From 3d70d43a1c929f6bb8162a82feba8facb396794e Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:03:32 +0200 Subject: [PATCH] fix: members can be added to or removed from a direct message through the API (#31575) The person who started a direct message could add or remove people through the API, although the app only offers this in group channels. Someone added this way could read the whole earlier conversation, and because the original pair no longer matched the conversation, their next message opened a second, empty direct message. Changing the members of a direct message now answers with a 403. Fixes #31570 --- backend/open_webui/routers/channels.py | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/backend/open_webui/routers/channels.py b/backend/open_webui/routers/channels.py index c9d38bf2ce..2a16e23be2 100644 --- a/backend/open_webui/routers/channels.py +++ b/backend/open_webui/routers/channels.py @@ -642,6 +642,9 @@ async def add_members_by_id( if channel.user_id != user.id and user.role != 'admin': raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + if channel.type == 'dm': + raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + try: memberships = await Channels.add_members_to_channel( channel.id, user.id, form_data.user_ids, form_data.group_ids, db=db @@ -686,9 +689,12 @@ async def remove_members_by_id( if channel.user_id != user.id and user.role != 'admin': raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + if channel.type == 'dm': + raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT()) + try: deleted = await Channels.remove_members_from_channel(channel.id, form_data.user_ids, db=db) - if channel.type in ['group', 'dm']: + if channel.type == 'group': await leave_room_for_users(f'channel:{channel.id}', form_data.user_ids) await publish_event(