From 41573d52f19070097c4e65a82818493ebd412530 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Mon, 27 Jul 2026 06:44:31 +0200 Subject: [PATCH] fix: require an authenticated user on the Ollama version route (#27199) get_ollama_versions was the only Ollama route besides the static health check without an authentication dependency, so an anonymous caller could read the configured backend's version string and, by walking url_idx until the lookup raised, count the configured backends. Nothing depends on the route being public. The frontend wrapper takes a token and sends it on every call, and its three call sites (admin model management, the model selector and the About panel) all pass an authenticated token, so the client already treats this as an authenticated route. Add the same get_verified_user dependency the sibling routes carry. Co-authored-by: Grg0rry --- backend/open_webui/routers/ollama.py | 1 + 1 file changed, 1 insertion(+) diff --git a/backend/open_webui/routers/ollama.py b/backend/open_webui/routers/ollama.py index 4610146cc3..f9b1468458 100644 --- a/backend/open_webui/routers/ollama.py +++ b/backend/open_webui/routers/ollama.py @@ -536,6 +536,7 @@ async def get_ollama_loaded_models( @router.get('/api/version/{url_idx}') async def get_ollama_versions( request: Request, + user=Depends(get_verified_user), url_idx: int | None = None, ): """Return the lowest Ollama version across all configured backends."""