From 7f3749ed6b2f4aa4a9dd1ace3234f466852105db Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Sat, 10 Oct 2026 18:01:41 +0200 Subject: [PATCH] fix: user created in the same second as the first admin takes over its protection (#32157) Account creation times are stored in whole seconds. On Postgres, a user created in the same second as the first admin, which is normal when a script sets up an instance, could be picked as the primary admin. Other admins could then demote or delete the real first admin, nobody could edit, lock or delete that user, and pending users were shown that user as the admin contact. An admin account now wins a same-second tie against a regular one. --- backend/open_webui/models/users.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/backend/open_webui/models/users.py b/backend/open_webui/models/users.py index 26106859ae..6a46388bb0 100644 --- a/backend/open_webui/models/users.py +++ b/backend/open_webui/models/users.py @@ -709,7 +709,9 @@ class UsersTable: async def get_first_user(self, db: AsyncSession | None = None) -> UserModel | None: """Return the earliest-created user (bootstrap admin detection).""" async with get_async_db_context(db) as session: - stmt = select(User).order_by(User.created_at).limit(1) + # created_at has 1s resolution; admin wins ties + admin_first = case((User.role == 'admin', 0), else_=1) + stmt = select(User).order_by(User.created_at, admin_first, User.id).limit(1) row = (await session.execute(stmt)).scalars().first() return UserModel.model_validate(row) if row else None