open-webui/backend/open_webui/utils
Classic298 d2e62db69b
fix: stop the sign-in rate limiter blocking the loop and leaking memory (#29977)
A slow Redis freezes the whole worker during sign-in, not just the user signing in. RateLimiter held a synchronous redis-py client and signin called is_limited inline from a coroutine, so every attempt did blocking round trips on the event-loop thread, with REDIS_SOCKET_TIMEOUT defaulting to None so nothing bounded the wait. Its Redis methods are now async and take the handle as their first argument, and both handlers pass request.app.state.redis, the async client the lifespan already creates. Building one in the limiter instead would pin its pooled connection to the first event loop that used it.

Without Redis, which is the default single-instance setup, the fallback store leaked. It was keyed by the rate-limit key and pruned a key's expired buckets only when that same key was checked again, so a login email never seen again was never reclaimed, and that email comes straight from an unauthenticated request body. It is now keyed by bucket, so one prune drops every key an expired bucket held, and it lives on the instance: pruning uses the per-instance num_buckets, so a shared store would let a limiter with a short window delete buckets a longer-windowed one still needs.

With a Redis costing a second per call, the widest event-loop tick gap drops from 2.010s to 0.010s and a concurrent request is answered at 0.05s instead of 2.05s, at no cost to the caller's own latency. Across 20,000 distinct keys the store goes from 40,000 entries and 6.4 MB, growing linearly, to a flat 1,004 entries and 100 KB. Rate-limiting decisions are unchanged across 700,000 randomised calls over 14 window, bucket and limit combinations, against a real Redis and the in-memory fallback alike, and sign-in still returns its first 429 on attempt 16.

Two behaviour changes worth naming. Pruning is now global rather than per key, so a wall clock that jumps forward past a full window and back forgets a hit it previously kept. The two limiters also stop sharing a store, which previously let a sign-in attempt with an IP-shaped email touch the token-exchange limiter's counters.
2026-09-13 20:28:41 -05:00
..
access_control refac 2026-09-07 12:40:44 -04:00
images perf: build debug log messages lazily so disabled debug logs cost nothing (#27834) 2026-07-31 19:09:01 -05:00
mcp refac 2026-09-12 14:57:22 -04:00
telemetry refac(telemetry): drop deprecated semconv SpanAttributes subclass (#25784) 2026-06-29 02:05:34 -05:00
actions.py fix: enforce action availability and model access on the chat action route (#27243) 2026-07-23 12:23:05 -04:00
anthropic.py fix: drop thinking blocks when converting Anthropic Messages requests to Chat Completions (#29849) 2026-09-12 15:56:59 -05:00
asgi_middleware.py refac 2026-08-24 18:29:36 -04:00
ask_user.py fix: a rejected ask_user call ending the turn with no reply (#29252) 2026-08-31 00:17:21 -04:00
audit.py perf: build debug log messages lazily so disabled debug logs cost nothing (#27834) 2026-07-31 19:09:01 -05:00
auth.py refac 2026-09-12 19:45:42 -04:00
automations.py refac 2026-09-12 16:56:26 -04:00
calendar.py refac 2026-08-29 16:14:32 -04:00
channels.py refac 2026-03-17 17:58:01 -05:00
chat.py fix: surface upstream errors on arena models instead of crashing (#29662) 2026-09-04 17:17:02 -04:00
chat_fork.py refac 2026-07-23 02:54:56 -04:00
chat_id.py refac 2026-07-26 21:12:14 -04:00
chat_variables.py perf: stabilize the model registry signature across workers (#29264) 2026-08-30 16:12:31 -04:00
code_interpreter.py refac 2026-07-31 17:41:14 -04:00
context_compaction.py refac 2026-08-23 13:36:53 -04:00
embeddings.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
files.py refac 2026-08-31 00:11:13 -04:00
filter.py refac 2026-08-31 01:29:36 -04:00
groups.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
headers.py refac 2026-09-12 15:41:57 -04:00
json_codec.py perf: write task payloads to Redis as bytes (#28833) 2026-08-20 12:58:52 -07:00
json_response.py perf: optional orjson JSON codec behind ENABLE_ORJSON (#27583) 2026-07-27 03:45:37 -04:00
logger.py perf: stop formatting every exported log record twice under OTEL log export (#27840) 2026-08-10 23:13:52 -06:00
memory.py refac 2026-08-10 19:28:21 -06:00
middleware.py refac 2026-09-12 20:23:50 -04:00
misc.py refac 2026-08-31 00:39:16 -04:00
model_ids.py refac 2026-07-26 23:09:22 -04:00
models.py refac 2026-09-07 12:40:44 -04:00
notifications.py fix: sanitize user-typed notification target ids the same way generated ones are (#29947) 2026-09-12 13:50:19 -05:00
oauth.py refac 2026-09-08 12:38:07 -04:00
payload.py refac 2026-08-16 22:56:19 -07:00
plugin.py perf: build info log messages lazily so raising the log level actually saves work (#27837) 2026-08-02 15:39:10 -05:00
rate_limit.py fix: stop the sign-in rate limiter blocking the loop and leaking memory (#29977) 2026-09-13 20:28:41 -05:00
redis.py fix: Set default Redis socket timeout to None (#27104) 2026-07-27 00:30:00 -04:00
response.py refac 2026-08-17 00:57:57 -07:00
sanitize.py refac 2026-03-17 17:58:01 -05:00
security_headers.py refac 2026-08-24 18:29:36 -04:00
session_pool.py fix: long streamed lines no longer abort the response (#28114) 2026-08-25 12:16:37 -04:00
subagents.py chore: format 2026-08-25 16:53:53 -04:00
task.py refac 2026-06-19 00:16:06 +02:00
terminals.py refac 2026-08-19 22:48:32 -07:00
timers.py fix: index the chat queries that make large SQLite instances unusable (#27663) 2026-08-23 16:11:54 -05:00
tool_approval.py chore: format 2026-08-25 16:53:53 -04:00
tools.py refac 2026-09-07 12:16:09 -04:00
validate.py refac 2026-07-27 19:39:36 -04:00
valves.py refac 2026-07-31 17:41:14 -04:00
webhook.py perf: build debug log messages lazily so disabled debug logs cost nothing (#27834) 2026-07-31 19:09:01 -05:00