docs: correct automation and sub-agent session entry

This commit is contained in:
Classic298 2026-10-05 09:23:52 +00:00
parent e744bd6df1
commit cc23d7626e
No known key found for this signature in database

View file

@ -59,7 +59,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- ⛓️ **Live connections end with the session.** A browser's live connection is now checked every 30 seconds and closed once its sign-in has been revoked or has expired, where it kept receiving updates. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226)
- 🤐 **Sign-in requests kept out of the audit log.** With request auditing on, the bodies of authentication and OAuth requests and their responses, such as sign-in, password changes and API key creation, are no longer written to the audit log. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226)
- 🛂 **Forwarded headers trust for open-webui serve.** Starting Open WebUI with "open-webui serve" or "open-webui dev" now honors "FORWARDED_ALLOW_IPS", where it trusted forwarded headers from every connection regardless of the setting. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226)
- 🤖 **Automations and sub-agents of deactivated accounts.** Automations and sub-agents no longer run for an account that has been deactivated, and their credentials stop working once the account is signed out everywhere. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226)
- 🤖 **Automation and sub-agent access ends with the account's sessions.** Signing an account out of every device, for example by changing its password, now also cuts off its running automations and sub-agents, whose access stayed valid for up to an hour. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226)
- 🔑 **OAuth sessions survive parallel requests.** Chatting through a connection that forwards your single sign-on token no longer logs your OAuth session out when two requests renew an expiring token at once against a provider that rotates refresh tokens, including requests handled by different workers or replicas sharing Redis, which previously cost every following request its token until you signed in again. [#30426](https://github.com/open-webui/open-webui/pull/30426), [#30450](https://github.com/open-webui/open-webui/pull/30450), [#30416](https://github.com/open-webui/open-webui/issues/30416)
- 🪪 **Token exchange group mapping.** With OAuth group mapping on, signing in through token exchange now assigns groups from the token's own groups claim when the provider's user info leaves it out, as it already did for roles. [Commit](https://github.com/open-webui/open-webui/commit/f412538756f745b531036840bc0a153e62b0f003)
- 🧱 **Blocked OAuth groups not created.** With automatic group creation on, groups matching "OAUTH_BLOCKED_GROUPS" are no longer created at sign-in, where a provider sending a user's full directory membership could fill the groups list with thousands of empty groups. [#31316](https://github.com/open-webui/open-webui/pull/31316), [#29558](https://github.com/open-webui/open-webui/issues/29558)