open-webui/backend/open_webui
Classic298 7fa705f3b8
feat: let operators expose chosen file metadata to the model in retrieved sources (#29696)
Custom metadata attached to a file upload now reaches the vector DB, but the model still never sees it. Both prompt-assembly paths build their output from a fixed field set: the classic RAG <source> tag carries only id, name and resource type, and the retrieval tools return only content, source and file id per chunk. A scraper that records where each document came from therefore cannot get that origin in front of the model, so answers cannot state it.

RAG_SOURCE_METADATA_KEYS names the chunk metadata keys allowed through to the model. Configured keys are emitted as extra attributes on the <source> tag and as extra fields on tool result chunks, covering both retrieval paths. It is empty by default, so nothing changes for existing deployments.

An allowlist instead of passing everything through, because chunk metadata also carries file hashes, collection names, embedding config and relevance scores, which would then be added to every retrieved chunk of every request. Values are attacker-controllable through an uploaded file, so they are escaped before they go into the tag, and a configured key can never displace a field the tag or the chunk already defines.

Reported in open-webui/open-webui#29486.
2026-09-19 17:02:59 -05:00
..
data refac: mv backend files to /open_webui dir 2024-09-04 16:54:48 +02:00
internal refac 2026-09-06 17:13:32 -04:00
migrations chore: format 2026-08-25 16:53:53 -04:00
models fix: label the search modal's archive action Unarchive for archived chats and report what happened (#30177) 2026-09-19 10:02:11 -05:00
retrieval feat: let operators expose chosen file metadata to the model in retrieved sources (#29696) 2026-09-19 17:02:59 -05:00
routers fix: keep the speech-to-text extension allowlist when the Audio settings are saved (#30208) 2026-09-19 17:36:38 -04:00
socket refac 2026-09-16 22:47:37 -04:00
static refac 2026-09-06 17:27:30 -04:00
storage refac 2026-09-06 17:13:32 -04:00
tools feat: let operators expose chosen file metadata to the model in retrieved sources (#29696) 2026-09-19 17:02:59 -05:00
utils feat: let operators expose chosen file metadata to the model in retrieved sources (#29696) 2026-09-19 17:02:59 -05:00
__init__.py perf: allow disabling websocket per-message-deflate (#28613) 2026-08-24 18:46:07 -04:00
alembic.ini fix: Alembic CLI commands from failing 2025-08-15 04:17:47 -04:00
config.py fix: pgvector reads leak their connection and lose most of their neighbours (#30142) 2026-09-18 19:31:49 -04:00
constants.py refac 2026-08-29 16:14:32 -04:00
env.py feat: let operators expose chosen file metadata to the model in retrieved sources (#29696) 2026-09-19 17:02:59 -05:00
events.py refac 2026-08-16 23:21:00 -07:00
functions.py fix: honor bypass_system_prompt on the pipe route (#28739) 2026-08-19 11:08:02 -07:00
main.py refac 2026-09-17 19:49:35 -04:00
tasks.py fix: stop tracking tasks under an empty item id (#29980) 2026-09-13 20:28:54 -05:00