User permission issue #3735

Closed
opened 2025-11-11 15:38:27 -06:00 by GiteaMirror · 2 comments
Owner

Originally created by @tandgers on GitHub (Feb 10, 2025).

User permission issue:
The 'Administrator' role can access all models normally, but it can directly modify the passwords of other administrators or users without knowing the original password, which poses a certain security issue;
Even if the user role is given the highest level of permissions, they cannot access the model and therefore cannot have normal conversations.

Originally created by @tandgers on GitHub (Feb 10, 2025). User permission issue: The 'Administrator' role can access all models normally, but it can directly modify the passwords of other administrators or users without knowing the original password, which poses a certain security issue; Even if the user role is given the highest level of permissions, they cannot access the model and therefore cannot have normal conversations.
Author
Owner

@tandgers commented on GitHub (Feb 10, 2025):

【管理员】角色可以正常访问所有模型,但是能在未知原密码的情况下,直接修改其他管理员或用户的密码,其存在一定安全问题;【用户】角色即使把权限给到最高也不能访问模型,也就不能正常对话。

@tandgers commented on GitHub (Feb 10, 2025): 【管理员】角色可以正常访问所有模型,但是能在未知原密码的情况下,直接修改其他管理员或用户的密码,其存在一定安全问题;【用户】角色即使把权限给到最高也不能访问模型,也就不能正常对话。
Author
Owner

@silenceroom commented on GitHub (Feb 10, 2025):

模型列表页是否指定了模型可访问组?用户是否能访问某个权限,取决于模型是否开放给用户使用。

@silenceroom commented on GitHub (Feb 10, 2025): 模型列表页是否指定了模型可访问组?用户是否能访问某个权限,取决于模型是否开放给用户使用。
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#3735