diff --git a/backend/open_webui/env.py b/backend/open_webui/env.py index 6cdc35ad57..388ac353da 100644 --- a/backend/open_webui/env.py +++ b/backend/open_webui/env.py @@ -914,7 +914,6 @@ if WEBUI_NAME != 'Open WebUI': # https://docs.openwebui.com/license. WEBUI_FAVICON_URL = 'https://openwebui.com/favicon.png' WEBUI_BUILD_HASH = os.getenv('WEBUI_BUILD_HASH', 'dev-build') -TRUSTED_SIGNATURE_KEY = os.getenv('TRUSTED_SIGNATURE_KEY', '') #################################### # Feature flags diff --git a/backend/open_webui/utils/auth.py b/backend/open_webui/utils/auth.py index 408b518c13..981f13b14f 100644 --- a/backend/open_webui/utils/auth.py +++ b/backend/open_webui/utils/auth.py @@ -3,7 +3,6 @@ from __future__ import annotations import asyncio import base64 import hashlib -import hmac import logging import os import uuid @@ -30,7 +29,6 @@ from open_webui.env import ( PASSWORD_VALIDATION_REGEX_PATTERN, REDIS_KEY_PREFIX, STATIC_DIR, - TRUSTED_SIGNATURE_KEY, WEBUI_AUTH_TRUSTED_EMAIL_HEADER, WEBUI_SECRET_KEY, pk, @@ -54,22 +52,6 @@ PASSWORD_BCRYPT_MAX_BYTES = 72 ############## -def verify_signature(payload: str, signature: str) -> bool: - """ - Verifies the HMAC signature of the received payload. - """ - try: - expected_signature = base64.b64encode( - hmac.new(TRUSTED_SIGNATURE_KEY, payload.encode(), hashlib.sha256).digest() - ).decode() - - # Compare securely to prevent timing attacks - return hmac.compare_digest(expected_signature, signature) - - except Exception: - return False - - def override_static(path: str, content: str): # Ensure path is safe if '/' in path or '..' in path: @@ -325,10 +307,6 @@ async def revoke_user_tokens(request, user_id: str): ) -def extract_token_from_auth_header(auth_header: str): - return auth_header[len('Bearer ') :] - - def create_api_key(): key = str(uuid.uuid4()).replace('-', '') return f'sk-{key}'