diff --git a/backend/open_webui/main.py b/backend/open_webui/main.py index e05497c616..a23d2c8a02 100644 --- a/backend/open_webui/main.py +++ b/backend/open_webui/main.py @@ -1834,8 +1834,10 @@ async def chat_completion( status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT(), ) - target_message_id = list(message_ids.values())[0] if message_ids else None - if target_message_id: + # Every message_ids value must match the channel; first-only let a multimodel id slip past. + for target_message_id in (message_ids or {}).values(): + if not target_message_id: + continue target_message = await Messages.get_message_by_id(target_message_id) if target_message and target_message.channel_id != channel.id: raise HTTPException( diff --git a/backend/open_webui/socket/main.py b/backend/open_webui/socket/main.py index 2884847a0e..e048b00978 100644 --- a/backend/open_webui/socket/main.py +++ b/backend/open_webui/socket/main.py @@ -841,11 +841,15 @@ async def _make_channel_emitter(request_info): async def _emit_channel_update(content: str, done: bool = False): from open_webui.models.messages import MessageForm, Messages + # Fail closed: only update a message that actually belongs to this channel. + msg = await Messages.get_message_by_id(message_id) + if not msg or msg.channel_id != channel_id: + return + update_form = MessageForm(content=content) if done: # Merge done flag into existing meta (preserve model_id etc.) - msg = await Messages.get_message_by_id(message_id) - existing_meta = (msg.meta or {}) if msg else {} + existing_meta = msg.meta or {} update_form = MessageForm( content=content, meta={**existing_meta, 'done': True},