Commit Graph
18031 Commits
Author SHA1 Message Date
G30andGitHub 90724cdee0 fix: drop the white backdrop behind model icons in the admin Models list (#27612) 2026-08-17 01:03:37 -06:00
G30andGitHub 8fc5ffe26e fix: persist the Open Sharing permission in default user permissions (#27609) 2026-08-17 01:03:07 -06:00
Timothy Jaeryang BaekandSolaris-star 0480ca9653 refac
Co-Authored-By: Solaris-star <67425364+solaris-star@users.noreply.github.com>
2026-08-17 00:01:38 -07:00
Timothy Jaeryang BaekandClassic298 927ce0eae6 refac
Co-Authored-By: Classic298 <27028174+Classic298@users.noreply.github.com>
2026-08-16 23:58:56 -07:00
54cefd2b99 fix: preserve complete user context in agentic retrieval (#27642)
* fix: preserve user info in agentic RAG tools

* fix: preserve user info in file access checks

---------

Co-authored-by: Damien SPINELLI <damien.spinelli@external.list.lu>
2026-08-17 00:56:48 -06:00
686d8dc54c fix: strip prefix id from model name in /responses endpoint (#28575)
The /openai/responses endpoint forwarded the prefixed model id (e.g.
"myprovider.gpt-4o") to the upstream provider instead of the stripped
native name, causing "model not found" errors when a connection has a
Prefix ID configured.

generate_chat_completion() already strips the prefix before forwarding;
apply the same strip_provider_model_prefix() call in responses() after
the urlIdx routing (which needs the prefixed id) and re-serialize the
body afterwards.

Also fixes the Azure non-v1 deployment path, which built the deployment
URL from the prefixed model name.

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-17 00:53:00 -06:00
Classic298andGitHub 3df485582d fix: reject skill IDs that are not URL path safe (#27660)
A skill ID goes straight into the path of every mutating skill endpoint (/api/v1/skills/id/{id}/...), but create only replaced spaces with hyphens. An ID containing a "/" was stored verbatim as the primary key, so the route never matched, the request fell through to the SPA static mount and the client got 405 Method Not Allowed. The skill could not be opened, edited, toggled or deleted, by admins either, and since skill.name is UNIQUE it could not be recreated under a corrected ID. Percent-encoding does not help: uvicorn decodes the path before Starlette routes it, so the only remaining fix was a direct database write.

Create now rejects any ID outside [a-z0-9_-] with 400 instead of silently storing an unreachable one. Two frontend paths that fed unsanitized IDs into it are fixed as well: the manual "Skill ID" field, which was bound with no sanitization at all and is the path that reproduces on every version, and the markdown import, which put the raw frontmatter name into the ID before opening the editor in clone mode, where the reactive slugify is disabled.

Existing rows with an unreachable ID are not repaired here; rewriting a primary key would also have to re-point the access grants keyed on it.

Fixes #27655
2026-08-17 00:52:16 -06:00
Timothy Jaeryang Baek 954613944b refac 2026-08-16 23:51:38 -07:00
Classic298andGitHub 805bfca5af feat: emit group events on OAuth group sync (#27657)
With ENABLE_OAUTH_GROUP_MANAGEMENT enabled, every SSO login reconciles the user's group membership against the IdP claims, adding and removing them from groups and, with ENABLE_OAUTH_GROUP_CREATION, creating groups that do not exist yet. None of it emitted an event, so the same membership change was observable when an admin made it through the UI or when it arrived over SCIM, but invisible when the IdP drove it. That is the path that changes membership most often.

Emits group.member_added and group.member_removed per membership transition and group.created for each auto-created group, using the same payload keys as the groups router. The member events are published only when the write returned a group, so a failed or no-op write emits nothing, and both loops already run only on an actual transition. update_user_groups takes the request so the events can be published; it has a single caller.
2026-08-17 00:50:47 -06:00
Timothy Jaeryang Baek d5d50169f4 refac 2026-08-16 23:48:05 -07:00
Timothy Jaeryang Baek 75df30c0ea refac 2026-08-16 23:47:02 -07:00
Timothy Jaeryang BaekandClassic298 3e186abdd9 refac
Co-Authored-By: Classic298 <27028174+Classic298@users.noreply.github.com>
2026-08-16 23:41:58 -07:00
G30andGitHub 2813eb44f2 fix: stop the What's New modal drawing two bullets per changelog entry (#28676) 2026-08-17 00:40:57 -06:00
G30andGitHub ad72dc6658 fix: scroll to the top of a chat on the first click of Scroll to Top (#28659) 2026-08-17 00:40:14 -06:00
Timothy Jaeryang Baek 16f118d77a refac 2026-08-16 23:38:34 -07:00
G30andGitHub 884388cac3 fix(search): wire up mark as unread in the search chats modal (#28136) 2026-08-17 00:34:49 -06:00
Timothy Jaeryang Baek 736e38338e refac 2026-08-16 23:32:23 -07:00
Timothy Jaeryang Baek a40f6f2860 refac 2026-08-16 23:28:48 -07:00
Timothy Jaeryang Baek b5da50f3df refac 2026-08-16 23:26:24 -07:00
Classic298andGitHub cd9db21c52 refac: bind tool server cookies per connection (#28630)
The tool callable now takes its connection's cookie jar as a parameter, matching how its headers are already passed and how the terminal tool factory in the same module builds its callables.
2026-08-17 00:25:07 -06:00
Classic298andGitHub 7d392bedc9 refac: align the channel completion gate with the message update route (#28631)
The gate now applies the same authorship condition the channel message update route already uses, so both paths agree on which messages a caller may modify.
2026-08-17 00:24:49 -06:00
Classic298andGitHub 1756c9d5d2 fix: default pinned models stop applying after a user's first page load (#28069)
Changing "Default Pinned Models" in admin settings had no effect for anyone who had already opened Open WebUI once. The sidebar copied the admin default into that user's own settings the first time it rendered and saved it to the server, which marked them as having customized their pins, so every later change to the default was ignored for them. Merely loading the page was enough, the user never had to touch a pin.

The default is now resolved for display only, through a shared store that falls back to the admin list while the user has no pins of their own, the same way default models already work. Nothing is written to the user's settings until they actually pin, unpin or reorder something, at which point their choice takes over for good. Unpinning everything still persists an empty list rather than snapping back to the default.

Users whose settings were already overwritten by the old behaviour keep that copy, since a stored pin list cannot be told apart from a deliberate one.

Fixes a drag-reorder path that mixed sidebar positions with stored ones, and stops the sidebar section reopening itself after any unrelated settings change.
2026-08-17 00:22:51 -06:00
Timothy Jaeryang Baek 1a376ac17f refac 2026-08-16 23:21:00 -07:00
Timothy Jaeryang Baek b211c407f4 refac 2026-08-16 23:14:08 -07:00
G30andGitHub 1d1c14bd77 fix: compare folder names for uniqueness with lower() equality instead of a LIKE pattern (#28695) 2026-08-17 00:00:02 -06:00
Timothy Jaeryang Baek e4694d6c3f refac 2026-08-16 22:59:10 -07:00
Timothy Jaeryang Baek f7a533cda6 refac 2026-08-16 22:57:01 -07:00
Timothy Jaeryang BaekandClassic298 3258330729 refac
Co-Authored-By: Classic298 <27028174+Classic298@users.noreply.github.com>
2026-08-16 22:56:19 -07:00
Timothy Jaeryang Baek 62fc436999 refac 2026-08-16 22:52:24 -07:00
Timothy Jaeryang Baek 31d08d592c refac 2026-08-15 01:10:14 -06:00
Timothy Jaeryang Baek 467be93e6d refac 2026-08-15 01:09:39 -06:00
Timothy Jaeryang Baek 7fc5fa1ff3 refac 2026-08-15 01:02:06 -06:00
Timothy Jaeryang Baek 3eb65f4715 refac 2026-08-15 00:06:38 -06:00
Timothy Jaeryang Baek 30f82788bc refac 2026-08-15 00:05:45 -06:00
Timothy Jaeryang Baek bbfdbd59f2 refac 2026-08-15 00:05:37 -06:00
Timothy Jaeryang Baek 98b9df0398 refac 2026-08-15 00:05:11 -06:00
Timothy Jaeryang Baek 0f821398ca refac 2026-08-14 23:52:13 -06:00
Timothy Jaeryang Baek 1b39ff352a refac 2026-08-14 23:50:34 -06:00
Timothy Jaeryang Baek a5ea732c1e refac 2026-08-14 23:47:00 -06:00
Timothy Jaeryang Baek 516cf1a9a6 refac 2026-08-14 21:44:13 -06:00
Timothy Jaeryang Baek d02b6a21fc refac 2026-08-14 00:55:21 -06:00
Timothy Jaeryang Baek c755ef60c6 refac 2026-08-14 00:54:33 -06:00
Timothy Jaeryang Baek a1579a01ff refac 2026-08-14 00:22:17 -06:00
Timothy Jaeryang Baek f7767d6be7 refac 2026-08-13 22:08:42 -06:00
Timothy Jaeryang Baek d9014b3483 refac 2026-08-13 22:01:33 -06:00
Timothy Jaeryang Baek 57bd08304e refac 2026-08-13 22:01:17 -06:00
Timothy Jaeryang Baek 14e4d72d9a refac 2026-08-13 22:01:15 -06:00
Timothy Jaeryang Baek 256cce505b refac 2026-08-13 21:51:04 -06:00
Timothy Jaeryang Baek 55c202e841 refac 2026-08-13 21:48:01 -06:00
Timothy Jaeryang Baek fa94a5ab24 refac 2026-08-13 21:36:41 -06:00