open-webui/backend
Claude e6199613c3
fix(stream): require chat_id, cap replay payload bytes
- resume_stream now requires both message_id AND chat_id in the
  payload; rejects otherwise. Previously chat_id was optional and
  replay would fall through to user-scoped-key-only validation when
  missing. With the frontend now always sending chat_id (since
  72429ea), the fallback was effectively dead code and weakened the
  auth posture. Made the requirement explicit and fail-closed.
  Collapsed the \`if chat_id:\` branch that handled the optional
  case into unconditional ownership validation.

- Cap resume-stream:replay payload to 900KB (under Socket.IO's
  default 1MB buffer). The most recent entries that fit are kept;
  older ones are dropped. Older content is already reflected in the
  DB-backed content the client loads on refresh, and the final
  done:True checkpoint reconciles anything else. Prevents the
  pathological case of a 2000-entry log full of large structural
  envelopes blowing past the Socket.IO buffer limit.

Deferred: cross-worker live-frame ordering. Still a documented
limitation in get_event_emitter's block comment. A distributed lock
per message_id is the only real fix and is a significant addition
of infrastructure dependency for a rare scenario.
2026-04-15 08:23:53 +00:00
..
data refac: mv backend files to /open_webui dir 2024-09-04 16:54:48 +02:00
open_webui fix(stream): require chat_id, cap replay payload bytes 2026-04-15 08:23:53 +00:00
.dockerignore fix: litellm config issue 2024-02-24 22:35:11 -08:00
.gitignore refac 2024-09-06 04:59:20 +02:00
dev.sh refac 2026-03-24 19:43:30 -05:00
requirements-min.txt refac 2026-04-13 23:40:09 -05:00
requirements.txt refac 2026-04-13 23:40:09 -05:00
start.sh refac 2026-03-24 19:43:30 -05:00
start_windows.bat refac 2026-03-24 19:43:30 -05:00