mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 19:08:59 -05:00
[PR #22430] [CLOSED] fix: public-read access grant should not confer write access to notes #42317
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/22430
Author: @gambletan
Created: 3/8/2026
Status: ❌ Closed
Base:
dev← Head:dev📝 Commits (1)
205b3bcfix: remove incorrect public-read grant from note write_access check📊 Changes
1 file changed (+0 additions, -1 deletions)
View changed files
📝
backend/open_webui/routers/notes.py(+0 -1)📄 Description
Description
has_public_read_access_grant()check was incorrectly included in the write access calculation. This meant that any user with public read access could also gain write access to notes, resulting in a privilege escalation vulnerability.Fixed
has_public_read_access_grant()from the write access logic so that public read access no longer confers write access to notes.Additional Information
Contributor License Agreement
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.