From 52533c567586c363a1baa48e8a5b3c4e20aea115 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:29:19 +0200 Subject: [PATCH] refac: calendar event tools use the calendar's access check (#31537) Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does. --- backend/open_webui/tools/builtin.py | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/backend/open_webui/tools/builtin.py b/backend/open_webui/tools/builtin.py index c1d1b164d6..c974c68b46 100644 --- a/backend/open_webui/tools/builtin.py +++ b/backend/open_webui/tools/builtin.py @@ -4413,10 +4413,10 @@ async def update_calendar_event( return JSONCodec.dumps({'error': 'Event not found'}) # Check write access to the event's calendar - if event.user_id != user_id and __user__.get('role') != 'admin': - cal = await Calendars.get_calendar_by_id(event.calendar_id) - if not cal: - return JSONCodec.dumps({'error': 'Access denied'}) + cal = await Calendars.get_calendar_by_id(event.calendar_id) + if not cal: + return JSONCodec.dumps({'error': 'Access denied'}) + if cal.user_id != user_id and __user__.get('role') != 'admin': user_group_ids = [g.id for g in await Groups.get_groups_by_member_id(user_id)] if not await AccessGrants.has_access( user_id=user_id, @@ -4517,10 +4517,10 @@ async def delete_calendar_event( return JSONCodec.dumps({'error': 'Event not found'}) # Check write access - if event.user_id != user_id and __user__.get('role') != 'admin': - cal = await Calendars.get_calendar_by_id(event.calendar_id) - if not cal: - return JSONCodec.dumps({'error': 'Access denied'}) + cal = await Calendars.get_calendar_by_id(event.calendar_id) + if not cal: + return JSONCodec.dumps({'error': 'Access denied'}) + if cal.user_id != user_id and __user__.get('role') != 'admin': user_group_ids = [g.id for g in await Groups.get_groups_by_member_id(user_id)] if not await AccessGrants.has_access( user_id=user_id,