From 6f27df88d58ac7649d1f484b5de0db440a72e4a0 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Thu, 14 May 2026 21:57:51 +0200 Subject: [PATCH] chore: trim verbose comment on channel: branch gate --- backend/open_webui/main.py | 10 ++-------- 1 file changed, 2 insertions(+), 8 deletions(-) diff --git a/backend/open_webui/main.py b/backend/open_webui/main.py index aa9c5e5336..dacdcda172 100644 --- a/backend/open_webui/main.py +++ b/backend/open_webui/main.py @@ -1800,14 +1800,8 @@ async def chat_completion( if metadata.get('chat_id') and user: chat_id = metadata['chat_id'] - # channel: chat_ids skip the chat ownership / storage block below, - # but the channel-emitter ultimately writes to a Messages row by - # the caller-supplied message_id. Without a gate here, any auth - # user could supply chat_id="channel:" + id="" and - # overwrite arbitrary messages in arbitrary channels (private, - # DM, channels they don't belong to). Enforce: caller must be - # able to write in the target channel, AND the supplied message - # must belong to that channel. + # Gate channel: branch — caller needs write access on the channel + # and the supplied message_id must belong to that channel. if chat_id.startswith('channel:'): channel_id = chat_id.removeprefix('channel:') channel = await Channels.get_channel_by_id(channel_id)