[PR #20623] [CLOSED] feat: add user-to-user resource sharing #25705

Closed
opened 2026-04-20 06:05:09 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/open-webui/open-webui/pull/20623
Author: @johnmgibson3
Created: 1/12/2026
Status: Closed

Base: devHead: feature/user-to-user-resource-sharing


📝 Commits (10+)

📊 Changes

5 files changed (+139 additions, -0 deletions)

View changed files

📝 backend/open_webui/config.py (+6 -0)
📝 backend/open_webui/main.py (+3 -0)
📝 backend/open_webui/routers/auths.py (+6 -0)
📝 src/lib/components/admin/Settings/General.svelte (+8 -0)
📝 src/lib/components/workspace/common/AccessControl.svelte (+116 -0)

📄 Description

Pull Request Checklist

Note to first-time contributors: Please open a discussion post in Discussions to discuss your idea/fix with the community before creating a pull request, and describe your changes before submitting a pull request.

This is to ensure large feature PRs are discussed with the community first, before starting work on it. If the community does not want this feature or it is not relevant for Open WebUI as a project, it can be identified in the discussion before working on the feature and submitting the PR.

Before submitting, make sure you've checked the following:

  • Target branch: Verify that the pull request targets the dev branch. Not targeting the dev branch will lead to immediate closure of the PR.
  • Description: Provide a concise description of the changes made in this pull request down below.
  • Changelog: Ensure a changelog entry following the format of Keep a Changelog is added at the bottom of the PR description.
  • Documentation: If necessary, update relevant documentation Open WebUI Docs like environment variables, the tutorials, or other documentation sources. (See Additional Info.)
  • Dependencies: Are there any new dependencies? Have you updated the dependency versions in the documentation?
  • Testing: Perform manual tests to verify the implemented fix/feature works as intended AND does not break any other functionality. Take this as an opportunity to make screenshots of the feature/fix and include it in the PR description.
  • Agentic AI Code: Confirm this Pull Request is not written by any AI Agent or has at least gone through additional human review AND manual testing. If any AI Agent is the co-author of this PR, it may lead to immediate closure of the PR.
  • Code review: Have you performed a self-review of your code, addressing any coding standard issues and ensuring adherence to the project's coding standards?
  • Title Prefix: To clearly categorize this pull request, prefix the pull request title using one of the following:
    • BREAKING CHANGE: Significant changes that may affect compatibility
    • build: Changes that affect the build system or external dependencies
    • ci: Changes to our continuous integration processes or workflows
    • chore: Refactor, cleanup, or other non-functional code changes
    • docs: Documentation update or addition
    • feat: Introduces a new feature or enhancement to the codebase
    • fix: Bug fix or error correction
    • i18n: Internationalization or localization changes
    • perf: Performance improvement
    • refactor: Code restructuring for better maintainability, readability, or scalability
    • style: Changes that do not affect the meaning of the code (white space, formatting, missing semi-colons, etc.)
    • test: Adding missing tests or correcting existing tests
    • WIP: Work in progress, a temporary label for incomplete or ongoing work

Changelog Entry

Description

  • Enables direct sharing of resources (models, knowledge bases, prompts, tools, channels, documents, and functions) with individual users, alongside existing group-based sharing. This addresses community requests from discussions #15070, #12358, #17639. Here is my discussion post, #20533

    Key points:

    • Backend already supported this functionality via has_access() checking user_ids - this PR adds the missing UI layer
    • No new security surface - uses the same user search API already employed by Channels
    • Feature-flagged via ENABLE_INDIVIDUAL_USER_SHARING config (disabled by default)
    • Fully backward compatible with existing group-based sharing

Added

  • User-to-user resource sharing capability for all shareable workspace resources
  • ENABLE_INDIVIDUAL_USER_SHARING configuration toggle in backend (config.py)
  • User search and selection interface in AccessControl.svelte component
  • Admin toggle in General Settings to enable/disable the feature
  • User list display with read/write permission controls matching existing group pattern

Changed

  • Enhanced workspace/common/AccessControl.svelte to conditionally display user selection based on feature flag (+116 lines)
  • Updated admin/Settings/General.svelte to include feature toggle (+8 lines)
  • Exposed configuration in main.py and routers/auths.py (+15 lines)

Deprecated

  • None

Removed

  • None

Fixed

  • None

Security

  • Respects existing workspace permission controls (USER_PERMISSIONS_WORKSPACE_*_ACCESS)
  • User-to-user sharing works within the existing permission framework, not as a bypass
  • No new user exposure - leverages the existing authenticated user search API used by Channels
  • Admins maintain full control through existing workspace permissions plus the new feature toggle

Breaking Changes

  • BREAKING CHANGE: None

Additional Information

  • Documentation: Will update Open WebUI docs to add ENABLE_INDIVIDUAL_USER_SHARING environment variable after maintainer review/approval
  • Files changed: 5 files, ~139 lines added
  • No new dependencies: Uses existing APIs and patterns
  • Works for all resource types: Models, knowledge bases, prompts, tools, channels, documents, and functions
  • Testing environment: Manually tested in AWS deployment with multiple users
  • Implementation note: This PR primarily adds UI - the backend has_access() utility and REST API already support user_ids in access control structures

Testing verification:

  • User search and selection works correctly
  • Read/write permissions apply as expected
  • Admin toggle successfully controls feature visibility
  • Existing group-based sharing continues to work unchanged
  • Public/private toggle functions properly alongside new feature
  • Feature respects existing workspace permission restrictions

Screenshots or Videos

  • Screenshot 2026-01-09 at 5 03 57 PM
Screenshot 2026-01-09 at 5 06 11 PM

Contributor License Agreement

By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.

Note

Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/open-webui/open-webui/pull/20623 **Author:** [@johnmgibson3](https://github.com/johnmgibson3) **Created:** 1/12/2026 **Status:** ❌ Closed **Base:** `dev` ← **Head:** `feature/user-to-user-resource-sharing` --- ### 📝 Commits (10+) - [`fe6783c`](https://github.com/open-webui/open-webui/commit/fe6783c16699911c7be17392596d579333fb110c) Merge pull request #19030 from open-webui/dev - [`fc05e0a`](https://github.com/open-webui/open-webui/commit/fc05e0a6c5d39da60b603b4d520f800d6e36f748) Merge pull request #19405 from open-webui/dev - [`e3faec6`](https://github.com/open-webui/open-webui/commit/e3faec62c58e3a83d89aa3df539feacefa125e0c) Merge pull request #19416 from open-webui/dev - [`9899293`](https://github.com/open-webui/open-webui/commit/9899293f050ad50ae12024cbebee7e018acd851e) Merge pull request #19448 from open-webui/dev - [`140605e`](https://github.com/open-webui/open-webui/commit/140605e660b8186a7d5c79fb3be6ffb147a2f498) Merge pull request #19462 from open-webui/dev - [`6f1486f`](https://github.com/open-webui/open-webui/commit/6f1486ffd0cb288d0e21f41845361924e0d742b3) Merge pull request #19466 from open-webui/dev - [`d95f533`](https://github.com/open-webui/open-webui/commit/d95f533214e3fe5beb5e41ec1f349940bc4c7043) Merge pull request #19729 from open-webui/dev - [`a727153`](https://github.com/open-webui/open-webui/commit/a7271532f8a38da46785afcaa7e65f9a45e7d753) 0.6.43 (#20093) - [`85c7d4d`](https://github.com/open-webui/open-webui/commit/85c7d4da7d86a03c89eb2fc67b621d5e10813de4) feat: add individual user resource sharing - [`6221686`](https://github.com/open-webui/open-webui/commit/622168629789ddbdefe609d1484651bf455c1cd6) fix: disable individual user sharing by default ### 📊 Changes **5 files changed** (+139 additions, -0 deletions) <details> <summary>View changed files</summary> 📝 `backend/open_webui/config.py` (+6 -0) 📝 `backend/open_webui/main.py` (+3 -0) 📝 `backend/open_webui/routers/auths.py` (+6 -0) 📝 `src/lib/components/admin/Settings/General.svelte` (+8 -0) 📝 `src/lib/components/workspace/common/AccessControl.svelte` (+116 -0) </details> ### 📄 Description # Pull Request Checklist ### Note to first-time contributors: Please open a discussion post in [Discussions](https://github.com/open-webui/open-webui/discussions) to discuss your idea/fix with the community before creating a pull request, and describe your changes before submitting a pull request. This is to ensure large feature PRs are discussed with the community first, before starting work on it. If the community does not want this feature or it is not relevant for Open WebUI as a project, it can be identified in the discussion before working on the feature and submitting the PR. **Before submitting, make sure you've checked the following:** - [x] **Target branch:** Verify that the pull request targets the `dev` branch. **Not targeting the `dev` branch will lead to immediate closure of the PR.** - [x] **Description:** Provide a concise description of the changes made in this pull request down below. - [x] **Changelog:** Ensure a changelog entry following the format of [Keep a Changelog](https://keepachangelog.com/) is added at the bottom of the PR description. - [ ] **Documentation:** If necessary, update relevant documentation [Open WebUI Docs](https://github.com/open-webui/docs) like environment variables, the tutorials, or other documentation sources. (See Additional Info.) - [x] **Dependencies:** Are there any new dependencies? Have you updated the dependency versions in the documentation? - [x] **Testing:** Perform manual tests to **verify the implemented fix/feature works as intended AND does not break any other functionality**. Take this as an opportunity to **make screenshots of the feature/fix and include it in the PR description**. - [x] **Agentic AI Code:** Confirm this Pull Request is **not written by any AI Agent** or has at least **gone through additional human review AND manual testing**. If any AI Agent is the co-author of this PR, it may lead to immediate closure of the PR. - [x] **Code review:** Have you performed a self-review of your code, addressing any coding standard issues and ensuring adherence to the project's coding standards? - [x] **Title Prefix:** To clearly categorize this pull request, prefix the pull request title using one of the following: - **BREAKING CHANGE**: Significant changes that may affect compatibility - **build**: Changes that affect the build system or external dependencies - **ci**: Changes to our continuous integration processes or workflows - **chore**: Refactor, cleanup, or other non-functional code changes - **docs**: Documentation update or addition - **feat**: Introduces a new feature or enhancement to the codebase - **fix**: Bug fix or error correction - **i18n**: Internationalization or localization changes - **perf**: Performance improvement - **refactor**: Code restructuring for better maintainability, readability, or scalability - **style**: Changes that do not affect the meaning of the code (white space, formatting, missing semi-colons, etc.) - **test**: Adding missing tests or correcting existing tests - **WIP**: Work in progress, a temporary label for incomplete or ongoing work # Changelog Entry ### Description - Enables direct sharing of resources (models, knowledge bases, prompts, tools, channels, documents, and functions) with individual users, alongside existing group-based sharing. This addresses community requests from discussions #15070, #12358, #17639. Here is my discussion post, #20533 Key points: - Backend already supported this functionality via has_access() checking user_ids - this PR adds the missing UI layer - No new security surface - uses the same user search API already employed by Channels - Feature-flagged via ENABLE_INDIVIDUAL_USER_SHARING config (disabled by default) - Fully backward compatible with existing group-based sharing ### Added - User-to-user resource sharing capability for all shareable workspace resources - ENABLE_INDIVIDUAL_USER_SHARING configuration toggle in backend (config.py) - User search and selection interface in AccessControl.svelte component - Admin toggle in General Settings to enable/disable the feature - User list display with read/write permission controls matching existing group pattern ### Changed - Enhanced workspace/common/AccessControl.svelte to conditionally display user selection based on feature flag (+116 lines) - Updated admin/Settings/General.svelte to include feature toggle (+8 lines) - Exposed configuration in main.py and routers/auths.py (+15 lines) ### Deprecated - None ### Removed - None ### Fixed - None ### Security - Respects existing workspace permission controls (USER_PERMISSIONS_WORKSPACE_*_ACCESS) - User-to-user sharing works within the existing permission framework, not as a bypass - No new user exposure - leverages the existing authenticated user search API used by Channels - Admins maintain full control through existing workspace permissions plus the new feature toggle ### Breaking Changes - **BREAKING CHANGE**: None --- ### Additional Information - **Documentation**: Will update Open WebUI docs to add `ENABLE_INDIVIDUAL_USER_SHARING` environment variable after maintainer review/approval - Files changed: 5 files, ~139 lines added - No new dependencies: Uses existing APIs and patterns - Works for all resource types: Models, knowledge bases, prompts, tools, channels, documents, and functions - Testing environment: Manually tested in AWS deployment with multiple users - Implementation note: This PR primarily adds UI - the backend has_access() utility and REST API already support user_ids in access control structures Testing verification: - ✅ User search and selection works correctly - ✅ Read/write permissions apply as expected - ✅ Admin toggle successfully controls feature visibility - ✅ Existing group-based sharing continues to work unchanged - ✅ Public/private toggle functions properly alongside new feature - ✅ Feature respects existing workspace permission restrictions ### Screenshots or Videos - <img width="1255" height="786" alt="Screenshot 2026-01-09 at 5 03 57 PM" src="https://github.com/user-attachments/assets/d1724dab-abd6-4de1-a195-fe093f1f0bc7" /> <img width="1236" height="602" alt="Screenshot 2026-01-09 at 5 06 11 PM" src="https://github.com/user-attachments/assets/53f3027f-1ce3-41d5-bebe-f9823090c51b" /> ### Contributor License Agreement By submitting this pull request, I confirm that I have read and fully agree to the [Contributor License Agreement (CLA)](https://github.com/open-webui/open-webui/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT), and I am providing my contributions under its terms. > [!NOTE] > Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in. --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-04-20 06:05:09 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#25705