open-webui/backend/open_webui/routers
Classic298 9918ab6265
fix: gate public sharing of skills behind sharing.public_skills on create/update (#24494)
The /create (L155-193) and /id/{id}/update (L248-297) endpoints in
routers/skills.py persisted form_data.access_grants directly to
AccessGrants.set_access_grants without filter_allowed_access_grants,
while every other shareable resource in the codebase (channels, knowledge,
models, notes, prompts, tools, calendars) and the dedicated
/id/{id}/access/update endpoint on this same router (L309-348) all do call
the filter. A user with workspace.skills permission (default False, but
admins can grant it to skill-creating users) could therefore attach
{"principal_type":"user","principal_id":"*","permission":"read"|"write"}
to the create or update payload and have it persisted unfiltered, bypassing
the sharing.public_skills gate that the rest of the cohort enforces.

Two changes:

- create_new_skill: call filter_allowed_access_grants with
  'sharing.public_skills' immediately before insert, after the existing
  permission check and ID-taken check.
- update_skill_by_id: call filter_allowed_access_grants with the same key
  after the access check, before form_data.model_dump() flows into
  Skills.update_skill_by_id. The pre-existing access check at L263-277 only
  restricts WHO may modify the skill; the new filter restricts WHICH grants
  they may set.

All supporting plumbing was already in place from prior PRs:
filter_allowed_access_grants is already imported at L22, the
USER_PERMISSIONS_WORKSPACE_SKILLS_ALLOW_PUBLIC_SHARING constant exists,
DEFAULT_USER_PERMISSIONS['sharing']['public_skills'] is wired up,
SharingPermissions.public_skills is in the Pydantic, and the admin UI
already renders the toggle. This is a pure 2-line router fix that closes
the cohort-consistency gap.

Same shape as the calendar fix in #24493, reported by Matteo Panzeri while
auditing the resource-cohort cohort during follow-up on #24493.

Co-authored-by: Matteo Panzeri <28739806+matte1782@users.noreply.github.com>
2026-05-09 23:19:03 +09:00
..
analytics.py chore: format 2026-04-12 18:12:59 -05:00
audio.py chore: format 2026-05-09 15:25:27 +09:00
auths.py fix:image url validation and signout post (#24420) 2026-05-09 07:33:31 +09:00
automations.py refac 2026-04-21 13:46:39 +09:00
calendar.py fix: gate public sharing of calendars behind sharing.public_calendars permission (#24493) 2026-05-09 23:18:51 +09:00
channels.py refac 2026-04-21 15:41:07 +09:00
chats.py refac 2026-05-09 08:28:29 +09:00
configs.py chore: format 2026-05-09 15:25:27 +09:00
evaluations.py chore: format 2026-04-12 18:12:59 -05:00
files.py Refactor file processing to use asyncio for transcribing, improving concurrency. (#24379) 2026-05-09 03:17:47 +09:00
folders.py chore: format 2026-04-12 18:12:59 -05:00
functions.py chore: format 2026-04-21 15:52:00 +09:00
groups.py refac: async db 2026-04-12 14:22:11 -05:00
images.py chore: format 2026-05-09 21:07:08 +09:00
knowledge.py chore: format 2026-04-19 22:45:54 +09:00
memories.py chore: format 2026-04-17 14:28:18 +09:00
models.py fix:image url validation and signout post (#24420) 2026-05-09 07:33:31 +09:00
notes.py Merge pull request #24486 from Classic298/fix/notes-is-pinned-typeerror 2026-05-09 20:56:06 +09:00
ollama.py refac 2026-05-09 04:17:58 +09:00
openai.py chore: format 2026-05-09 15:25:27 +09:00
pipelines.py refac 2026-04-20 08:53:06 +09:00
prompts.py perf(prompts): make /tags fetch only the tags column with SQL access filter (#24287) 2026-05-09 05:20:13 +09:00
retrieval.py feat: brave search llm context 2026-05-09 06:34:25 +09:00
scim.py refac: async db 2026-04-12 14:22:11 -05:00
skills.py fix: gate public sharing of skills behind sharing.public_skills on create/update (#24494) 2026-05-09 23:19:03 +09:00
tasks.py refac 2026-05-09 05:14:55 +09:00
terminals.py refac 2026-04-20 08:36:24 +09:00
tools.py chore: format 2026-04-24 18:48:21 +09:00
users.py fix: gate public sharing of calendars behind sharing.public_calendars permission (#24493) 2026-05-09 23:18:51 +09:00
utils.py refac 2026-04-13 14:08:58 -05:00