mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-11 03:38:02 +00:00
fix: user created in the same second as the first admin takes over its protection (#32157)
Account creation times are stored in whole seconds. On Postgres, a user created in the same second as the first admin, which is normal when a script sets up an instance, could be picked as the primary admin. Other admins could then demote or delete the real first admin, nobody could edit, lock or delete that user, and pending users were shown that user as the admin contact. An admin account now wins a same-second tie against a regular one.
This commit is contained in:
parent
e056b29685
commit
7f3749ed6b
1 changed files with 3 additions and 1 deletions
|
|
@ -709,7 +709,9 @@ class UsersTable:
|
|||
async def get_first_user(self, db: AsyncSession | None = None) -> UserModel | None:
|
||||
"""Return the earliest-created user (bootstrap admin detection)."""
|
||||
async with get_async_db_context(db) as session:
|
||||
stmt = select(User).order_by(User.created_at).limit(1)
|
||||
# created_at has 1s resolution; admin wins ties
|
||||
admin_first = case((User.role == 'admin', 0), else_=1)
|
||||
stmt = select(User).order_by(User.created_at, admin_first, User.id).limit(1)
|
||||
row = (await session.execute(stmt)).scalars().first()
|
||||
return UserModel.model_validate(row) if row else None
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue