open-webui/backend/open_webui
Claude ff48c99d6c
fix(stream): address code review findings on resume-stream
- Critical (auth): the resume-stream handler verified chat ownership but
  not that the requested message_id actually lives in that chat. Because
  the Redis log is keyed by message_id alone, an attacker who learned a
  victim's message_id could pass one of their own chat_ids to satisfy
  the ownership check and replay the victim's stream. Added an explicit
  message-to-chat binding check via Chats.get_message_by_id_and_message_id
  after the ownership check.

- Safety: reject non-dict payloads (`if not isinstance(data, dict)`) so
  stray client input — string/list/null — doesn't raise AttributeError
  on `data.get(...)`.

- Perf: the per-token log append was doing two Redis round-trips (XADD +
  EXPIRE) on the streaming hot path. Collapse them into a single pipeline
  execute (one RTT), and refresh the TTL only every 64 appends instead
  of every append. With a 1h TTL that still leaves comfortable headroom
  for even pathologically long responses without EXPIRE ever risking
  mid-stream expiry.

- Protocol cleanup: removed the resume-stream:ack emission. The frontend
  doesn't consume it and YAGNI — the seq idempotency guard in
  chatEventHandler already delivers the observability (you can see
  last_seq advance as replays arrive). Can be added back when a concrete
  client-side use case appears.
2026-04-14 21:16:39 +00:00
..
data refac: mv backend files to /open_webui dir 2024-09-04 16:54:48 +02:00
internal refac 2026-04-12 19:41:02 -05:00
migrations refac 2026-04-01 18:26:46 -05:00
models refac 2026-04-13 21:29:03 -05:00
retrieval fix(retrieval): offload Loader.load to a worker thread so file uploads stop blocking the event loop (#23705) 2026-04-14 10:55:46 -05:00
routers fix(retrieval): offload Loader.load to a worker thread so file uploads stop blocking the event loop (#23705) 2026-04-14 10:55:46 -05:00
socket fix(stream): address code review findings on resume-stream 2026-04-14 21:16:39 +00:00
static refac 2026-03-23 23:39:52 -05:00
storage refac 2026-04-12 19:08:30 -05:00
test refac 2026-03-17 17:58:01 -05:00
tools fix(retrieval): offload sync VECTOR_DB_CLIENT calls in async paths via AsyncVectorDBClient (#23706) 2026-04-14 10:50:18 -05:00
utils refac 2026-04-14 10:55:11 -05:00
__init__.py refac (#22987) 2026-03-24 15:41:26 -05:00
alembic.ini fix: Alembic CLI commands from failing 2025-08-15 04:17:47 -04:00
config.py refac 2026-04-14 00:07:50 -05:00
constants.py refac 2026-04-13 14:08:58 -05:00
env.py refac 2026-04-13 16:25:44 -05:00
functions.py refac: async db 2026-04-12 14:22:11 -05:00
main.py fix(middleware): replace BaseHTTPMiddleware HTTP middlewares with pure ASGI implementations (#23709) 2026-04-14 10:47:48 -05:00
tasks.py refac 2026-03-17 17:58:01 -05:00