Raised on LibreChat-AI#16259: LibreChat-AI#16259 (comment)
Principal-scoped config overrides (role, group, user) are written through the admin config API as a Mixed overrides document without passing through configSchema, then deep-merged over the base librechat.yaml config at resolution time. A malformed override field therefore replaces a valid base value before any consumer sees it.
For passkeys.perUserMax (LibreChat-AI#16259), the resolver now holds the value to the schema's 1-100 integer bounds and falls back to MAX_PASSKEYS_PER_USER, then 20. But when YAML sets a lower cap such as 2 and an override sets an invalid value, the valid base 2 is already gone and the user's cap becomes 20. The same shape applies to every other config field an override can set.
Proposed fix: validate override payloads against the matching configSchema section when they are written (reject invalid fields), or strip invalid override fields before the merge so the base value survives. Validating at write time fixes every field at once instead of hardening each consumer.
Raised on LibreChat-AI#16259: LibreChat-AI#16259 (comment)
Principal-scoped config overrides (role, group, user) are written through the admin config API as a Mixed
overridesdocument without passing throughconfigSchema, then deep-merged over the baselibrechat.yamlconfig at resolution time. A malformed override field therefore replaces a valid base value before any consumer sees it.For
passkeys.perUserMax(LibreChat-AI#16259), the resolver now holds the value to the schema's 1-100 integer bounds and falls back toMAX_PASSKEYS_PER_USER, then 20. But when YAML sets a lower cap such as 2 and an override sets an invalid value, the valid base 2 is already gone and the user's cap becomes 20. The same shape applies to every other config field an override can set.Proposed fix: validate override payloads against the matching
configSchemasection when they are written (reject invalid fields), or strip invalid override fields before the merge so the base value survives. Validating at write time fixes every field at once instead of hardening each consumer.