mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 10:58:17 -05:00
[PR #21595] [MERGED] fix: respect BYPASS_ADMIN_ACCESS_CONTROL in file list/search endpoints #41785
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/21595
Author: @Classic298
Created: 2/19/2026
Status: ✅ Merged
Merged: 2/19/2026
Merged by: @tjbck
Base:
dev← Head:fix-admin-access-control-file-modal📝 Commits (1)
56522b5fix: respect BYPASS_ADMIN_ACCESS_CONTROL in file list/search endpoints📊 Changes
1 file changed (+4 additions, -3 deletions)
View changed files
📝
backend/open_webui/routers/files.py(+4 -3)📄 Description
The list_files and search_files endpoints unconditionally showed all files
to admin users. Now they check BYPASS_ADMIN_ACCESS_CONTROL so that when
it is set to False, admins only see their own files, consistent with how
other routers (models, knowledge, tools, prompts) handle this setting.
Fixes: https://github.com/open-webui/open-webui/discussions/21589
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.