From 297369b195b1a65cba8e651a855d83a1dce2fa83 Mon Sep 17 00:00:00 2001 From: DrMelone <27028174+Classic298@users.noreply.github.com> Date: Sun, 12 Apr 2026 22:51:45 +0200 Subject: [PATCH] fix: await has_connection_access to prevent authorization bypass --- backend/open_webui/tools/builtin.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/backend/open_webui/tools/builtin.py b/backend/open_webui/tools/builtin.py index b8ba62cb89..08aed33aa0 100644 --- a/backend/open_webui/tools/builtin.py +++ b/backend/open_webui/tools/builtin.py @@ -2894,7 +2894,7 @@ async def upload_file_to_terminal( ) if connection: - if not has_connection_access(UserModel(**__user__), connection): + if not await has_connection_access(UserModel(**__user__), connection): return json.dumps({'error': 'Access denied to terminal server'}) terminal_url = connection.get('url', '').rstrip('/') @@ -2916,7 +2916,7 @@ async def upload_file_to_terminal( headers['Authorization'] = f'Bearer {__request__.state.token.credentials}' elif auth_type == 'system_oauth': cookies = __request__.cookies - oauth_token = (metadata.get('oauth_token') or {}) + oauth_token = metadata.get('oauth_token') or {} if oauth_token.get('access_token'): headers['Authorization'] = f'Bearer {oauth_token["access_token"]}' # auth_type == 'none': no Authorization header