Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Bifrost HTTP 2.2.6: Setup-Token für /api-Aufrufe ohne Dashboard-Authentifizierung
Bifrost HTTP v2.2.6 verlangt bei OSS-Installationen ohne aktive Dashboard-Authentifizierung für nicht öffentliche /api-Aufrufe ein Setup-Token (setup_token bzw. BIFROST_SETUP_TOKEN) und aktiviert enforce_auth_on_inference für neue Deployments standardmäßig.
Bifrost HTTP Transport Release v2.2.6
✨ Features
- OSS Management API Setup Lock - While dashboard auth is not active (no admin account, or auth disabled), every non-public
/apicall on OSS Bifrost now needs the setup token, sent as theX-Bifrost-Setup-Tokenheader or as thebifrost_setup_sessioncookie the dashboard gets fromPOST /api/session/setup. A missing token returns401. A wrong token, or no token set on the server, returns403./health,/api/version, the session login routes,/.well-known/*and whitelisted routes stay public. The lock lifts as soon as an enabled admin is saved (#8010)<Warning> Migration: set `setup_token` in config.json (or `BIFROST_SETUP_TOKEN`) and restart. Then either enable dashboard auth, or send `X-Bifrost-Setup-Token` from scripts and API clients that call `/api` with auth off. Enterprise is not affected by the lock. </Warning> - Inference Auth On by Default -
enforce_auth_on_inferencenow defaults totruefor fresh deployments when config.json leaves it out, file-only deployments included. Creating the first enabled admin also turns inference auth on unless the request sets it explicitly. Inference without a credential then returns401. A stored database value always wins, and an explicitfalseis always kept. This also applies to Bifrost Enterprise (#8010, #7864) <Warning> …