ChatGPTNextWeb/ChatGPT-Next-Web

[Feature Request] 打开 https://app.nextchat.dev/ 官方网址, 填入 url/key, 无脑使用就行吧?

Closed this issue · 5 comments

🥰 需求描述

打开 https://app.nextchat.dev/ 官方网址, 填入 url/key使用就行吧?

我记得以前看过 url/key只存储在浏览器端, 不需要考虑密码之类的

我是客户端的老用户, 这次准备给别人推荐一下, 想让对方直接访问/体验

🧐 解决方案

麻烦了

📝 补充信息

No response

Bot detected the issue body's language is not English, translate it automatically.


Title: [Feature Request] Open the official website https://app.nextchat.dev/, fill in the url/key, just use it without thinking, right?

🥰 Description of requirements

Open the official website https://app.nextchat.dev/, fill in the url/key and use it, right?

I remember seeing before that url/key is only stored on the browser side, and there is no need to consider passwords and the like.

I am an old user of the client. This time I am going to recommend it to others. I want them to have direct access/experience.

🧐 Solution

Trouble

📝 Supplementary information

No response

不推荐这样,有泄露key的风险
推荐自己部署然后开启访问码即可

Bot detected the issue body's language is not English, translate it automatically.


This is not recommended as there is a risk of leaking the key.
It is recommended to deploy it yourself and then enable the access code.

不推荐这样,有泄露key的风险 推荐自己部署然后开启访问码即可

感谢
不过我想问一下, 目前知道的会怎么泄露呢?

  1. 钓鱼网站, 读取本地的 session/key
  2. 网络抓包

Bot detected the issue body's language is not English, translate it automatically.


This is not recommended as there is a risk of leaking the key. It is recommended to deploy it yourself and then enable the access code.

grateful
But I want to ask, how will what is known so far be leaked?

  1. Phishing website, read local session/key
  2. Network packet capture