SamurAIGPT / Open-Custom-GPT

Create Custom GPT and add/embed on your site using Assistants api
https://customgpt.thesamur.ai
MIT License
1.52k stars 269 forks source link

API Keys Exposed Publicly in Shared Links #9

Closed Keldos-Li closed 6 months ago

Keldos-Li commented 6 months ago

Hi, the current sharing mechanism reveals API keys publicly in shared links, posing a critical security threat. I think we need a new, secure linking method.

Anil-matcha commented 6 months ago

Will release an update next to fix this

Anil-matcha commented 6 months ago

Fixed now and allows user to input their api key before using the created assistant

mledwards commented 1 month ago

Hmm, this could have been fixed in a way that didn't stop the share link being unusable unless someone has a paid account?