From b36e55cf1ff1907fedebeff1940226719d4c60fc Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Tue, 24 Feb 2026 13:27:48 -0600 Subject: [PATCH 001/149] refac --- src/lib/components/chat/Navbar.svelte | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/lib/components/chat/Navbar.svelte b/src/lib/components/chat/Navbar.svelte index 6dcdd34413..7e0b540a06 100644 --- a/src/lib/components/chat/Navbar.svelte +++ b/src/lib/components/chat/Navbar.svelte @@ -107,7 +107,7 @@ {/if}
From 64ec73635b5a84b57164107e3c240c53f48e2103 Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Tue, 24 Feb 2026 14:47:28 -0600 Subject: [PATCH 002/149] refac --- backend/open_webui/utils/security_headers.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/backend/open_webui/utils/security_headers.py b/backend/open_webui/utils/security_headers.py index fbcf7d6977..3b31c2c05c 100644 --- a/backend/open_webui/utils/security_headers.py +++ b/backend/open_webui/utils/security_headers.py @@ -28,6 +28,7 @@ def set_security_headers() -> Dict[str, str]: - x-frame-options - x-permitted-cross-domain-policies - content-security-policy + - reporting-endpoints Each environment variable is associated with a specific setter function that constructs the header. If the environment variable is set, the @@ -47,6 +48,7 @@ def set_security_headers() -> Dict[str, str]: "XFRAME_OPTIONS": set_xframe, "XPERMITTED_CROSS_DOMAIN_POLICIES": set_xpermitted_cross_domain_policies, "CONTENT_SECURITY_POLICY": set_content_security_policy, + "REPORTING_ENDPOINTS": set_reporting_endpoints, } for env_var, setter in header_setters.items(): @@ -131,3 +133,8 @@ def set_xpermitted_cross_domain_policies(value: str): # Set Content-Security-Policy response header def set_content_security_policy(value: str): return {"Content-Security-Policy": value} + + +# Set Reporting-Endpoints response header +def set_reporting_endpoints(value: str): + return {"Reporting-Endpoints": value} From 0b6c92baa702e3cf46ced54cb726e8efa0a6ee83 Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Tue, 24 Feb 2026 14:57:59 -0600 Subject: [PATCH 003/149] refac --- .../admin/Settings/Models/ModelList.svelte | 38 ++++++++++++++----- 1 file changed, 29 insertions(+), 9 deletions(-) diff --git a/src/lib/components/admin/Settings/Models/ModelList.svelte b/src/lib/components/admin/Settings/Models/ModelList.svelte index d501a485d4..d6ad88a7db 100644 --- a/src/lib/components/admin/Settings/Models/ModelList.svelte +++ b/src/lib/components/admin/Settings/Models/ModelList.svelte @@ -1,7 +1,7 @@ {#if modelIds.length > 0}
- {#each modelIds as modelId, modelIdx (`${modelId}-${modelIdx}`)} + {#each modelIds as modelId (modelId)}
From 538501c88da034434bcd1969f15341dbbaf154e4 Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Tue, 24 Feb 2026 15:19:49 -0600 Subject: [PATCH 004/149] refac --- backend/open_webui/config.py | 11 ++++++++++ backend/open_webui/models/groups.py | 21 ++++++++++++++++++- .../admin/Users/Groups/General.svelte | 2 +- 3 files changed, 32 insertions(+), 2 deletions(-) diff --git a/backend/open_webui/config.py b/backend/open_webui/config.py index b276f9de90..5c45b9f35a 100644 --- a/backend/open_webui/config.py +++ b/backend/open_webui/config.py @@ -1287,6 +1287,17 @@ DEFAULT_GROUP_ID = PersistentConfig( os.environ.get("DEFAULT_GROUP_ID", ""), ) +# Controls the default "Who can share to this group" setting for new groups. +# Env var values: "true" (anyone), "false" (no one), "members" (only group members). +_default_group_share = os.environ.get( + "DEFAULT_GROUP_SHARE_PERMISSION", "members" +).strip().lower() +DEFAULT_GROUP_SHARE_PERMISSION = ( + "members" + if _default_group_share == "members" + else _default_group_share == "true" +) + PENDING_USER_OVERLAY_TITLE = PersistentConfig( "PENDING_USER_OVERLAY_TITLE", "ui.pending_user_overlay_title", diff --git a/backend/open_webui/models/groups.py b/backend/open_webui/models/groups.py index c9a38f1ede..ff6d61b929 100644 --- a/backend/open_webui/models/groups.py +++ b/backend/open_webui/models/groups.py @@ -6,6 +6,7 @@ import uuid from sqlalchemy.orm import Session from open_webui.internal.db import Base, JSONField, get_db, get_db_context +from open_webui.config import DEFAULT_GROUP_SHARE_PERMISSION from open_webui.models.files import FileMetadataResponse @@ -130,13 +131,26 @@ class GroupListResponse(BaseModel): class GroupTable: + def _ensure_default_share_config(self, group_data: dict) -> dict: + """Ensure the group data dict has a default share config if not already set.""" + if "data" not in group_data or group_data["data"] is None: + group_data["data"] = {} + if "config" not in group_data["data"]: + group_data["data"]["config"] = {} + if "share" not in group_data["data"]["config"]: + group_data["data"]["config"]["share"] = DEFAULT_GROUP_SHARE_PERMISSION + return group_data + def insert_new_group( self, user_id: str, form_data: GroupForm, db: Optional[Session] = None ) -> Optional[GroupModel]: with get_db_context(db) as db: + group_data = self._ensure_default_share_config( + form_data.model_dump(exclude_none=True) + ) group = GroupModel( **{ - **form_data.model_dump(exclude_none=True), + **group_data, "id": str(uuid.uuid4()), "user_id": user_id, "created_at": int(time.time()), @@ -504,6 +518,11 @@ class GroupTable: user_id=user_id, name=group_name, description="", + data={ + "config": { + "share": DEFAULT_GROUP_SHARE_PERMISSION, + } + }, created_at=int(time.time()), updated_at=int(time.time()), ) diff --git a/src/lib/components/admin/Users/Groups/General.svelte b/src/lib/components/admin/Users/Groups/General.svelte index 4d32b3148b..16a04acd06 100644 --- a/src/lib/components/admin/Users/Groups/General.svelte +++ b/src/lib/components/admin/Users/Groups/General.svelte @@ -78,7 +78,7 @@
+
+
+
+ +
+
+
+ +
+ +
+ +
+
+
+ + + + {#if showAdvanced} +
+
+
+
+
+ {$i18n.t('OpenAPI Spec')} +
+
+
+ +
+
+
+ + +
+
+
+ +
+ {$i18n.t(`WebUI will make requests to "{{url}}"`, { + url: path.includes('://') + ? path + : `${url}${path.startsWith('/') ? '' : '/'}${path}` + })} +
+
+
+ {/if} + +
+
+
+
+
+ {$i18n.t('Auth')} +
+
+
+ +
+
+ +
+ +
+ {#if auth_type === 'bearer'} + + {:else if auth_type === 'none'} +
+ {$i18n.t('No authentication')} +
+ {:else if auth_type === 'session'} +
+ {$i18n.t('Forwards system user session credentials to authenticate')} +
+ {/if} +
+
+
+
+ +
+
+
+ {#if edit} + + {/if} + + +
+
+
+ +
+ + + diff --git a/src/lib/components/AddToolServerModal.svelte b/src/lib/components/AddToolServerModal.svelte index 878fcc5264..aac8f71ee1 100644 --- a/src/lib/components/AddToolServerModal.svelte +++ b/src/lib/components/AddToolServerModal.svelte @@ -542,80 +542,80 @@ {#if showAdvanced} - {#if ['', 'openapi'].includes(type)} -
-
-
-
-
- {$i18n.t('OpenAPI Spec')} + {#if ['', 'openapi'].includes(type)} +
+
+
+
+
+ {$i18n.t('OpenAPI Spec')} +
-
-
-
- -
- -
- {#if spec_type === 'url'} -
- - -
- {:else if spec_type === 'json'} -
+
+