mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-06 02:48:04 +00:00
fix: members can be added to or removed from a direct message through the API (#31575)
The person who started a direct message could add or remove people through the API, although the app only offers this in group channels. Someone added this way could read the whole earlier conversation, and because the original pair no longer matched the conversation, their next message opened a second, empty direct message. Changing the members of a direct message now answers with a 403. Fixes #31570
This commit is contained in:
parent
fa66b0f306
commit
3d70d43a1c
1 changed files with 7 additions and 1 deletions
|
|
@ -642,6 +642,9 @@ async def add_members_by_id(
|
|||
if channel.user_id != user.id and user.role != 'admin':
|
||||
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
|
||||
|
||||
if channel.type == 'dm':
|
||||
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
|
||||
|
||||
try:
|
||||
memberships = await Channels.add_members_to_channel(
|
||||
channel.id, user.id, form_data.user_ids, form_data.group_ids, db=db
|
||||
|
|
@ -686,9 +689,12 @@ async def remove_members_by_id(
|
|||
if channel.user_id != user.id and user.role != 'admin':
|
||||
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
|
||||
|
||||
if channel.type == 'dm':
|
||||
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
|
||||
|
||||
try:
|
||||
deleted = await Channels.remove_members_from_channel(channel.id, form_data.user_ids, db=db)
|
||||
if channel.type in ['group', 'dm']:
|
||||
if channel.type == 'group':
|
||||
await leave_room_for_users(f'channel:{channel.id}', form_data.user_ids)
|
||||
|
||||
await publish_event(
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue