[PR #23635] [CLOSED] fix: block knowledge-bases meta-collection enumeration and enforce KB read access on query endpoints #66148

Closed
opened 2026-05-06 12:18:58 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/open-webui/open-webui/pull/23635
Author: @Classic298
Created: 4/12/2026
Status: Closed

Base: devHead: fix/kb-meta-collection-enumeration


📝 Commits (3)

  • df39e3f fix: block knowledge-bases meta-collection enumeration and enforce KB read access on query endpoints
  • 4fa3229 merge: resolve conflicts with upstream async DB migration
  • f561d1a fix: adapt _validate_collection_access to async DB layer

📊 Changes

1 file changed (+53 additions, -4 deletions)

View changed files

📝 backend/open_webui/routers/retrieval.py (+53 -4)

📄 Description

The _validate_collection_access function only blocked user-memory-* and file-* patterns, allowing any authenticated user to query the knowledge-bases meta-collection to discover all KB UUIDs, names, and descriptions across the entire instance.

Blocks access to the knowledge-bases meta-collection for non-admins. Also enforces KB ownership and AccessGrants read permission checks on KB-ID collections via the query/doc and query/collection endpoints.

Contributor License Agreement

Note

Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/open-webui/open-webui/pull/23635 **Author:** [@Classic298](https://github.com/Classic298) **Created:** 4/12/2026 **Status:** ❌ Closed **Base:** `dev` ← **Head:** `fix/kb-meta-collection-enumeration` --- ### 📝 Commits (3) - [`df39e3f`](https://github.com/open-webui/open-webui/commit/df39e3f9cf7395dccac4f6cfb575956401f29218) fix: block knowledge-bases meta-collection enumeration and enforce KB read access on query endpoints - [`4fa3229`](https://github.com/open-webui/open-webui/commit/4fa3229051180bd4aba82289365c97dfb2f23e29) merge: resolve conflicts with upstream async DB migration - [`f561d1a`](https://github.com/open-webui/open-webui/commit/f561d1ab6264103d77a9d5458e063f9ce6afc373) fix: adapt _validate_collection_access to async DB layer ### 📊 Changes **1 file changed** (+53 additions, -4 deletions) <details> <summary>View changed files</summary> 📝 `backend/open_webui/routers/retrieval.py` (+53 -4) </details> ### 📄 Description The _validate_collection_access function only blocked user-memory-* and file-* patterns, allowing any authenticated user to query the knowledge-bases meta-collection to discover all KB UUIDs, names, and descriptions across the entire instance. Blocks access to the knowledge-bases meta-collection for non-admins. Also enforces KB ownership and AccessGrants read permission checks on KB-ID collections via the query/doc and query/collection endpoints. ### Contributor License Agreement <!-- 🚨 DO NOT DELETE THE TEXT BELOW 🚨 Keep the "Contributor License Agreement" confirmation text intact. Deleting it will trigger the CLA-Bot to INVALIDATE your PR. Your PR will NOT be reviewed or merged until you check the box below confirming that you have read and agree to the terms of the CLA. --> - [X] By submitting this pull request, I confirm that I have read and fully agree to the [Contributor License Agreement (CLA)](https://github.com/open-webui/open-webui/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT), and I am providing my contributions under its terms. > [!NOTE] > Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in. --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-05-06 12:18:58 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#66148