mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 19:08:59 -05:00
[PR #23029] [CLOSED] fix: tool calls fail for non-admin users due to model access check #65838
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/23029
Author: @yang1002378395-cmyk
Created: 3/25/2026
Status: ❌ Closed
Base:
dev← Head:fix-tool-call-permission-check📝 Commits (10+)
fe6783cMerge pull request #19030 from open-webui/devfc05e0aMerge pull request #19405 from open-webui/deve3faec6Merge pull request #19416 from open-webui/dev9899293Merge pull request #19448 from open-webui/dev140605eMerge pull request #19462 from open-webui/dev6f1486fMerge pull request #19466 from open-webui/devd95f533Merge pull request #19729 from open-webui/deva7271530.6.43 (#20093)6adde20Merge pull request #20394 from open-webui/devf9b0534Merge pull request #20522 from open-webui/dev📊 Changes
1 file changed (+3 additions, -1 deletions)
View changed files
📝
backend/open_webui/utils/middleware.py(+3 -1)📄 Description
Fixes #22851
Pull Request Checklist
Changelog Entry
Description
Fixes a bug where non-admin users tool calls would fail during subsequent response generation due to model access permission checks.
Fixed
Problem
Non-admin users experience tool call failures:
Root Cause
generate_chat_completion() calls check_model_access() to verify model permissions. When non-admin users use tools:
Solution
Add bypass_filter=True to all generate_chat_completion() calls in middleware.py that are for tool decision/response generation.
Changes
Testing
Analyzed the code flow through middleware.py and chat.py to identify the permission check issue. The fix allows internal system calls to bypass model access checks while maintaining security for direct user requests.
Contributor License Agreement
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.