[GH-ISSUE #7047] enh: user level access control #30109

Closed
opened 2026-04-25 04:24:40 -05:00 by GiteaMirror · 1 comment
Owner

Originally created by @tjbck on GitHub (Nov 19, 2024).
Original GitHub issue: https://github.com/open-webui/open-webui/issues/7047

#2924

Originally created by @tjbck on GitHub (Nov 19, 2024). Original GitHub issue: https://github.com/open-webui/open-webui/issues/7047 #2924
Author
Owner

@TheLastFrame commented on GitHub (Jan 14, 2026):

So, as you saw in #19859 I would really love to have user based access control, as this would enable non-admins with knowledge management permissions to create knowledge and easily configure access. A sort of self-service.

You said

chances are we'll depreciate the current group based access control and instead introduce a better scalable mechanism here
Does this mean you want to move away from groups to user only - or which other mechanism do you have in mind to be more scalable?

Anyways I'd be ready to redo my PR again for the newest version. This would imo not change much - only enable the user based access control, which the api already supports.

Removing the group feature can still be done in a later PR - but I guess that would be a breaking change for a lot of enterprise users with OICD auth?

I'd be really interested in your view of this feature :)

<!-- gh-comment-id:3748704310 --> @TheLastFrame commented on GitHub (Jan 14, 2026): So, as you saw in #19859 I would really love to have user based access control, as this would enable non-admins with knowledge management permissions to create knowledge and easily configure access. A sort of self-service. You said > chances are we'll depreciate the current group based access control and instead introduce a better scalable mechanism here Does this mean you want to move away from groups to user only - or which other mechanism do you have in mind to be more scalable? Anyways I'd be ready to redo my PR again for the newest version. This would imo not change much - only enable the user based access control, which the api already supports. Removing the group feature can still be done in a later PR - but I guess that would be a breaking change for a lot of enterprise users with OICD auth? I'd be really interested in your view of this feature :)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#30109