diff --git a/backend/open_webui/config.py b/backend/open_webui/config.py index 1b842940d9..43f0b01993 100644 --- a/backend/open_webui/config.py +++ b/backend/open_webui/config.py @@ -1806,6 +1806,9 @@ USER_PERMISSIONS_CALENDAR_ALLOW_PUBLIC_SHARING = ( USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_USERS = ( os.getenv('USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_USERS', 'True').lower() == 'true' ) +USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_GROUPS = ( + os.getenv('USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_GROUPS', 'True').lower() == 'true' +) USER_PERMISSIONS_CHAT_CONTROLS = os.getenv('USER_PERMISSIONS_CHAT_CONTROLS', 'True').lower() == 'true' @@ -1930,6 +1933,7 @@ DEFAULT_USER_PERMISSIONS = { }, 'access_grants': { 'allow_users': USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_USERS, + 'allow_groups': USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_GROUPS, }, 'chat': { 'controls': USER_PERMISSIONS_CHAT_CONTROLS, diff --git a/backend/open_webui/utils/access_control/__init__.py b/backend/open_webui/utils/access_control/__init__.py index a98f95f97e..b8d672cf99 100644 --- a/backend/open_webui/utils/access_control/__init__.py +++ b/backend/open_webui/utils/access_control/__init__.py @@ -253,6 +253,23 @@ async def filter_allowed_access_grants( ): access_grants = strip_user_access_grants(access_grants) + if any( + (grant.get('principal_type') if isinstance(grant, dict) else getattr(grant, 'principal_type', None)) + == 'group' + for grant in access_grants + ) and not await has_permission( + user_id, + 'access_grants.allow_groups', + default_permissions, + db=db, + ): + access_grants = [ + grant + for grant in access_grants + if (grant.get('principal_type') if isinstance(grant, dict) else getattr(grant, 'principal_type', None)) + != 'group' + ] + return access_grants