mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 02:48:13 -05:00
[PR #12894] [MERGED] security/fix: prevent email and password changes to the primary admin account #23046
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/12894
Author: @Classic298
Created: 4/15/2025
Status: ✅ Merged
Merged: 4/18/2025
Merged by: @tjbck
Base:
dev← Head:patch-2📝 Commits (1)
4f14b17Update users.py📊 Changes
1 file changed (+27 additions, -0 deletions)
View changed files
📝
backend/open_webui/routers/users.py(+27 -0)📄 Description
Pull Request Checklist
Note to first-time contributors: Please open a discussion post in Discussions and describe your changes before submitting a pull request.
Before submitting, make sure you've checked the following:
devbranch.Changelog Entry
Description
/users/update/roleendpoint.Security
/users/{user_id}/updateendpoint to prevent admins from modifying the user identified byUsers.get_first_user(), unless the requesting admin is that first user./users/{user_id}/deleteendpoint to prevent any admin from deleting the user identified byUsers.get_first_user().Breaking Changes
Additional Information
Users.get_first_user()method.🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.