From e3900d5ca752d66d4390b33a9aa245bbeb8fbd20 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Thu, 20 Aug 2026 22:06:35 +0200 Subject: [PATCH] refactor: remove the dead signature check, the token header helper and an unused environment variable The backend carries an HMAC signature verifier that nothing calls. It could not have worked in any case: it feeds the key straight from the environment into the HMAC constructor as text where bytes are required, so every call raised, got swallowed by the surrounding catch-all and returned false for correct and incorrect signatures alike. It failed closed, so there was never a window where a bad signature was accepted. A helper that pulls a token out of an authorization header sits in the same module with no caller since token checks moved to dependencies. Removing the verifier leaves TRUSTED_SIGNATURE_KEY with no reader, so it goes too. The variable is not referenced in the documentation and setting it never had an effect, so no deployment changes. --- backend/open_webui/env.py | 1 - backend/open_webui/utils/auth.py | 22 ---------------------- 2 files changed, 23 deletions(-) diff --git a/backend/open_webui/env.py b/backend/open_webui/env.py index 6cdc35ad57..388ac353da 100644 --- a/backend/open_webui/env.py +++ b/backend/open_webui/env.py @@ -914,7 +914,6 @@ if WEBUI_NAME != 'Open WebUI': # https://docs.openwebui.com/license. WEBUI_FAVICON_URL = 'https://openwebui.com/favicon.png' WEBUI_BUILD_HASH = os.getenv('WEBUI_BUILD_HASH', 'dev-build') -TRUSTED_SIGNATURE_KEY = os.getenv('TRUSTED_SIGNATURE_KEY', '') #################################### # Feature flags diff --git a/backend/open_webui/utils/auth.py b/backend/open_webui/utils/auth.py index 408b518c13..981f13b14f 100644 --- a/backend/open_webui/utils/auth.py +++ b/backend/open_webui/utils/auth.py @@ -3,7 +3,6 @@ from __future__ import annotations import asyncio import base64 import hashlib -import hmac import logging import os import uuid @@ -30,7 +29,6 @@ from open_webui.env import ( PASSWORD_VALIDATION_REGEX_PATTERN, REDIS_KEY_PREFIX, STATIC_DIR, - TRUSTED_SIGNATURE_KEY, WEBUI_AUTH_TRUSTED_EMAIL_HEADER, WEBUI_SECRET_KEY, pk, @@ -54,22 +52,6 @@ PASSWORD_BCRYPT_MAX_BYTES = 72 ############## -def verify_signature(payload: str, signature: str) -> bool: - """ - Verifies the HMAC signature of the received payload. - """ - try: - expected_signature = base64.b64encode( - hmac.new(TRUSTED_SIGNATURE_KEY, payload.encode(), hashlib.sha256).digest() - ).decode() - - # Compare securely to prevent timing attacks - return hmac.compare_digest(expected_signature, signature) - - except Exception: - return False - - def override_static(path: str, content: str): # Ensure path is safe if '/' in path or '..' in path: @@ -325,10 +307,6 @@ async def revoke_user_tokens(request, user_id: str): ) -def extract_token_from_auth_header(auth_header: str): - return auth_header[len('Bearer ') :] - - def create_api_key(): key = str(uuid.uuid4()).replace('-', '') return f'sk-{key}'