fix: check the Channels permission when a channel automation runs (#31577)

An automation that posts into a channel now only runs when the user who created it has the Channels permission.
This commit is contained in:
Classic298 2026-09-30 17:02:37 +02:00 • committed by GitHub
parent 028dab8f1f
commit 9b45bedeaf
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -261,6 +261,13 @@ async def _execute_channel_automation(
if not channel_id or not await Config.get('channels.enable'):
raise ValueError('Channel not found')
from open_webui.utils.access_control import has_permission
if user.role != 'admin' and not await has_permission(
user.id, 'features.channels', await Config.get('user.permissions')
):
raise ValueError('Owner no longer permitted to use channels')
model = getattr(app.state, 'MODELS', {}).get(model_id, {})
request = _build_request(app, token=token)