Commit graph

5323 commits

Author SHA1 Message Date
Classic298
f98ca224c5
perf: use the faster JSON encoder by default (#31616)
ENABLE_ORJSON has shipped as an option since v0.11.0 (2026-07-27), five releases and two months ago, and orjson is already installed with every instance. The only two problems ever found with it (rare line break characters splitting a stream, and extra encoding options being ignored) were fixed in v0.11.1 and nothing has come up since. The regression suite at https://github.com/open-webui/tests now runs 222 tests with the option on and off side by side, on SQLite, Postgres, several workers sharing one Redis with some on and some off, and in the browser: chats, completions for every provider format, tool calls, citations, all workspace and admin data, exports and imports, notes and live socket updates behave the same, and every API response is byte for byte identical. The only differences were in how non-English text gets saved to the database, where the standard encoder is the one with bugs (missed searches and too small size limits). Turning it on by default gives every instance the speedup measured in #27583 (live socket updates encode 17x and decode 3x faster), and ENABLE_ORJSON=false keeps the old encoder.
2026-09-30 19:42:53 +04:00
Classic298
bff0492b5f
fix: every log line is exported twice to the OpenTelemetry collector when traces and logs are both on (#31528)
With ENABLE_OTEL, ENABLE_OTEL_TRACES and ENABLE_OTEL_LOGS all on, the collector received each log line twice, once with code location attributes and once without, because the logging instrumentation for traces now attaches its own log exporter next to Open WebUI's. It now keeps trace context on log lines without adding that second exporter, so each log line reaches the collector once, and OTEL_PYTHON_LOG_AUTO_INSTRUMENTATION=false is no longer needed as a workaround.

Fixes #31524
2026-09-30 19:36:43 +04:00
Classic298
bee06b08ba
fix: jina-colbert-v2 reranker fails to load and turns hybrid search off (#31532)
Choosing jinaai/jina-colbert-v2 as the reranking model failed on the current transformers release with "'HF_ColBERT' object has no attribute 'all_tied_weights_keys'", and saving the Documents settings quietly switched hybrid search back off. The ColBERT reranker now finishes loading, reranks search results and hybrid search stays on after saving.

Fixes #31522
2026-09-30 19:34:20 +04:00
Classic298
710b9f1e2c
fix: exact matches score as the worst result on Weaviate (#31531)
With Weaviate as the vector database, a chunk identical to the query (distance 0) was treated as having no distance and got a relevance score of 0. Perfect matches could land at the bottom of the results or fall below the relevance threshold. They now score 1 as expected.

Fixes #31527
2026-09-30 19:29:59 +04:00
Classic298
52533c5675
refac: calendar event tools use the calendar's access check (#31537)
Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does.
2026-09-30 19:29:19 +04:00
Classic298
288bf91f73
fix: tool prompts time out when the user's tab is on another instance (#31620)
With WEBSOCKET_MANAGER=redis and several instances or workers, an instance only subscribed to Redis once a browser tab had connected to it. Until then, when a tool or Function asked the user something (a confirmation or an input dialog) and the user's tab was connected to another instance, the user's reply never reached the tool and it waited until it timed out. Every instance now subscribes at startup, so the reply arrives whichever instance the tab is on.
2026-09-30 19:24:03 +04:00
Classic298
6d409da9d2
refac: apply the Notes permission to live note editing (#31552)
Opening a note for live collaborative editing now follows the same Notes permission as the rest of the Notes feature.
2026-09-30 19:19:53 +04:00
Classic298
321a24dfea
fix: non-English text is missed by searches and counted six times against size limits (#31615)
With ENABLE_ORJSON off (the default), non-English letters were saved to the database as escape codes, so "Ü" was stored as \u00dc. Searches that ignore upper and lower case compare against that saved text, so they missed any match that differs only in the case of a non-English letter: filtering models by the tag "Überblick" found nothing on Postgres, and searching automations for "отчёт" missed a prompt containing "Отчёт" on SQLite and Postgres. The 100,000 character size limit for user and chat variables counted the escape codes too, so Cyrillic or Chinese variables were refused as too large (or chat variables silently came out empty in the system prompt) at about a sixth of that size. Non-English text is now saved as written, which is how it is already saved with ENABLE_ORJSON on, so nothing changes for those instances, and the limit counts real characters. Anything saved before this keeps the escape codes until it is next edited.
2026-09-30 19:19:29 +04:00
Classic298
2062231f9c
fix: apply the usual login check when the app loads its settings (#31621)
Loading the app's settings now uses the same login check as every other request, so a session that is no longer valid gets the logged-out settings.
2026-09-30 19:09:34 +04:00
Classic298
d3dde3609d
fix: audit log records new passwords in plain text (#31622)
With request auditing turned on, the audit log only masked fields named exactly "password". The new password from a password change, and passwords entered in admin settings such as YaCy or Jupyter, were written to the log as-is. Any field whose name ends in "password", in any letter case, is now replaced with asterisks.
2026-09-30 19:09:03 +04:00
Classic298
b4ebd0d62f
refac(hardening): apply the same safety checks to generated image downloads (#31623)
When an image generation backend returns a link instead of the image itself, the download now goes through the same safety checks used for other external image downloads. Links on the configured ComfyUI address are still trusted as before, so a ComfyUI server on a local network keeps working.
2026-09-30 19:08:48 +04:00
Classic298
6a2aad92f2
fix: SSO login failures show the email/password error (#31629)
When signing in through an OAuth/OIDC provider failed, for example because the provider denied access, the account had no email or its email domain was not allowed, the login page told the user their email or password was wrong, even though they never typed one. Every such failure now shows "Sign-in with your identity provider failed. Please contact your administrator for assistance." The text is the same for every cause so it does not reveal which check failed, and the exact reason is still written to the server log as a warning.

Fixes #31627
2026-09-30 19:07:49 +04:00
Classic298
b6dfa3799d
fix: chat links in finished and failed webhook notifications open a 404 (#31572)
The link in "chat finished" and "chat failed" webhook notifications was missing the `/c/` part of the chat address, so clicking it opened a 404 page. The link is sent as `/c/<chat id>` again and opens the chat.

Fixes #31565
2026-09-30 19:05:45 +04:00
Classic298
c488f60e8b
fix: temporary chats save sub-agent conversations on the server (#31573)
In a temporary chat, when the model handed a task to a sub-agent, the sub-agent's conversation with the task and its answer was saved on the server, although a temporary chat should leave nothing behind. The model is no longer offered sub-agents in temporary chats.

Fixes #31567
2026-09-30 19:05:21 +04:00
Classic298
3d70d43a1c
fix: members can be added to or removed from a direct message through the API (#31575)
The person who started a direct message could add or remove people through the API, although the app only offers this in group channels. Someone added this way could read the whole earlier conversation, and because the original pair no longer matched the conversation, their next message opened a second, empty direct message. Changing the members of a direct message now answers with a 403.

Fixes #31570
2026-09-30 19:03:32 +04:00
Classic298
fa66b0f306
fix: background sub-agent and timer replies only show in the open chat after a page reload (#31576)
When a sub-agent running in the background finished, or a timer the model set went off, the result and the model's follow-up reply were saved but did not show in the chat the user had open. They only appeared after a manual page reload. They now show in the open chat as soon as they arrive.

Fixes #31566
2026-09-30 19:03:01 +04:00
Classic298
9b45bedeaf
fix: check the Channels permission when a channel automation runs (#31577)
An automation that posts into a channel now only runs when the user who created it has the Channels permission.
2026-09-30 19:02:37 +04:00
Classic298
028dab8f1f
fix: apply the Channels permission to real-time channel messages (#31578)
Real-time channel messages are now only delivered to users who have the Channels permission set in the admin user permission settings.
2026-09-30 19:02:21 +04:00
Classic298
e26da43076
fix: automation still shows "Last run Never" after "Run now" (#31583)
* fix: automation still shows "Last run Never" after "Run now"

Running an automation with "Run now" added the run to its history, but the automation page and the Automations list kept showing "Last run Never" (or the time of the last scheduled run). Only scheduled runs recorded a last run time. A manual run now records it too, so the automation page and the Automations list show the time of the run you just started.

Fixes #31580

* fix: show the new last run time right after Run now

The automation page now takes the automation the server returns after Run now, so the last run time updates on the spot and no reload is needed.
2026-09-30 19:01:42 +04:00
Classic298
c1f245845c
fix: MCP tool calls ignore AIOHTTP_CLIENT_TIMEOUT_TOOL_SERVER (#31641)
A tool call to an MCP server had no time limit, so a server that hung kept the chat waiting until a reverse proxy or the server itself closed the connection, even with AIOHTTP_CLIENT_TIMEOUT_TOOL_SERVER set. The call now stops after the configured number of seconds and the model sees the timeout as a tool error, which is how OpenAPI tool servers already behave. When the variable is unset it falls back to AIOHTTP_CLIENT_TIMEOUT, and with neither set (or a value of 0 or below) MCP tool calls still have no time limit.

Fixes #31640
2026-09-30 19:00:20 +04:00
Classic298
ad01bca2b0
fix: repeating calendar events are missing when they began before the visible dates (#31606)
A repeating event that was still running when the visible dates began was left out of the calendar. A weekly event from 23:00 to 01:00, for example, did not show on the following day, while the same event without a repeat did. Repeating events are now shown whenever any part of them falls within the visible dates.

Fixes #31605
2026-09-29 20:25:18 +04:00
Classic298
d4b9d19645
fix: system prompt and compacted context are lost after approving a tool call (#31501)
With tool approval set to ask, the request sent to the model after approving a tool call left out the system prompt. In a compacted chat it also left out the conversation summary and sent the whole history again. The request after approval now has the same system prompt and compacted context as the one before it, plus the tool call and its result. The system prompt is picked the same way as for any other message: the chat Controls prompt, else your personal Settings prompt, else the admin default. A system prompt sent only in an API request is not kept by the server, so it is still missing after approval.

Fixes #31499
2026-09-28 07:59:43 +04:00
Classic298
b00745c8d0
fix: approved tool results are lost and approved tools can run twice (#31502)
With tool approval set to ask, the result of an approved tool call was dropped from the chat once the reply finished, so the model no longer saw it in later turns. When the model then asked for a second tool, the first call went back to waiting for approval, and approving it again ran the tool a second time. Approved results now stay in the chat and each tool runs once.

Related to #31499
2026-09-28 07:59:20 +04:00
Classic298
fc9ad75164
fix: admins can still read and change other users' chats with ENABLE_ADMIN_CHAT_ACCESS off (#31416)
With ENABLE_ADMIN_CHAT_ACCESS turned off, opening another user's chat was refused, but through direct API requests an admin could still get the whole chat back in the reply to editing or deleting one of its messages, grant themselves read access in the chat's share settings, clone a chat someone shared privately with another user, or delete the chat. They could also send messages into it, attach it as context to their own chat, approve its tool calls, and list or stop its running replies. All of these are now refused for an admin on another user's chat, the same as opening it. With the setting on, admins keep full access as before.

Fixes #31413
2026-09-28 01:51:59 +04:00
Classic298
e8d6a8734a
fix: model upload, download and unload ignore a connection's custom headers and auth type (#31490)
Uploading or downloading a GGUF model to an Ollama connection sent neither the key nor the connection's custom headers, so it failed behind gateways such as Cloudflare Access and on servers that need a key. Unloading a model dropped the custom headers and sent the key as a Bearer token even with the authentication type set to None, for Ollama and llama.cpp connections alike. These requests now use the connection's headers and authentication type the same as chatting and the Manage Ollama dialog already do. Follow-up to #31489.
2026-09-28 01:48:26 +04:00
Timothy Jaeryang Baek
af6b82a18c refac 2026-09-28 00:11:04 +04:00
Classic298
00a245b9fa
fix: Manage Ollama ignores a connection's custom headers and auth type (#31489)
Listing, pulling, creating, copying and deleting models from the Manage Ollama dialog ignored the connection's custom headers and authentication type, so the dialog failed behind gateways such as Cloudflare Access and sent the key as a Bearer token even with the authentication type set to None. Checking a single connection's version sent no key at all. All of these, and the other requests to an Ollama connection such as text generation and embeddings, now use the connection's headers and authentication type, matching what verifying the connection and chatting already do.

Fixes #31487
2026-09-28 00:04:18 +04:00
Timothy Jaeryang Baek
bc2416c5db refac 2026-09-27 23:29:38 +04:00
Classic298
1c813902ec
fix: keep relevance scores on knowledge tool citations (#31307)
With native function calling, citations produced by query_knowledge_files and query_chat_files never showed the relevance percentage badge, while the same knowledge base queried through classic RAG did.

The tools already return a distance per chunk, but the step that groups tool results into citation sources dropped it. Each grouped source now carries a distances list aligned with its documents, the same shape the classic RAG path emits, so the existing citation UI shows the badge without frontend changes. Chunks without a score (notes) leave the list empty, which the UI already treats as no score.

Fixes #29776
2026-09-27 23:21:21 +04:00
Classic298
0fe9ed0d3c
fix: Anthropic API streams report a failed response as a finished one (#31405)
When the provider failed partway through a streaming request to the Anthropic Messages endpoint, the stream still ended like a normally finished answer, so Claude Code and the Anthropic SDKs took the cut-off text as complete. The stream now ends with an Anthropic error event, with the provider's error message if it sent one, so clients raise an error. Successful streams are unchanged.

Fixes #31403
2026-09-27 23:20:50 +04:00
Classic298
6e5e5fe6e9
feat: add a Tavily search depth setting (#31308)
Tavily web search always ran at Tavily's default depth (basic), because the search request never sent `search_depth`. The only Tavily depth control in Admin > Settings > Web Search, "Tavily Extract Depth", applies to the Extract API used by the web loader, never to search.

This adds `TAVILY_SEARCH_DEPTH` (env var and persisted setting, default `basic`) and a "Tavily Search Depth" select (ultra-fast, fast, basic, advanced) under the Tavily search engine settings. The value is sent as `search_depth` on every Tavily search request, so admins can set search and extract depth independently, for example fast search with advanced extraction.

The default matches Tavily's own default, so existing setups keep the same behaviour until the setting is changed.

Fixes #29891
2026-09-27 23:15:09 +04:00
Classic298
b8de508dbc
fix: keep arena model access after editing it in Settings > Models (#31309)
Saving an arena model in Admin Settings > Models (for example to set default tools or capabilities) creates a model entry with the arena id. That entry replaced the arena model's metadata wholesale, dropping the access grants, model_ids and filter_mode configured in Admin Settings > Evaluations. From then on every non-admin user lost the arena model, even when it was public, and chats through it ignored the configured model pool.

The override now keeps those three keys from the evaluation config, which is where arena access and the model pool are managed. Everything else set in Settings > Models (tools, capabilities, description, profile image) still applies.

Verified end to end on base and patched: after the override a user sees and can chat with a public arena model (base: hidden, 400), private arena models stay hidden, and 20 admin chats all route to the configured pool (base: spread across all models).

Fixes #29564
2026-09-27 23:14:47 +04:00
Classic298
35dda256f0
fix: approve every tool call from a multi-call turn in ask mode (#31315)
In "Ask for approval" mode, when the model requested several tools in one turn, only the first call got an approval card. The others stayed on "Executing..." forever, never ran, could not be approved (the server answered "already resolved"), and the model was called again without their results. The stuck state was saved to the chat.

Once streaming finishes, every call in the turn is marked as completed (arguments done, nothing run yet). The approval pause only queued siblings that were still in progress, so these were skipped. They are now queued as well, and each one gets its own approval card in turn after the previous one is resolved.

Calls that already have a result and rejected calls are untouched, and single-call turns behave as before. Verified against the real approval functions with same-name, mixed-name, reject and ask_user batches, plus the tests-repo unit suite (identical results before and after).

Fixes #29293
2026-09-27 23:14:30 +04:00
Classic298
b91a558c9d
fix: stop forwarding empty tools arrays from the Anthropic Messages endpoint (#31343)
Anthropic clients such as Claude Code send "tools": [] on text-only requests like prompt-hook evaluation. The Anthropic Messages endpoint carried that empty array into the converted OpenAI request, and vLLM and the OpenAI API reject it with HTTP 400, so those requests failed while normal chats with tools kept working. A "tools": null body crashed the converter with a 500.

The converter now only emits tools when the list is non-empty, and only emits tool_choice when tools were emitted. Dropping tools alone is not enough: the same backends also reject tool_choice without tools, so a request sending an empty tool list plus a tool_choice would still fail.

Requests with real tools are converted exactly as before. Verified end to end against a mock backend enforcing vLLM's validation: empty, null and tool_choice-only requests went from 400/500 to 200 with end_turn, streaming included.

Fixes #31341
2026-09-27 23:11:45 +04:00
Classic298
91fb33ef57
fix(retrieval): name the link when process/url cannot fetch it (#31354)
Attaching a link in chat or to a knowledge base that cannot be fetched (closed port, blocked by the fetch filter, an HTTP error such as 404) showed the toast "Error processing URL", which never said which link failed or that fetching it was the problem.

The fetch step now answers with "Could not read content from <url>", the same message process/web gives for a link it cannot read, so both endpoints report a dead link the same way. The too-large 413 still passes through unchanged, and a working link returns exactly what it did before.

The new handler covers only the fetch. Rewording the endpoint's existing catch-all would be one line, but that handler also receives database errors from the config and file lookups, which would then be reported as an unreadable link.

Related to #31347
2026-09-27 23:11:20 +04:00
Classic298
5d4f9b957e
fix: foreground sub-agents cannot use personal tool servers like Open Terminal (#31424)
With a personal tool server connection such as Open Terminal, the main model could call its tools but a foreground sub-agent it delegated to got none of them. Chats resuming after a tool approval lost those tools the same way. Setting up the tools for the main model emptied the list those later steps read from. It now works on a copy, so sub-agents and resumed chats get the same tools as the parent.

Fixes #29893
2026-09-27 23:10:16 +04:00
Classic298
d6b19dcaa1
fix: on PostgreSQL, searching automations or filtering models by a non-ASCII word finds nothing (#31423)
On PostgreSQL with ENABLE_ORJSON off (the default), searching automations by a word from their prompt, or filtering models by a tag, found nothing when the word was non-ASCII, for example Chinese. SQLite, and PostgreSQL with ENABLE_ORJSON on, were fine. With the default setting non-ASCII text is saved as \uXXXX codes, and PostgreSQL reads the backslash in a search pattern as a special character, so the search never matched. Special characters in the search text are now taken literally, so these searches work on both databases, and a % or _ typed into them now matches only itself.

Fixes #31422
2026-09-27 23:09:54 +04:00
Classic298
59ea3b7c2c
fix: backslashes in uploaded HTML files turn into line breaks or break the upload (#31450)
With the default content extraction engine, backslashes in an uploaded .html or .htm file were read as escape sequences. A path like C:\new\table was saved with a line break and a tab in it, and a page containing C:\Users failed to upload with a 'unicodeescape' codec error. HTML files are now read the same way as .txt and .md uploads, so the saved text matches the page.

Fixes #31440
2026-09-27 23:08:14 +04:00
Classic298
31a09a1eeb
refac: check the owner's role before continuing a chat after a subagent finishes (#31451)
The parent chat now only continues with a finished subagent's result while its owner still has a verified role, the same check timers already make.
2026-09-27 22:59:11 +04:00
Classic298
eda8d85361
fix: hybrid search finds nothing when a collection cannot be read (#31460)
With hybrid search on and a vector database without built-in hybrid search, a collection that failed to load (for example Qdrant strict mode rejecting the request) was skipped quietly, so retrieval returned no documents and never fell back to normal vector search. A failed load now counts as a failed collection, so when every collection fails retrieval falls back to vector search, the same way it already does when the search itself fails. The retrieval API returns its usual error in that case.

Part of #31459
2026-09-27 22:59:02 +04:00
Classic298
8a90f0fc93
fix: file uploads and hybrid search fail on Qdrant with strict mode enabled (#31461)
With Qdrant strict mode on and a max_query_limit below 999999999, Qdrant rejects Open WebUI's reads with "Limit exceeded", so every file upload after the first fails in the default multitenancy mode, and hybrid search finds nothing. Reads now go in pages of 1000 points, so any strict-mode limit of 1000 or more works. Without strict mode the results are the same as before.

Tested against Qdrant 1.19.1 with max_query_limit 1000, for both multitenancy on and off: collections of up to 2500 points come back complete, limits are respected, and tenants stay separated.

Fixes #31459
2026-09-27 22:58:42 +04:00
Classic298
b0650d04b2
fix: failed timer leaves a blank, unfinished reply in the chat (#31483)
When a scheduled timer failed before the model started answering, for example because its model had been removed, the chat showed the timer's prompt with a blank reply that looked stuck, and the error never appeared in the chat. The reply now shows the error and stops loading, like any other failed message.

Fixes #31481
2026-09-27 22:56:20 +04:00
Classic298
420b4a2797
fix(retrieval): name the link when process/web cannot fetch it (#31351)
Some checks are pending
Python CI / Ruff Format (3.11) (push) Waiting to run
Python CI / Ruff Format (3.12) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/arm64 runner:ubuntu-24.04-arm], map[build_args:USE_SLIM=true free_disk:false name:slim suffix:-slim]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/amd64 runner:ubuntu-latest], map[build_args: free_disk:false name:main suffix:]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/amd64 runner:ubuntu-latest], map[build_args:USE_CUDA=true USE_CUDA_VER=cu126 free_disk:true name:cuda126 suffix:-cuda126]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/amd64 runner:ubuntu-latest], map[build_args:USE_CUDA=true free_disk:true name:cuda suffix:-cuda]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/amd64 runner:ubuntu-latest], map[build_args:USE_OLLAMA=true free_disk:false name:ollama suffix:-ollama]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/amd64 runner:ubuntu-latest], map[build_args:USE_SLIM=true free_disk:false name:slim suffix:-slim]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/arm64 runner:ubuntu-24.04-arm], map[build_args: free_disk:false name:main suffix:]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/arm64 runner:ubuntu-24.04-arm], map[build_args:USE_CUDA=true USE_CUDA_VER=cu126 free_disk:true name:cuda126 suffix:-cuda126]) (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/arm64 runner:ubuntu-24.04-arm], map[build_args:USE_CUDA=true free_disk:true name:cuda suffix:-cuda]) (push) Waiting to run
Create and publish Docker images with specific build args / copy-to-dockerhub (, main) (push) Blocked by required conditions
Create and publish Docker images with specific build args / copy-to-dockerhub (-cuda, cuda) (push) Blocked by required conditions
Create and publish Docker images with specific build args / copy-to-dockerhub (-cuda126, cuda126) (push) Blocked by required conditions
Create and publish Docker images with specific build args / copy-to-dockerhub (-ollama, ollama) (push) Blocked by required conditions
Create and publish Docker images with specific build args / copy-to-dockerhub (-slim, slim) (push) Blocked by required conditions
Frontend Build / Format & Build (push) Waiting to run
Frontend Build / Unit Tests (push) Waiting to run
Create and publish Docker images with specific build args / build (map[arch:linux/arm64 runner:ubuntu-24.04-arm], map[build_args:USE_OLLAMA=true free_disk:false name:ollama suffix:-ollama]) (push) Waiting to run
Create and publish Docker images with specific build args / merge (map[name:cuda suffix:-cuda]) (push) Blocked by required conditions
Create and publish Docker images with specific build args / merge (map[name:cuda126 suffix:-cuda126]) (push) Blocked by required conditions
Create and publish Docker images with specific build args / merge (map[name:main suffix:]) (push) Blocked by required conditions
Create and publish Docker images with specific build args / merge (map[name:ollama suffix:-ollama]) (push) Blocked by required conditions
Create and publish Docker images with specific build args / merge (map[name:slim suffix:-slim]) (push) Blocked by required conditions
Create and publish Docker images with specific build args / notify-helm-charts (push) Blocked by required conditions
A link whose host refuses the connection, such as a closed port, still came back from POST /api/v1/retrieval/process/web as "Error querying knowledge base", so the caller was told the knowledge base failed when the link was the problem.

The web loaders log a failed fetch and return no documents. That empty result then failed while being saved to the vector store, and the save error was the one reported.

process_web now answers with the existing "Could not read content from <url>" 400 as soon as the loader returns no documents, the same message a link refused by the fetch filter already gets. The check sits in the endpoint so web search and the other users of the loaders keep their current behaviour.

With process=false or embedding bypassed, an unreachable link now gets the same 400 where it used to return 200 with empty content.

Fixes #31347
2026-09-26 07:28:13 +04:00
G30
ffe21bef8d
fix: remove the share links of chats deleted along with their folder (#31306) 2026-09-26 07:27:49 +04:00
Classic298
42cd4f0ec0
refactor: check shared chat access before loading the snapshot on clone (#30388)
The clone endpoint now resolves and checks the share before reading its snapshot, matching the order used by the shared chat view endpoint.
2026-09-26 07:20:14 +04:00
Classic298
fe8b30438a
fix: stray <|end_of_solution|> marker left in the reply (#31436)
When a model wraps its answer in <|begin_of_solution|> and <|end_of_solution|>, only the opening marker was removed. The closing marker stayed visible in the reply and was saved with the message, and anything the model wrote after it was glued onto the answer. Now both markers are removed and text after the answer shows up as a normal part of the reply.

Fixes #31434
2026-09-26 07:19:09 +04:00
Classic298
25604d7070
fix: chats keep failing on Anthropic and Bedrock after a tool call is saved incorrectly (#31431)
Sometimes a reply where the model used tools gets saved with a tool result that no call in that reply asked for, or with a tool call that never got its result. The chat history was then sent to the provider unchanged, Anthropic and Bedrock rejected it, and every following message in that chat failed until the user deleted the broken reply. Now each tool call is only kept together with its own result from the same reply, and the unmatched calls and results are left out of what gets sent to the model. The chat itself is not changed, and correctly saved chats are sent exactly as before.

Fixes #28937
2026-09-26 07:19:00 +04:00
Classic298
583f5a66d2
fix: max_tokens sent through the API is ignored for Ollama models (#31437)
When an API request to an Ollama model set max_tokens, Open WebUI passed it on in a place Ollama does not read, so Ollama ignored it and replies ran to full length. The limit now reaches Ollama as its own output length setting, so replies stop at the requested length. It also wins over a max_tokens value saved in the model's advanced parameters, as the API docs describe. Chats in the web UI were not affected, since their limit already reached Ollama correctly.

Fixes #31432
2026-09-26 07:18:43 +04:00
Classic298
8081ac299f
fix: missing space in reasoning model answers right after the thinking block (#31438)
With reasoning models, when the first part of the answer arrived together with the end of the thinking block and ended with a space, that space went missing, so "The answer is 4." was shown and saved as "The answeris 4.". That space is now kept.

Fixes #31435
2026-09-26 07:18:35 +04:00
Classic298
9d6b17ffbc
fix: errors on Responses API connections are not shown or not kept after a reload (#31439)
With a connection set to the Responses API, when the provider reported a reply as failed, the error showed while streaming but was gone after a reload, leaving an empty reply. Some other provider errors never showed up at all, not even while streaming. Both kinds of error now show up and are still there after a reload, the same as on Chat Completions connections.

Fixes #31433
2026-09-26 07:18:23 +04:00