From 42cd4f0ec0569797edef36b97229735b8d01d024 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Sat, 26 Sep 2026 05:20:14 +0200 Subject: [PATCH] refactor: check shared chat access before loading the snapshot on clone (#30388) The clone endpoint now resolves and checks the share before reading its snapshot, matching the order used by the shared chat view endpoint. --- backend/open_webui/routers/chats.py | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/backend/open_webui/routers/chats.py b/backend/open_webui/routers/chats.py index 7138dc9f21..e46fed259c 100644 --- a/backend/open_webui/routers/chats.py +++ b/backend/open_webui/routers/chats.py @@ -1848,18 +1848,6 @@ async def clone_shared_chat_by_id( ): await require_chat_import_permission(request, user, db) - chat = await Chats.get_chat_by_share_id(id, db=db) - - # Fallback: admins can also access any chat directly by chat ID - if not chat and user.role == 'admin' and ENABLE_ADMIN_CHAT_ACCESS: - chat = await Chats.get_chat_by_id(id, db=db) - - if not chat: - raise HTTPException( - status_code=status.HTTP_401_UNAUTHORIZED, - detail=ERROR_MESSAGES.NOT_FOUND, - ) - # Enforce access grants (owner and admins bypass) shared = await SharedChats.get_by_id(id, db=db) if shared and user.role != 'admin' and shared.user_id != user.id: @@ -1876,6 +1864,18 @@ async def clone_shared_chat_by_id( detail=ERROR_MESSAGES.ACCESS_PROHIBITED, ) + chat = await Chats.get_chat_by_share_id(id, db=db) if shared else None + + # Fallback: admins can also access any chat directly by chat ID + if not chat and user.role == 'admin' and ENABLE_ADMIN_CHAT_ACCESS: + chat = await Chats.get_chat_by_id(id, db=db) + + if not chat: + raise HTTPException( + status_code=status.HTTP_401_UNAUTHORIZED, + detail=ERROR_MESSAGES.NOT_FOUND, + ) + updated_chat = { **chat.chat, 'originalChatId': chat.id,