From 05252e19b54157cfa94202b8503205c9d5d3e16c Mon Sep 17 00:00:00 2001 From: Jacob Leksan <63938553+jmleksan@users.noreply.github.com> Date: Wed, 25 Mar 2026 17:34:45 -0400 Subject: [PATCH] refactor: streamline logging and permission checks in auths.py (#22960) --- backend/open_webui/routers/auths.py | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/backend/open_webui/routers/auths.py b/backend/open_webui/routers/auths.py index 367ea4478c..88f0fe69fb 100644 --- a/backend/open_webui/routers/auths.py +++ b/backend/open_webui/routers/auths.py @@ -1155,8 +1155,9 @@ async def update_ldap_config(request: Request, form_data: LdapConfigForm, user=D # create api key @router.post('/api_key', response_model=ApiKey) async def generate_api_key(request: Request, user=Depends(get_current_user), db: Session = Depends(get_session)): - if not request.app.state.config.ENABLE_API_KEYS or not has_permission( - user.id, 'features.api_keys', request.app.state.config.USER_PERMISSIONS + if not request.app.state.config.ENABLE_API_KEYS or ( + user.role != 'admin' + and not has_permission(user.id, 'features.api_keys', request.app.state.config.USER_PERMISSIONS) ): raise HTTPException( status_code=status.HTTP_403_FORBIDDEN,