From 2062231f9cd69ea62556ec7682b7c673cf08987a Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:09:34 +0200 Subject: [PATCH] fix: apply the usual login check when the app loads its settings (#31621) Loading the app's settings now uses the same login check as every other request, so a session that is no longer valid gets the logged-out settings. --- backend/open_webui/main.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/backend/open_webui/main.py b/backend/open_webui/main.py index ecba6407f3..da2eea353d 100644 --- a/backend/open_webui/main.py +++ b/backend/open_webui/main.py @@ -221,6 +221,7 @@ from open_webui.utils.auth import ( get_http_authorization_cred, get_license_data, get_verified_user, + is_valid_token, ) from open_webui.utils.chat import ( chat_completed as chat_completed_handler, @@ -2242,7 +2243,7 @@ async def get_app_config(request: Request): status_code=status.HTTP_401_UNAUTHORIZED, detail='Invalid token', ) - if data is not None and 'id' in data: + if data is not None and 'id' in data and await is_valid_token(data, request.app.state.redis): user = await Users.get_user_by_id(data['id']) onboarding = False