mirror of
https://github.com/Mintplex-Labs/anything-llm.git
synced 2026-07-21 01:25:28 -04:00
Open
opened 2026-02-22 18:29:46 -05:00 by yindo
·
7 comments
No Branch/Tag Specified
master
5846-bug-when-scrolling-up-scrolling-jumps
2235-translations
2235-bug-how-to-upload-a-folder-with-subfolders-with-files-to-anythingllm
refactor-remove-workspace-pfp
5969-bug-stopgenerationbutton-disappears-on-the-first-prompt-that-initiates-an-agent-session
5968-chore-update-default-system-prompt-for-better-tool-use
5990-workspace-update-fails-with-unknown-argument-router_id-v1130v1150-intel-mac
opencomputer-examples
pg
feat/image-generation-translations
feat/image-generation
5924-bug-meeting-summary-fails-with-sincludes-is-not-a-function-when-default-llm-is-anthropic-claude
render
feat/uniform-modal-component
5883-bug-unescaped-content-in-json-strings-being-passed-to-document-generator-tools
5901-bug-api-update-embeddings-fails-prisma-argument-filename-is-missing-on-workspace_documentscreate-desktop-windows-v1141
hybrid-search
1981-translations
5752-bug-prompts-to-local-jan-endpoint-unresponsive
feat-disable-native-tool-calling-env-var
5676-bug-non-ollama-agent-providers-do-not-parse-and-present-reasoning-content
feat/markdown-web-scraping
5717-bug-apiv1documentupload-silently-drops-metadata-field-in-desktop-1130-arg-count-mismatch-nested-payload-key
fix/aibitat-context-overflow
5711-bug-erratic-deepseek-v4-flash-the-agent-model-failed-to-respond-400-the-reasoning_content
5631-feat-custom-api-request-timeouts-for-ai-providers
feat-reasoning-control
feat-agent-clarifying-questions-translations
5583-bug-lm-studio-provider-does-not-present-reasoning-output
5313-normalize-translations
feat/memory-translations
5305-lemonade-embedding-engine-swallows-errors-falsely-reports-documents-as-embedded
5060-bug-agent-interactions-agent-are-not-persisted-to-thread-history-via-api
pptx-subagent
feat-render-images-from-mcp-tool-results
stt-provider-expansion-openai-api-compatible
feat-file-search-agent-tool
feat-native-embedder-job-queue
5189-normalize-translations
feat-file-search-agent-tool-translations
i18n-eslint
5140-auto-migration
5112-bug-openrouter-failed-message-bug
3506-feat-parameters-for-openrouter-models
4992-feat-preserve-scroll-position
4973-bug-markdown-numbered-list-display-in-reasoning-pane
desktop
4938-bug-pending-chat-rerendering-ui-bug
quickstart-env
node-llama-cpp-in-container-cuda
node-llama-cpp-in-container
ollama-in-container
4817-feat-set-cooldown-per-mcp-server
4845-keyboard-shortcuts-to-navigate-in-chat
4844-feat-reorder-threads-by-latest-interaction
standardize-username-constraints-normalize-translations
4792-feat-refactor-workspacepfp-image
1382-embed-ip-improvements
1382-bug-embed-api-improvements
refactor-eslint-frontend
4687-feat-refactor-vector-db-providers
4615-feat-disable-apidocs-with-environment-variable
4559-feat-agent-web-search-enable-ordering-of-results
4599-bug-ollama-race-condition-bug
4572-bug-lmstudio-provided-llm-stopped-working-with-anything-llm-after-upgrading-to-190
4508-agent-youtube-transcript-analysis
4497-feat-workspace-names
frontend-eslint
ollama-lmstudio-auto-context-window
4431-validate-vector-database-connectioN
2019-slash-command-keyboard-selection
microsoft-foundry-provider
4431-validate-vector-database-connection
4325-sys-prompt-var-improvements
3209-feat-apiv1workspacestream-chat-sources-citations
4210-bug-voice-to-text-overwrite
4136-feat-jan-as-a-backend-server-option
4172-feat-openai-o3-support
1.8.3-rerelease
web-push-notifications-service
tasks
3955-feat-jinaai-embedder-provider-support
3921-feat-agent-skills-uiux-improvements
3901-bug-validfunccall-checks-optional-arguments
keyboard-dev
1787-custom-roles-and-permissions
add-jira-slack-data-connector
office-extension-wip
lightmode-dropdown-color-update
3586-bug-agent-flow-function-description-provided-by-user-is-not-seen-in-the-llm-query
3463-bug-agent-continues-to-run-if-request-failed-even-after-exit
3439-feat-call-variables-within-the-flow-api-block-url-field
3282-manager-view-models-workspace
3280-token-counting-server-side-truncation-improvements
3147-bug-embedded-chat-widget---not-considering-query-mode-option-always-working-in-chat-mode
2995-feat-disable-temperature-setting-for-deepseek-r1-deepseek-reasoner-model
2827-feat-perplexity-citations
2866-feat-finally-a-gemini-models-endpoint
2647-feat-hpp-header-for-a-c++-code-file-mime-addition
lancedb-revert
1656-feat-implement-tooltip-ui-designs
2011-feat-bump-perplexity-models
1873-feat-auto-add-and-watch-folder-for-document-uploads
1297-feat-gemini-agent-support
1759-bug-ui-bug-fixes
1686-feat-implement-winston-for-logging
1536-bug-toggling-on-users-can-delete-workspaces-does-not-take-effect
agent-ui-mobile-styles
1522-feat-chromadb-support
1595-bug-unable-to-get-live-web-search-and-browsing-agent-working-using-google-custom-search-engine-error-getaddrinfo-enotfound-http-errno-3008
1582-bug-lm-studio-does-not-allow-for-different-model-selection
1312-bug-usernames-should-not-be-case-sensitive-when-logging-in
1029-feat-hf-serverless-inference-api
1086-feat-implement-normalized-input-fields
knowledge-graph-support
644-bug-uploaded-file-name-does-not-match-the-displayed-file-name-after-the-upload
v1.15.0
v1.14.2
v1.14.1
v1.14.0
v1.13.0
v1.12.1
v1.12.0
v1.11.2
v1.11.1
v1.11.0
v1.10.0
v1.9.1
v1.9.0
v1.8.5
v1.8.4
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.7.8
v1.7.6
v1.7.5
v1.7.4
v1.4.0
v1.3.0
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.1
v1.1.0
v1.0.0
Labels
Clear labels
Desktop
Docker
Integration Request
Integration Request
OS: Linux
OS: Mobile
OS: Windows
UI/UX
blocked
bug
bug
core-team-only
documentation
duplicate
embed-widget
enhancement
feature request
github_actions
good first issue
investigating
needs info / can't replicate
possible bug
pull-request
question
stage: specifications
wontfix
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Mintplex-Labs/anything-llm#2463
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @stentorianjoe on GitHub (May 20, 2025).
Original GitHub issue: https://github.com/Mintplex-Labs/anything-llm/issues/3855
What would you like to see?
Expansion on #2970 (Workspace-assigned Custom Skills);
Current implementation requires the MCP tool flow to manage auth to the external service in the chat context using tool parameters, or via global env supplied in AnythingLLM config that authorizes all Agent enabled Threads across all Workspaces for each configured MCP server.
Design-Agnostic - MCP Client Session per Workspace/User/Thread rather than per Server, with associated management - possible stepping stone could be to limit available tools in a Workspace according to an 'Enabled Tools' dictionary filtered upon registration to the MCP servers.
Would further enable RBAC for different users to have access to different MCP servers/tools based on their AnythingLLM User and/or Workspace.
@timothycarambat commented on GitHub (May 20, 2025):
https://github.com/Mintplex-Labs/anything-llm/issues/2970
and
https://github.com/Mintplex-Labs/anything-llm/pull/3799
Would cover the scope of this :+1
@stentorianjoe commented on GitHub (May 23, 2025):
The end result seems similar, but because MCP clients need to manage unique streaming sessions (currently per-instance of AnythingLLM) it is unclear how this should be handled, and its implementation may be very different to those (adding a parameter to the request, spawning sessions based on thread or workspace).
Had a debate with myself whether to add it to #2970 but decided to separate concerns. How is this being done in #3799?
@RobMaye commented on GitHub (Jun 6, 2025):
Would love to see this too.
@timothycarambat commented on GitHub (Jun 6, 2025):
Since MCPs are just skills, this should be just any skills not just MCP. It winds up being the same thing but less specific and more useful
@roller100 commented on GitHub (Jul 21, 2025):
MCP Workspace-Specific Authentication: RBAC Use Case Summary
Executive Summary
This document outlines a critical security requirement for Model Context Protocol (MCP) implementations in enterprise environments: workspace-specific agent skills with proper RBAC pass-through authentication. The current limitation where all workspaces share global MCP configurations creates significant security vulnerabilities and compliance risks that block enterprise adoption.
The Problem: Shared Credentials Across All Workspaces
Current AnythingLLM MCP Implementation
Security Vulnerabilities
Use Case: Neo4j Database with Proper RBAC
Scenario
Development team uses AnythingLLM with Neo4j MCP server to query knowledge graph database:
What Should Happen: Per-User Authentication
Database-Side RBAC (Already Configured)
Current State of MCP OAuth 2.1 Specification
What OAuth 2.1 DOES Provide
What OAuth 2.1 DOESN'T Solve
Key Insight
MCP OAuth 2.1 provides building blocks but doesn't solve the fundamental client-side workspace isolation problem.
Required Solution: GitHub Issue #3855
Feature Request: Workspace-Specific Agent Skills
GitHub Issue #3855 requests:
Technical Implementation Needs
Business Impact
Without This Feature
With This Feature
Broader Applicability
This use case affects any MCP server connecting to systems with existing RBAC:
Recommendation
Priority: CRITICAL - This is a security requirement that blocks enterprise MCP adoption
Implementation Path:
Related Issues:
Conclusion
The workspace-specific agent skills feature (GitHub Issue #3855) is not just a convenience enhancement - it's a fundamental security requirement for enterprise MCP deployment. Without proper credential isolation and RBAC pass-through, MCP implementations cannot meet basic security and compliance standards required by regulated industries.
The Neo4j use case demonstrates this requirement clearly: database systems already have proper RBAC configured, but AnythingLLM's global MCP configuration bypasses these controls entirely, creating unacceptable security risks. This same pattern affects any system with existing RBAC - making AnythingLLM unsuitable for enterprise deployment until workspace-specific MCP configurations are implemented.
@HanJammer commented on GitHub (Nov 10, 2025):
Absolutely agree.
That's one of the most important things to implement actually. Without it the multi-user mode is seriously impacted for anything but the most basic use cases with read-only tools.
[FEAT]: Workspace specific agent skillsto [GH-ISSUE #3855] [FEAT]: Workspace specific agent skills@miraculix95 commented on GitHub (May 18, 2026):
Adding a concrete production use-case + implementation thought to push this forward.
Use-Case
I'm running a multi-tenant RAG setup with a self-hosted vector database (pgvector) exposed via a custom MCP server. Each customer/workspace needs auth-scoped access to their own data only. Today this is blocked because:
anythingllm_mcp_servers.jsonis loaded globally — every workspace sees the same MCP servers with the same env (auth tokens included)This is a real blocker for serious multi-tenant deployments — exactly the scenarios where AnythingLLM as a SaaS-style frontend would shine.
Suggested Implementation Direction
Following the design hint from the issue body, the minimal version could be:
allowed_mcp_servers(JSON array) to the workspace settings schema in PrismaPUT /workspace/:slug/mcp-serversfor admins to scope per workspacemcpHypervisor.serverslist byworkspace.allowed_mcp_serversbefore passing to the agent runtimeHappy to test a PoC PR against production data if a maintainer wants to collaborate on the design. Without per-workspace MCP scoping, the "agent mode" feature is essentially restricted to single-tenant or fully-trusted-team scenarios — which is a shame given how much infrastructure AnythingLLM already provides for multi-workspace setups.
Also seeing recent Discord activity on this exact ask (May 2026) — the need is current, not dormant.