diff --git a/CHANGELOG.md b/CHANGELOG.md index 3369311781..4ddebc827a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [0.11.5] - 2026-10-05 ### Added +- 🔏 **Two-factor sign-in.** Administrators can require an authenticator app for every user under Admin Settings > Authentication, or with "ENABLE_MFA", so users set one up from a QR code on their next sign-in, get ten single-use recovery codes, and can later replace their authenticator or create new recovery codes in their account settings; OAuth and trusted-header sign-ins can be let through without it with "MFA_ALLOW_OAUTH_BYPASS" and "MFA_ALLOW_TRUSTED_HEADER_BYPASS", and the "open-webui mfa reset" command gives a user who lost their authenticator a one-time recovery token. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226) - 📡 **Lighter multi-instance streaming.** Deployments that share websocket traffic through Redis use less CPU while streaming, because each server now skips live updates for rooms it has no one in; set "WEBSOCKET_REDIS_ROOM_CHANNELS" to false to restore the previous delivery. [#28818](https://github.com/open-webui/open-webui/pull/28818) - 📑 **Word and PowerPoint files from code.** The code interpreter can now create Word documents and PowerPoint decks that open in Office, using libraries bundled with Open WebUI so it also works without internet access. [#30382](https://github.com/open-webui/open-webui/pull/30382), [#30361](https://github.com/open-webui/open-webui/issues/30361) @@ -24,6 +25,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - 🆔 **MCP Connection ID filled in from the name.** When adding an MCP tool server, the ID field is now labeled Connection ID and filled in from the server name, so it no longer has to be typed before saving or registering an OAuth client, and importing a connection keeps its ID. [Commit](https://github.com/open-webui/open-webui/commit/079647f1425ef80be5a330bf1b2c4158d66c8340) - 🔩 **MCP tools listed in the chat tools dialog.** Expanding an MCP tool server in the tools dialog of the chat input now loads and lists its tools with their descriptions and a tool count, offers Reconnect when the server needs you to sign in again, and only shows the tool servers selected for the chat. [Commit](https://github.com/open-webui/open-webui/commit/fb741ebcd2daed626405f9458c192e5161bce4c0) - 🪣 **S3 file storage on the slim image.** The slim image can now keep files in an S3 bucket with "STORAGE_PROVIDER" set to s3, where it only supported local storage; Google Cloud and Azure storage still need the standard image. [Commit](https://github.com/open-webui/open-webui/commit/425da8b6cc14144895c6eba19a70cf5c8881d3cf) +- 🚪 **Sign out all devices for a user.** Administrators can now sign a user out of every device from the user edit dialog, while the user's API keys keep working. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226) - 🔄 **General improvements.** Various improvements were implemented across the application to enhance performance, stability, and security. - 🌐 **Translation updates.** Translations for German, Italian, Turkish, Persian, Indonesian, Catalan, French, Malay, Simplified Chinese, Hindi and Japanese were enhanced and expanded. @@ -53,6 +55,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - 📝 **Notes permission for live note editing.** Opening a note for live collaborative editing now requires the Notes permission, like the rest of the Notes feature. [#31552](https://github.com/open-webui/open-webui/pull/31552) - 📆 **Calendar tools check calendar access.** Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does. [#31537](https://github.com/open-webui/open-webui/pull/31537) - 📞 **Voice mode permission applies to call links.** Opening a chat with "?call=true" in the URL now respects the "Allow Call" permission and the same checks as the Voice mode button, so it no longer starts a voice call for users without that permission, with several models selected or with the Web API speech-to-text engine. [#31826](https://github.com/open-webui/open-webui/pull/31826), [#31825](https://github.com/open-webui/open-webui/issues/31825) +- 🔒 **Password changes sign out everywhere without Redis.** Changing a password, by the user or an administrator, now signs that account out on every device even on installations without Redis, where existing sessions stayed valid until they expired. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226) +- ⛓️ **Live connections end with the session.** A browser's live connection is now checked every 30 seconds and closed once its sign-in has been revoked or has expired, where it kept receiving updates. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226) +- 🤐 **Sign-in requests kept out of the audit log.** With request auditing on, the bodies of authentication and OAuth requests and their responses, such as sign-in, password changes and API key creation, are no longer written to the audit log. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226) +- 🛂 **Forwarded headers trust for open-webui serve.** Starting Open WebUI with "open-webui serve" or "open-webui dev" now honors "FORWARDED_ALLOW_IPS", where it trusted forwarded headers from every connection regardless of the setting. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226) +- 🤖 **Automations and sub-agents of deactivated accounts.** Automations and sub-agents no longer run for an account that has been deactivated, and their credentials stop working once the account is signed out everywhere. [Commit](https://github.com/open-webui/open-webui/commit/24e30d1cbdaab624dfe20f479f805e6791cf0226) - 🔑 **OAuth sessions survive parallel requests.** Chatting through a connection that forwards your single sign-on token no longer logs your OAuth session out when two requests renew an expiring token at once against a provider that rotates refresh tokens, including requests handled by different workers or replicas sharing Redis, which previously cost every following request its token until you signed in again. [#30426](https://github.com/open-webui/open-webui/pull/30426), [#30450](https://github.com/open-webui/open-webui/pull/30450), [#30416](https://github.com/open-webui/open-webui/issues/30416) - 🪪 **Token exchange group mapping.** With OAuth group mapping on, signing in through token exchange now assigns groups from the token's own groups claim when the provider's user info leaves it out, as it already did for roles. [Commit](https://github.com/open-webui/open-webui/commit/f412538756f745b531036840bc0a153e62b0f003) - 🧱 **Blocked OAuth groups not created.** With automatic group creation on, groups matching "OAUTH_BLOCKED_GROUPS" are no longer created at sign-in, where a provider sending a user's full directory membership could fill the groups list with thousands of empty groups. [#31316](https://github.com/open-webui/open-webui/pull/31316), [#29558](https://github.com/open-webui/open-webui/issues/29558) @@ -228,12 +235,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Changed +- ⚠️ **Database Migrations**: This release includes database schema changes; we strongly recommend backing up your database and all associated data before upgrading in production environments. If you are running a multi-worker, multi-server, or load-balanced deployment, all instances must be updated simultaneously, rolling updates are not supported and will cause application failures due to schema incompatibility. - ⚠️ **IMPORTANT for Milvus and Milvus multitenancy users: back up your Milvus data before upgrading**: On first start with "ENABLE_DB_MIGRATIONS" on (the default), every existing Milvus collection is copied in full into a new one holding its vectors, text and BM25 keyword index together, and Open WebUI only finishes starting once that is done, which can take hours for hundreds of gigabytes and needs free disk space for a second copy of your Milvus data. Nothing is re-embedded, and the originals are only dropped once every copy has succeeded. Back up first and avoid upgrading Milvus and Open WebUI on the same day. Hybrid search on Milvus needs Milvus 2.5 or newer; on older versions the migration is skipped and there is no native hybrid search. [#31645](https://github.com/open-webui/open-webui/pull/31645), [#31660](https://github.com/open-webui/open-webui/pull/31660) - 🔌 **ENABLE_PLUGINS is the master switch.** Setting "ENABLE_PLUGINS=false" now turns off every kind of plugin, including external OpenAPI, MCP and Open Terminal servers and personal direct connections, and overrides "ENABLE_TOOLS", "ENABLE_FUNCTIONS" and "ENABLE_TOOL_SERVERS"; all four need a restart to take effect. [Commit](https://github.com/open-webui/open-webui/commit/f50f9e6252209760d0b96f090766e91fb826ecba), [#31509](https://github.com/open-webui/open-webui/issues/31509) - ⚡ **orjson on by default.** "ENABLE_ORJSON" now defaults to on, and setting "ENABLE_ORJSON=false" switches back to the standard JSON encoder. [#31616](https://github.com/open-webui/open-webui/pull/31616) - 🔁 **Update Redis-backed instances together.** Where several servers share their websocket traffic through Redis, every instance should be updated at the same time, since live chat updates sent by an updated instance do not reach one still on an older version unless "WEBSOCKET_REDIS_ROOM_CHANNELS" is set to false. [#28818](https://github.com/open-webui/open-webui/pull/28818) - 🏟️ **Arena models off by default.** "ENABLE_EVALUATION_ARENA_MODELS" now defaults to off, so new installations no longer show the built-in arena model in the model selector; existing installations keep their current setting. [Commit](https://github.com/open-webui/open-webui/commit/77e6bc28932bff9f1d2e1aad5933a2736416e081) - 🔖 **Build shown next to the version.** The version in Settings shows "dev" and the commit for development builds and the commit for other non-release builds, and update checks and the update notification now only run on release builds. [Commit](https://github.com/open-webui/open-webui/commit/51f0e01258b92c77952d4534bb8ce8c618b2700c) +- 📂 **Folder default model set in the folder settings.** A folder's default model for new chats is now chosen in the folder's settings, and switching the model inside a chat in that folder no longer changes the folder's default. [Commit](https://github.com/open-webui/open-webui/commit/a3a2e42ee00a70d6c646735345e6b771bcd2a70d), [Commit](https://github.com/open-webui/open-webui/commit/8f4f29d8345196e3221c85ecff0411fbd7e371af) +- 🏷️ **Workspace model list links.** In the workspace model list, clicking a model's name now opens its editor and a small arrow next to it opens the model in a new chat, the enable switch goes back if saving fails, and deleting with Shift held now asks for confirmation. [Commit](https://github.com/open-webui/open-webui/commit/5bb1c470802c7df9a48cc0ca45c1886c294d6e6e) ## [0.11.4] - 2026-09-21