mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-06 02:48:04 +00:00
fix: apply the Channels permission to real-time channel messages (#31578)
Real-time channel messages are now only delivered to users who have the Channels permission set in the admin user permission settings.
This commit is contained in:
parent
e26da43076
commit
028dab8f1f
1 changed files with 9 additions and 4 deletions
|
|
@ -36,6 +36,7 @@ from open_webui.env import (
|
|||
from open_webui.models.access_grants import AccessGrants
|
||||
from open_webui.models.channels import Channels
|
||||
from open_webui.models.chats import Chats
|
||||
from open_webui.models.config import Config
|
||||
from open_webui.models.folders import Folders
|
||||
from open_webui.models.notes import Notes, NoteUpdateForm
|
||||
from open_webui.models.users import UserNameResponse, Users
|
||||
|
|
@ -392,8 +393,12 @@ async def enter_room_for_users(room: str, user_ids: list[str]):
|
|||
user_ids (list[str]): The target user's IDs.
|
||||
"""
|
||||
try:
|
||||
for user_id in user_ids:
|
||||
session_ids = get_session_ids_from_room(f'user:{user_id}')
|
||||
default_permissions = await Config.get('user.permissions')
|
||||
for user in await Users.get_users_by_user_ids(user_ids):
|
||||
if user.role != 'admin' and not await has_permission(user.id, 'features.channels', default_permissions):
|
||||
continue
|
||||
|
||||
session_ids = get_session_ids_from_room(f'user:{user.id}')
|
||||
for sid in session_ids:
|
||||
await sio.enter_room(sid, room)
|
||||
except Exception as e:
|
||||
|
|
@ -501,7 +506,7 @@ async def user_join(sid, data):
|
|||
await sio.enter_room(sid, f'user:{user.id}')
|
||||
|
||||
# Join all the channels only if user has channels permission
|
||||
if user.role == 'admin' or await has_permission(user.id, 'features.channels'):
|
||||
if user.role == 'admin' or await has_permission(user.id, 'features.channels', await Config.get('user.permissions')):
|
||||
channels = await Channels.get_channels_by_user_id(user.id)
|
||||
log.debug('channels=%r', channels)
|
||||
for channel in channels:
|
||||
|
|
@ -533,7 +538,7 @@ async def join_channel(sid, data):
|
|||
return
|
||||
|
||||
# Join all the channels only if user has channels permission
|
||||
if user.role == 'admin' or await has_permission(user.id, 'features.channels'):
|
||||
if user.role == 'admin' or await has_permission(user.id, 'features.channels', await Config.get('user.permissions')):
|
||||
channels = await Channels.get_channels_by_user_id(user.id)
|
||||
log.debug('channels=%r', channels)
|
||||
for channel in channels:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue