From 8c34af303329e80a0c68bd93c214f1808af29d99 Mon Sep 17 00:00:00 2001 From: G30 <50341825+silentoplayz@users.noreply.github.com> Date: Sun, 4 Oct 2026 22:42:55 -0400 Subject: [PATCH] fix: keep private arena models with no access grants visible to admins without the admin bypass (#31858) --- backend/open_webui/routers/models.py | 7 +++++-- backend/open_webui/utils/models.py | 15 +++++++++------ 2 files changed, 14 insertions(+), 8 deletions(-) diff --git a/backend/open_webui/routers/models.py b/backend/open_webui/routers/models.py index e8426b1dae..f02abd5615 100644 --- a/backend/open_webui/routers/models.py +++ b/backend/open_webui/routers/models.py @@ -809,8 +809,11 @@ async def get_model_profile_image( for arena_model in arena_models: if arena_model.get('id') == id: arena_meta = arena_model.get('meta', {}) - if bypass_access_control or await has_access( - user.id, permission='read', access_grants=arena_meta.get('access_grants', []), db=db + access_grants = arena_meta.get('access_grants', []) + if ( + bypass_access_control + or (not access_grants and user.role == 'admin') + or await has_access(user.id, permission='read', access_grants=access_grants, db=db) ): profile_image_url = arena_meta.get('profile_image_url') break diff --git a/backend/open_webui/utils/models.py b/backend/open_webui/utils/models.py index 778441de48..2d968172a7 100644 --- a/backend/open_webui/utils/models.py +++ b/backend/open_webui/utils/models.py @@ -476,11 +476,14 @@ async def check_model_access(user, model, model_info=None, db=None): if model.get('arena'): meta = model.get('info', {}).get('meta', {}) access_grants = meta.get('access_grants', []) - if not await has_access( - user.id, - permission='read', - access_grants=access_grants, - db=db, + if not ( + (not access_grants and user.role == 'admin') + or await has_access( + user.id, + permission='read', + access_grants=access_grants, + db=db, + ) ): log.warning( 'Model access denied: user_id=%r model_id=%r reason=arena_read_denied', @@ -561,7 +564,7 @@ async def get_filtered_models(models, user, db=None): if model.get('arena'): meta = model.get('info', {}).get('meta', {}) access_grants = meta.get('access_grants', []) - if await has_access( + if (not access_grants and user.role == 'admin') or await has_access( user.id, permission='read', access_grants=access_grants,