From 6d409da9d290d93129e94becab49230d463aad84 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:19:53 +0200 Subject: [PATCH] refac: apply the Notes permission to live note editing (#31552) Opening a note for live collaborative editing now follows the same Notes permission as the rest of the Notes feature. --- backend/open_webui/socket/main.py | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/backend/open_webui/socket/main.py b/backend/open_webui/socket/main.py index dbfb0f417d..b901c658c4 100644 --- a/backend/open_webui/socket/main.py +++ b/backend/open_webui/socket/main.py @@ -559,6 +559,11 @@ async def join_note(sid, data): if not user: return + if user.role != 'admin' and not await has_permission( + user.id, 'features.notes', await Config.get('user.permissions') + ): + return + note = await Notes.get_note_by_id(data['note_id']) if not note: log.error(f'Note {data["note_id"]} not found for user {user.id}') @@ -692,6 +697,11 @@ async def ydoc_document_join(sid, data): document_id = normalize_document_id(data['document_id']) if document_id.startswith('note:'): + if user.get('role') != 'admin' and not await has_permission( + user.get('id'), 'features.notes', await Config.get('user.permissions') + ): + return + note_id = document_id.split(':')[1] note = await Notes.get_note_by_id(note_id) if not note: