mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 10:58:17 -05:00
[PR #23719] [CLOSED] fix: add missing db parameter to filter_allowed_access_grants in update_note_access_by_id #50380
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/23719
Author: @Ricardo-M-L
Created: 4/14/2026
Status: ❌ Closed
Base:
dev← Head:fix/notes-missing-db-param📝 Commits (10+)
fe6783cMerge pull request #19030 from open-webui/devfc05e0aMerge pull request #19405 from open-webui/deve3faec6Merge pull request #19416 from open-webui/dev9899293Merge pull request #19448 from open-webui/dev140605eMerge pull request #19462 from open-webui/dev6f1486fMerge pull request #19466 from open-webui/devd95f533Merge pull request #19729 from open-webui/deva7271530.6.43 (#20093)6adde20Merge pull request #20394 from open-webui/devf9b0534Merge pull request #20522 from open-webui/dev📊 Changes
1 file changed (+1 additions, -0 deletions)
View changed files
📝
backend/open_webui/routers/notes.py(+1 -0)📄 Description
Description
In
update_note_access_by_id()(notes.py:345), the call tofilter_allowed_access_grants()is missing thedb=dbparameter. The identical call inupdate_note_by_id()at line 281 correctly passesdb=db.filter_allowed_access_grants()acceptsdb: Session | None = Noneand uses it for group-based access grant validation. Without it, the function falls back toNone, which may cause incorrect access control behavior when filtering grants.Changelog
dbparameter infilter_allowed_access_grants()call withinupdate_note_access_by_id(), matching the pattern used inupdate_note_by_id().Breaking Changes
Additional Information
db=db,to the function call at line 345 inbackend/open_webui/routers/notes.pyContributor License Agreement
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.