mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-05 02:41:34 +00:00
fix: check the Channels permission when a channel automation runs (#31577)
An automation that posts into a channel now only runs when the user who created it has the Channels permission.
This commit is contained in:
parent
028dab8f1f
commit
9b45bedeaf
1 changed files with 7 additions and 0 deletions
|
|
@ -261,6 +261,13 @@ async def _execute_channel_automation(
|
|||
if not channel_id or not await Config.get('channels.enable'):
|
||||
raise ValueError('Channel not found')
|
||||
|
||||
from open_webui.utils.access_control import has_permission
|
||||
|
||||
if user.role != 'admin' and not await has_permission(
|
||||
user.id, 'features.channels', await Config.get('user.permissions')
|
||||
):
|
||||
raise ValueError('Owner no longer permitted to use channels')
|
||||
|
||||
model = getattr(app.state, 'MODELS', {}).get(model_id, {})
|
||||
request = _build_request(app, token=token)
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue