. + +## Behavior and caveats + +- **Local accounts only.** Passkey enrollment and sign-in are limited to local accounts. Accounts created through an identity provider or LDAP must keep authenticating through that provider. +- **Works with email login disabled.** The **Sign in with a passkey** button and its routes depend only on `ALLOW_PASSKEY_LOGIN`. With `ALLOW_EMAIL_LOGIN=false`, existing local users can still sign in with passkeys they enrolled earlier. +- **Two-factor authentication.** Passkey sign-in goes through the same 2FA gate as password sign-in. With [`ENFORCE_TWO_FACTOR_AUTHENTICATION=true`](/docs/configuration/authentication#required-two-factor-authentication), a user who has not enrolled in 2FA is sent to the setup flow after signing in with a passkey. +- **Changing the RP ID orphans passkeys.** Passkeys created under one RP ID never work under another. Changing `PASSKEY_RP_ID`, or changing `DOMAIN_CLIENT` while `PASSKEY_RP_ID` is unset, leaves every existing passkey unusable; users must sign in another way and enroll again. +- **Origins must match.** If users reach LibreChat on an origin not covered by `PASSKEY_ORIGINS` (or the derived defaults), the browser shows "Passkeys are not available on this domain". Add every public origin to `PASSKEY_ORIGINS` when you serve LibreChat on more than one. +- **Password reset removes passkeys.** A completed password reset signs the account out everywhere and deletes all of its passkeys, so a passkey enrolled before the reset can no longer be used to get in. Users enroll again afterward. diff --git a/content/docs/configuration/dotenv.mdx b/content/docs/configuration/dotenv.mdx index 5c15db06b..cd3c3feec 100644 --- a/content/docs/configuration/dotenv.mdx +++ b/content/docs/configuration/dotenv.mdx @@ -1954,6 +1954,70 @@ Prevents brute force attacks and spam registrations by limiting login attempts a The login-attempt budget is shared by the local login API and top-level social or federated OAuth navigations from the same IP. A rejected API login receives the existing JSON `429` response. A rate-limited or banned `/oauth/*` browser navigation returns to `/login?redirect=false` with a localized error code instead of rendering a JSON document; `redirect=false` prevents an automatic OpenID redirect from immediately entering the limiter again. +#### Two-factor authentication rate limiting + + + +These are process-wide settings that apply before request or tenant configuration is available. See [Required Two-Factor Authentication](/docs/configuration/authentication#required-two-factor-authentication). + +#### Passkey rate limiting + + + #### Password reset and email verification rate limiting LibreChat applies separate IP-based limits to requesting an email and submitting the token from that email. This prevents repeated token guesses without forcing deployments to use the same limit for email delivery and token validation. @@ -2011,6 +2075,53 @@ LibreChat applies separate IP-based limits to requesting an email and submitting ]} /> +#### Email change rate limiting + +Limits [email address change](/docs/configuration/authentication/email#email-address-change) requests per signed-in user, and verification link openings per IP and per account. + +> Note: These can also be configured via `librechat.yaml` in the `rateLimits.emailChange` and `rateLimits.emailChangeConfirm` sections. A value set in `librechat.yaml` takes precedence over the environment variable. + + + #### Score for each violation Note: These can also be configured via `librechat.yaml` in the `rateLimits.conversationsImport` section. A value set in `librechat.yaml` takes precedence over the environment variable. + > Note: You can utilize both limiters, but default is to limit by IP only. ##### IP Limiter: @@ -2329,7 +2460,7 @@ Limits how often users can fork conversations to prevent abuse. Limits how often users can upload files to prevent abuse. -> Note: These can also be configured via `librechat.yaml` in the `rateLimits.fileUploads` section. +> Note: These can also be configured via `librechat.yaml` in the `rateLimits.fileUploads` section. A value set in `librechat.yaml` takes precedence over the environment variable. ##### IP Limiter: @@ -2373,7 +2504,7 @@ Limits how often users can upload files to prevent abuse. Limits how often users can use Text-to-Speech to prevent abuse. -> Note: These can also be configured via `librechat.yaml` in the `rateLimits.tts` section. +> Note: These can also be configured via `librechat.yaml` in the `rateLimits.tts` section. A value set in `librechat.yaml` takes precedence over the environment variable. ##### IP Limiter: @@ -2417,7 +2548,7 @@ Limits how often users can use Text-to-Speech to prevent abuse. Limits how often users can use Speech-to-Text to prevent abuse. -> Note: These can also be configured via `librechat.yaml` in the `rateLimits.stt` section. +> Note: These can also be configured via `librechat.yaml` in the `rateLimits.stt` section. A value set in `librechat.yaml` takes precedence over the environment variable. ##### IP Limiter: @@ -2503,7 +2634,9 @@ see: **[Authentication System](/docs/configuration/authentication)** All authentication settings in this section should be configured in your `.env` file, not in the `librechat.yaml` file or `docker-compose.override.yml`. The `docker-compose.override.yml` file is only used to mount volumes and set environment variables for Docker, while the `librechat.yaml` - file is used for custom endpoints and other application settings. + file is used for custom endpoints and other application settings. The exceptions are + `ALLOW_EMAIL_CHANGE` and `MAX_PASSKEYS_PER_USER`, which `emailChange` and `passkeys` in + `librechat.yaml` override when set. - General Settings: @@ -2558,6 +2691,18 @@ see: **[Authentication System](/docs/configuration/authentication)** 'Set to true to allow users to log in without verifying their email address. If set to false, users will be required to verify their email before logging in.', 'ALLOW_UNVERIFIED_EMAIL_LOGIN=true', ], + [ + 'ALLOW_EMAIL_CHANGE', + 'boolean', + 'Allow local-account users to change their email address from Settings > Account. Requires email delivery. Enabled by default if omitted. emailChange.enabled in librechat.yaml takes precedence. Keep it false during multi-node rollouts until every node supports it.', + '# ALLOW_EMAIL_CHANGE=true', + ], + [ + 'ENFORCE_TWO_FACTOR_AUTHENTICATION', + 'boolean', + 'Require local and LDAP accounts to enroll in 2FA before a full session is issued. Federated identity providers keep their own MFA policies.', + 'ENFORCE_TWO_FACTOR_AUTHENTICATION=false', + ], [ 'MIN_PASSWORD_LENGTH', 'number', @@ -2567,6 +2712,8 @@ see: **[Authentication System](/docs/configuration/authentication)** ]} /> +See [Email Address Change](/docs/configuration/authentication/email#email-address-change) for `ALLOW_EMAIL_CHANGE` and [Required Two-Factor Authentication](/docs/configuration/authentication#required-two-factor-authentication) for `ENFORCE_TWO_FACTOR_AUTHENTICATION`. + > **Quick Tip:** Even with registration disabled, add users directly to the database using `npm run create-user`. > **Quick Tip:** With registration disabled, you can delete a user with `npm run delete-user email@domain.com`. @@ -2597,6 +2744,45 @@ see: **[Authentication System](/docs/configuration/authentication)** - For more information: **[Refresh Token](https://github.com/LibreChat-AI/LibreChat/pull/927)** +- Passkey Settings: + +Passkey (WebAuthn) sign-in for local accounts. Requires HTTPS in production; `localhost` is exempt. See [Passkeys](/docs/configuration/authentication/passkeys). + + Account. +# Omitted, these fall back to ALLOW_EMAIL_CHANGE and a 15-minute link. +# emailChange: +# enabled: true +# tokenTTLSeconds: 900 + +# Passkey (WebAuthn) enrollment limits. +# Omitted, perUserMax falls back to MAX_PASSKEYS_PER_USER, then 20. +# passkeys: +# perUserMax: 20 + # Example Registration Object Structure (optional) registration: socialLogins: ['github', 'google', 'discord', 'openid', 'facebook'] @@ -488,6 +499,17 @@ registration: # ipWindowInMinutes: 60 # Rate limit window for conversation imports per IP # userMax: 50 # userWindowInMinutes: 60 # Rate limit window for conversation imports per user +# # Asking for a change of the registered email, per authenticated user. +# emailChange: +# userMax: 3 +# userWindowInMinutes: 2 +# # Opening a verification link. The endpoint is unauthenticated, so the source +# # address is bounded as well as the account the link names. +# emailChangeConfirm: +# ipMax: 20 +# ipWindowInMinutes: 2 +# userMax: 2 +# userWindowInMinutes: 2 # Source-aware content filters are disabled when omitted. `filters` is loaded # only from the base config; role, group, and user overrides cannot change it. diff --git a/content/docs/configuration/librechat_yaml/object_structure/config.mdx b/content/docs/configuration/librechat_yaml/object_structure/config.mdx index 59bb125dc..876a7289f 100644 --- a/content/docs/configuration/librechat_yaml/object_structure/config.mdx +++ b/content/docs/configuration/librechat_yaml/object_structure/config.mdx @@ -28,6 +28,57 @@ icon: Settings ]} /> +## projects + +_Newer than v0.8.8._ + +**Key:** + + + +**Subkeys:** + + + +See [Projects](/docs/features/projects). Unknown keys inside `projects` fail validation. + +```yaml filename="projects" +projects: + maxFiles: 50 + maxInstructionsLength: 16000 + maxDescriptionLength: 1000 +``` + ## permissions Controls retry behavior for concurrent access-control-list writes. @@ -151,6 +202,23 @@ See: [Content Filter Object Structure](/docs/configuration/librechat_yaml/object See: [Legacy messageFilter](/docs/configuration/librechat_yaml/object_structure/message_filter#legacy-messagefilter) +## fileListLimit + +_Newer than v0.8.8._ + + + +Requests without a `limit` are not affected. The composer's recent files list ([`interface.composerRecentFiles`](/docs/configuration/librechat_yaml/object_structure/interface)) is capped at 100, this setting's default, so the palette never asks for more rows than a default deployment returns. + ## fileStrategy - **Options**: "local" | "firebase" | "s3" | "azure_blob" | "cloudfront" @@ -399,6 +467,50 @@ Set `secureImageLinks: false` only as a compatibility opt-out for deployments th ]} /> +## conversationList + +_Newer than v0.8.8._ + +**Key:** + + + +**Subkeys:** + + + +See [Navigation](/docs/features/navigation) for the conversation list filters. Values outside these ranges fail config validation like any other invalid key. An invalid value set through an Admin Panel override is ignored with a warning, and the defaults apply. + +```yaml filename="conversationList" +conversationList: + maxEndpointFilters: 50 + maxEndpointNameLength: 128 +``` + ## ocr **Key:** @@ -742,9 +854,29 @@ see: [File Config Object Structure](/docs/configuration/librechat_yaml/object_st ], ['stt', 'Object', 'Configures rate limits specifically for speech-to-text (stt) requests', ''], ['tts', 'Object', 'Configures rate limits specifically for text-to-speech (tts) requests', ''], + [ + 'mcpApps', + 'Object', + 'Per-user limits for MCP App browser routes, in a fixed one-minute window.', + '', + ], + [ + 'emailChange', + 'Object', + 'Limits requests to change the registered email address, per signed-in user.', + '', + ], + [ + 'emailChangeConfirm', + 'Object', + 'Limits openings of email change verification links, per IP and per account.', + '', + ], ]} /> +**Precedence:** at startup, LibreChat writes each value set under `fileUploads`, `conversationsImport`, `tts`, `stt`, `agentEvents`, `emailChange`, and `emailChangeConfirm` into the matching environment variable (prefixes `FILE_UPLOAD`, `IMPORT`, `TTS`, `STT`, `AGENT_EVENT`, `EMAIL_CHANGE`, and `EMAIL_CHANGE_CONFIRM`, with suffixes `_IP_MAX`, `_IP_WINDOW`, `_USER_MAX`, and `_USER_WINDOW`). A YAML value therefore overrides the environment variable, and a key you leave out keeps the environment value or the built-in default. `twoFactorManagement` and `mcpApps` have no environment equivalents. + **twoFactorManagement Subkeys:** +**mcpApps Subkeys:** + + + +**emailChange Subkeys:** + + + +**emailChangeConfirm Subkeys:** + + + +The confirmation endpoint is unauthenticated, so it is bounded by source address as well as by the account the link names. See [Email Address Change](/docs/configuration/authentication/email#email-address-change). + - **Example**: ```yaml filename="rateLimits" rateLimits: @@ -881,6 +1064,17 @@ This admission bucket is separate from normal message execution limits. The dura ipWindowInMinutes: 1 userMax: 50 userWindowInMinutes: 1 + mcpApps: + resourcesPerMinute: 120 + toolCallsPerMinute: 60 + emailChange: + userMax: 3 + userWindowInMinutes: 2 + emailChangeConfirm: + ipMax: 20 + ipWindowInMinutes: 2 + userMax: 2 + userWindowInMinutes: 2 ``` ## registration @@ -908,6 +1102,82 @@ see also: - [alloweddomains](/docs/configuration/librechat_yaml/object_structure/registration#alloweddomains), - [Registration Object Structure](/docs/configuration/librechat_yaml/object_structure/registration) +## emailChange + +_Newer than v0.8.8._ + +**Key:** + + Account, and how long verification links last.', + '', + ], + ]} +/> + +**Subkeys:** + + + +Each field set here takes precedence over its environment fallback. Email delivery must be configured for the option to appear. See [Email Address Change](/docs/configuration/authentication/email#email-address-change). + +```yaml filename="emailChange" +emailChange: + enabled: true + tokenTTLSeconds: 900 +``` + +## passkeys + +_Newer than v0.8.8._ + +**Key:** + + + +**Subkeys:** + + + +Passkeys themselves are enabled with `ALLOW_PASSKEY_LOGIN` in `.env`. See [Passkeys](/docs/configuration/authentication/passkeys). + +```yaml filename="passkeys" +passkeys: + perUserMax: 20 +``` + ## memory **Key:** @@ -1149,11 +1419,11 @@ see also: 'Enables or disables the "Run Code" button for Markdown Code Blocks', '', ], - ['webSearch', 'Boolean', 'Enables or disables the web search button in the chat interface', ''], + ['webSearch', 'Boolean', 'Enables or disables the Web Search tool in the composer palette', ''], [ 'fileSearch', 'Boolean', - 'Enables or disables the file search button in the chat interface', + 'Enables or disables the File Search tool in the composer palette', '', ], ['fileCitations', 'Boolean', 'Globally enables or disables file citations for all users', ''], diff --git a/content/docs/configuration/librechat_yaml/object_structure/interface.mdx b/content/docs/configuration/librechat_yaml/object_structure/interface.mdx index 8cd12438c..8dc0acf36 100644 --- a/content/docs/configuration/librechat_yaml/object_structure/interface.mdx +++ b/content/docs/configuration/librechat_yaml/object_structure/interface.mdx @@ -37,12 +37,18 @@ These are fields under `interface`: - `autoSubmitFromUrl` - `customWelcome` - `codeHighlightThrottleMs` +- `artifactUndocking` - `runCode` - `webSearch` - `fileSearch` - `fileCitations` - `feedback` +- `replyNotifications` - `defaultPinnedTools` +- `composerRecentFiles` +- `steerArmConfirmationTimeoutMs` +- `queuedTurnReconciliationTimeoutMs` +- `queuedSendLockTimeoutMs` - `peoplePicker` - `marketplace` @@ -129,6 +135,7 @@ interface: fireConcurrency: 5 customWelcome: 'Hey {{user.name}}! Welcome to LibreChat' codeHighlightThrottleMs: 300 + artifactUndocking: true runCode: true webSearch: true fileSearch: true @@ -137,7 +144,6 @@ interface: defaultPinnedTools: - artifacts - execute_code - - mcp ``` ## theme @@ -312,6 +318,14 @@ interface: ]} /> +### Where the policy links appear + +On the sign-in and registration screens, published policies appear as a consent sentence: "By continuing, you agree to the Terms of Service and acknowledge the Privacy Policy." If only one policy is published, the sentence names only that one. On the registration screen it sits under the submit button; on the sign-in screen it sits below the sign-in options. + +In chat, the policy links appear under the message box on the welcome screen of a new chat, and are hidden once a conversation starts. + +A policy whose `externalUrl` is empty or blank is treated as not published and is never shown. When `termsOfService.modalAcceptance` is `true`, the auth screens show plain policy links instead of the consent sentence, because users accept the terms explicitly in the dialog after signing in. + ## termsOfService **Key:** @@ -1059,14 +1073,14 @@ Controls whether the temporary chat feature is available to users. Temporary cha 'temporaryChat', 'Boolean', 'Enables or disables the temporary chat feature.', - 'When set to `false`, users will not see the option to start temporary chats.', + 'When set to false, users will not see the option to start temporary chats, unless retentionMode is "ephemeral", which shows the toggle locked on for everyone.', ], ]} /> **Default:** `true` -**Note:** The retention period for temporary chats can be configured using `temporaryChatRetention`. +**Note:** The retention period for temporary chats can be configured using `temporaryChatRetention`. Under `retentionMode: "ephemeral"` the toggle is shown, locked on, to every user regardless of this setting or the `TEMPORARY_CHAT` permission. **Example:** @@ -1077,7 +1091,7 @@ interface: ## temporaryChatRetention -The `temporaryChatRetention` configuration allows you to customize how long temporary chats are retained before being automatically deleted. +The `temporaryChatRetention` configuration allows you to customize how long temporary chats are retained before being automatically deleted. Under `retentionMode: "ephemeral"`, every chat is temporary, so this value is the lifetime of every chat. **Key:** @@ -1123,7 +1137,7 @@ interface: ## generalChatRetention -Controls how long regular chats are retained when `retentionMode` is set to `"all"`. +Controls how long regular chats are retained when `retentionMode` is set to `"all"`. It is ignored by the other modes; under `"ephemeral"` every chat is temporary and uses `temporaryChatRetention`.