From 9b45bedeaf9b7aefa91c2ce0538ba8c46410ba9e Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:02:37 +0200 Subject: [PATCH] fix: check the Channels permission when a channel automation runs (#31577) An automation that posts into a channel now only runs when the user who created it has the Channels permission. --- backend/open_webui/utils/automations.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/backend/open_webui/utils/automations.py b/backend/open_webui/utils/automations.py index be5d6868f1..d6c0f4dfe4 100644 --- a/backend/open_webui/utils/automations.py +++ b/backend/open_webui/utils/automations.py @@ -261,6 +261,13 @@ async def _execute_channel_automation( if not channel_id or not await Config.get('channels.enable'): raise ValueError('Channel not found') + from open_webui.utils.access_control import has_permission + + if user.role != 'admin' and not await has_permission( + user.id, 'features.channels', await Config.get('user.permissions') + ): + raise ValueError('Owner no longer permitted to use channels') + model = getattr(app.state, 'MODELS', {}).get(model_id, {}) request = _build_request(app, token=token)