[GH-ISSUE #22300] issue: Security / Folder permissions in Groups are ignored #58358

Closed
opened 2026-05-05 23:00:48 -05:00 by GiteaMirror · 1 comment
Owner

Originally created by @schoenbi on GitHub (Mar 6, 2026).
Original GitHub issue: https://github.com/open-webui/open-webui/issues/22300

Check Existing Issues

  • I have searched for any existing and/or related issues.
  • I have searched for any existing and/or related discussions.
  • I have also searched in the CLOSED issues AND CLOSED discussions and found no related items (your issue might already be addressed on the development branch!).
  • I am using the latest version of Open WebUI.

Installation Method

Docker

Open WebUI Version

v0.8.8

Ollama Version (if applicable)

No response

Operating System

Ubuntu 22.04

Browser (if applicable)

Firefox, Safari, Edge

Confirmation

  • I have read and followed all instructions in README.md.
  • I am using the latest version of both Open WebUI and Ollama.
  • I have included the browser console logs.
  • I have included the Docker container logs.
  • I have provided every relevant configuration, setting, and environment variable used in my setup.
  • I have clearly listed every relevant configuration, custom setting, environment variable, and command-line option that influences my setup (such as Docker Compose overrides, .env values, browser settings, authentication configurations, etc).
  • I have documented step-by-step reproduction instructions that are precise, sequential, and leave nothing to interpretation. My steps:
  • Start with the initial platform/version/OS and dependencies used,
  • Specify exact install/launch/configure commands,
  • List URLs visited, user input (incl. example values/emails/passwords if needed),
  • Describe all options and toggles enabled or changed,
  • Include any files or environmental changes,
  • Identify the expected and actual result at each stage,
  • Ensure any reasonably skilled user can follow and hit the same issue.

Expected Behavior

  1. I create a Group G-A and assign a User U-a to it.
  2. I turn off the Folder Permission in the Default Permission Section
  3. I turn on the Folder Permission in the Group G-A Permission Section
  4. User U-a should see the Folder functionality in the sidebar

Actual Behavior

Following instructions 1-3 from above
4. User U-a does not see the Folder functionality in the sidebar

Either the Folder functionality is available for everbody or nobody (except the Administrator)

Steps to Reproduce

See above

Logs & Screenshots

The description is self-explanatory

Additional Information

No response

Originally created by @schoenbi on GitHub (Mar 6, 2026). Original GitHub issue: https://github.com/open-webui/open-webui/issues/22300 ### Check Existing Issues - [x] I have searched for any existing and/or related issues. - [x] I have searched for any existing and/or related discussions. - [x] I have also searched in the CLOSED issues AND CLOSED discussions and found no related items (your issue might already be addressed on the development branch!). - [x] I am using the latest version of Open WebUI. ### Installation Method Docker ### Open WebUI Version v0.8.8 ### Ollama Version (if applicable) _No response_ ### Operating System Ubuntu 22.04 ### Browser (if applicable) Firefox, Safari, Edge ### Confirmation - [x] I have read and followed all instructions in `README.md`. - [x] I am using the latest version of **both** Open WebUI and Ollama. - [x] I have included the browser console logs. - [x] I have included the Docker container logs. - [x] I have **provided every relevant configuration, setting, and environment variable used in my setup.** - [x] I have clearly **listed every relevant configuration, custom setting, environment variable, and command-line option that influences my setup** (such as Docker Compose overrides, .env values, browser settings, authentication configurations, etc). - [x] I have documented **step-by-step reproduction instructions that are precise, sequential, and leave nothing to interpretation**. My steps: - Start with the initial platform/version/OS and dependencies used, - Specify exact install/launch/configure commands, - List URLs visited, user input (incl. example values/emails/passwords if needed), - Describe all options and toggles enabled or changed, - Include any files or environmental changes, - Identify the expected and actual result at each stage, - Ensure any reasonably skilled user can follow and hit the same issue. ### Expected Behavior 1. I create a Group G-A and assign a User U-a to it. 2. I turn off the Folder Permission in the Default Permission Section 3. I turn on the Folder Permission in the Group G-A Permission Section 4. User U-a should see the Folder functionality in the sidebar ### Actual Behavior Following instructions 1-3 from above 4. User U-a does not see the Folder functionality in the sidebar Either the Folder functionality is available for everbody or nobody (except the Administrator) ### Steps to Reproduce See above ### Logs & Screenshots The description is self-explanatory ### Additional Information _No response_
GiteaMirror added the bug label 2026-05-05 23:00:48 -05:00
Author
Owner

@Classic298 commented on GitHub (Mar 6, 2026):

Cannot reproduce, I followed your steps to reproduce precisely and user 1 in my test still has access to folders

https://github.com/user-attachments/assets/94c8ed2b-dc6b-4a72-bee2-99a2c938b284

<!-- gh-comment-id:4010563186 --> @Classic298 commented on GitHub (Mar 6, 2026): Cannot reproduce, I followed your steps to reproduce precisely and user 1 in my test still has access to folders https://github.com/user-attachments/assets/94c8ed2b-dc6b-4a72-bee2-99a2c938b284
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#58358