Restrict GET /api/tasks and POST /api/tasks/stop/{task_id} to admin-only
Add new scoped POST /api/tasks/chat/{chat_id}/stop endpoint with ownership check so regular users can stop their own chat tasks
Allow admins to access the scoped chat task endpoints alongside owners
Update frontend to use the new scoped stop endpoint when a chatId is available
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
Note
Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.
## 📋 Pull Request Information
**Original PR:** https://github.com/open-webui/open-webui/pull/23454
**Author:** [@Classic298](https://github.com/Classic298)
**Created:** 4/6/2026
**Status:** ✅ Merged
**Merged:** 4/12/2026
**Merged by:** [@tjbck](https://github.com/tjbck)
**Base:** `dev` ← **Head:** `task-ownership`
---
### 📝 Commits (3)
- [`b42d132`](https://github.com/open-webui/open-webui/commit/b42d13277882604f77718e63475209a6d32fb551) Add ownership checks to global task endpoints
- [`18d56d4`](https://github.com/open-webui/open-webui/commit/18d56d4c415b8147623cfb390c53b46719a1e036) Handle temporary (local:) chat IDs in scoped task endpoints
- [`eced8fb`](https://github.com/open-webui/open-webui/commit/eced8fbaed42df331b2c91614a8bc88872310e7e) Verify session ownership for local: chat IDs and URL-encode chat_id
### 📊 Changes
**3 files changed** (+72 additions, -9 deletions)
<details>
<summary>View changed files</summary>
📝 `backend/open_webui/main.py` (+29 -6)
📝 `src/lib/apis/index.ts` (+33 -1)
📝 `src/lib/components/chat/Chat.svelte` (+10 -2)
</details>
### 📄 Description
- Restrict GET /api/tasks and POST /api/tasks/stop/{task_id} to admin-only
- Add new scoped POST /api/tasks/chat/{chat_id}/stop endpoint with ownership check so regular users can stop their own chat tasks
- Allow admins to access the scoped chat task endpoints alongside owners
- Update frontend to use the new scoped stop endpoint when a chatId is available
### Contributor License Agreement
<!--
🚨 DO NOT DELETE THE TEXT BELOW 🚨
Keep the "Contributor License Agreement" confirmation text intact.
Deleting it will trigger the CLA-Bot to INVALIDATE your PR.
Your PR will NOT be reviewed or merged until you check the box below confirming that you have read and agree to the terms of the CLA.
-->
- [X] By submitting this pull request, I confirm that I have read and fully agree to the [Contributor License Agreement (CLA)](https://github.com/open-webui/open-webui/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT), and I am providing my contributions under its terms.
> [!NOTE]
> Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in.
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/23454
Author: @Classic298
Created: 4/6/2026
Status: ✅ Merged
Merged: 4/12/2026
Merged by: @tjbck
Base:
dev← Head:task-ownership📝 Commits (3)
b42d132Add ownership checks to global task endpoints18d56d4Handle temporary (local:) chat IDs in scoped task endpointseced8fbVerify session ownership for local: chat IDs and URL-encode chat_id📊 Changes
3 files changed (+72 additions, -9 deletions)
View changed files
📝
backend/open_webui/main.py(+29 -6)📝
src/lib/apis/index.ts(+33 -1)📝
src/lib/components/chat/Chat.svelte(+10 -2)📄 Description
Contributor License Agreement
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.