diff --git a/backend/open_webui/routers/channels.py b/backend/open_webui/routers/channels.py index c9d38bf2ce..2a16e23be2 100644 --- a/backend/open_webui/routers/channels.py +++ b/backend/open_webui/routers/channels.py @@ -642,6 +642,9 @@ async def add_members_by_id( if channel.user_id != user.id and user.role != 'admin': raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + if channel.type == 'dm': + raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + try: memberships = await Channels.add_members_to_channel( channel.id, user.id, form_data.user_ids, form_data.group_ids, db=db @@ -686,9 +689,12 @@ async def remove_members_by_id( if channel.user_id != user.id and user.role != 'admin': raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + if channel.type == 'dm': + raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + try: deleted = await Channels.remove_members_from_channel(channel.id, form_data.user_ids, db=db) - if channel.type in ['group', 'dm']: + if channel.type == 'group': await leave_room_for_users(f'channel:{channel.id}', form_data.user_ids) await publish_event(