diff --git a/CHANGELOG.md b/CHANGELOG.md index c7564011ca..eef662c577 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,6 +28,20 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - ๐Ÿ“ก **Channels permission for live messages and automations.** Users without the Channels permission no longer receive live channel messages, and an automation that posts into a channel no longer runs once its creator has lost that permission. [#31578](https://github.com/open-webui/open-webui/pull/31578), [#31577](https://github.com/open-webui/open-webui/pull/31577) - ๐Ÿซฅ **Temporary chats leave no sub-agent chats.** Temporary chats no longer offer the model sub-agents or timers, whose conversations were saved on the server although a temporary chat should leave nothing behind. [#31573](https://github.com/open-webui/open-webui/pull/31573), [#31567](https://github.com/open-webui/open-webui/issues/31567) - ๐Ÿงพ **Passwords kept out of the audit log.** With request auditing on, a new password from a password change and passwords typed into admin settings such as YaCy or Jupyter are now masked in the audit log, where only fields named exactly "password" were. [#31622](https://github.com/open-webui/open-webui/pull/31622) +- ๐Ÿ‘๏ธ **Cloning shared chats checks access first.** Cloning a shared chat now checks access to the share before its content is read, the same order the shared chat view uses. [#30388](https://github.com/open-webui/open-webui/pull/30388) +- ๐Ÿ“ **Files attached to folders.** Files attached to a folder when it is created, or newly added by someone editing a shared folder, are now checked against that person's own access, so a folder can no longer be used to reach files they cannot open. [#30442](https://github.com/open-webui/open-webui/pull/30442) +- ๐Ÿšช **Removed channel members stop receiving messages.** Removing someone from a group channel now also disconnects their open sessions from it, so they stop receiving its live messages right away. [#30446](https://github.com/open-webui/open-webui/pull/30446) +- ๐Ÿ—๏ธ **Stronger generated secret key.** The secret key Open WebUI generates when "WEBUI_SECRET_KEY" is not set now comes from a cryptographically secure random source. [#30441](https://github.com/open-webui/open-webui/pull/30441) +- ๐ŸŒ **Wildcard searches on SQLite.** Searches on SQLite can no longer tie up the server with a search term full of wildcards, which could make matching take exponentially long. [#30393](https://github.com/open-webui/open-webui/pull/30393) +- ๐ŸŒ€ **Message cleanup for background tasks.** Cleaning details blocks and images out of messages before titles, tags and follow-ups are generated can no longer stall on crafted message content. [#30394](https://github.com/open-webui/open-webui/pull/30394) +- ๐Ÿ—ƒ๏ธ **Live document saves limited to notes.** Live collaborative edits are now only saved for note documents, the only documents that have a save handler. [#30395](https://github.com/open-webui/open-webui/pull/30395) +- ๐Ÿ›‘ **Sub-agent results after a role change.** A chat now only continues with a finished sub-agent's result while its owner still has an active role, the same check timers already make, so a deactivated or pending account no longer keeps generating replies. [#31451](https://github.com/open-webui/open-webui/pull/31451) +- ๐Ÿ”— **Only safe file links open.** File attachment links and file links in code execution results now open only web, mail, phone and relative links, the same check links in chat messages go through. [#31491](https://github.com/open-webui/open-webui/pull/31491) +- ๐ŸŽ›๏ธ **Tool approval mode no longer restored from drafts.** Restoring a saved message draft no longer switches the chat's tool approval mode, which could save settings and approve tools without asking. [Commit](https://github.com/open-webui/open-webui/commit/332237662f446f8264cd4db10a1b4513ba5fb76b) +- ๐Ÿงฑ **Safety checks for generated image downloads.** When an image generation backend returns a link instead of the image, the download now goes through the same safety checks as other external image downloads, while links on the configured ComfyUI address stay trusted. [#31623](https://github.com/open-webui/open-webui/pull/31623) +- ๐ŸŽซ **Login check when loading the app settings.** Loading the app's settings now uses the same login check as every other request, so a session that is no longer valid only gets the logged-out settings. [#31621](https://github.com/open-webui/open-webui/pull/31621) +- ๐Ÿ“ **Notes permission for live note editing.** Opening a note for live collaborative editing now requires the Notes permission, like the rest of the Notes feature. [#31552](https://github.com/open-webui/open-webui/pull/31552) +- ๐Ÿ“† **Calendar tools check calendar access.** Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does. [#31537](https://github.com/open-webui/open-webui/pull/31537) - ๐Ÿ”‘ **OAuth sessions survive parallel requests.** Chatting through a connection that forwards your single sign-on token no longer logs your OAuth session out when two requests renew an expiring token at once against a provider that rotates refresh tokens, including requests handled by different workers or replicas sharing Redis, which previously cost every following request its token until you signed in again. [#30426](https://github.com/open-webui/open-webui/pull/30426), [#30450](https://github.com/open-webui/open-webui/pull/30450), [#30416](https://github.com/open-webui/open-webui/issues/30416) - ๐Ÿชช **Token exchange group mapping.** With OAuth group mapping on, signing in through token exchange now assigns groups from the token's own groups claim when the provider's user info leaves it out, as it already did for roles. [Commit](https://github.com/open-webui/open-webui/commit/f412538756f745b531036840bc0a153e62b0f003) - ๐Ÿงฑ **Blocked OAuth groups not created.** With automatic group creation on, groups matching "OAUTH_BLOCKED_GROUPS" are no longer created at sign-in, where a provider sending a user's full directory membership could fill the groups list with thousands of empty groups. [#31316](https://github.com/open-webui/open-webui/pull/31316), [#29558](https://github.com/open-webui/open-webui/issues/29558)