Access to join

#47
by nroggendorff - opened

This feature used to be a part of blog explorers, and it looks like it isn't anymore.

It was worth a shot.

nroggendorff changed discussion status to closed
nroggendorff changed discussion title from Can I join, please? to Access to join

If this is somehow seen by an admin, I'd like it to be known that I want enterprise for None-yet to have more access to ZeroGPU so people are actually incentivized and able to put stuff on there.

Social Post Explorers org

If this is somehow seen by an admin, I'd like it to be known that I want enterprise for None-yet to have more access to ZeroGPU so people are actually incentivized and able to put stuff on there.

If that is done you should change it to require approval, otherwise it could be abused similar to Nerdyface

I don't think requiring approval to join would help with that, as I'd probably just approve almost everyone anyway. I would say using some sort of activity-based filtering would work, but I didn't have any demos when I was added to zerogpu-explorers. Plus, that would be pretty easy to trick, too.

I just realized that the one space we have has a major vulnerability. We should definitely get Enterprise for access tokens, because right now if someone merges a PR with import os; print(os.environ["HF_TOKEN"]), it will expose the token in the public logs.

It's not bad right now, because I'm the only one that can merge PRs.
It's also possible that token was revoked by now.

cc @Reality123b

Sign up or log in to comment