From 7b29834d4216e5db70b68f3598fa1ad654d3512b Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Wed, 17 Jun 2026 00:43:59 +0200 Subject: [PATCH] refac --- backend/open_webui/models/auths.py | 7 ++++++- backend/open_webui/utils/auth.py | 6 ------ 2 files changed, 6 insertions(+), 7 deletions(-) diff --git a/backend/open_webui/models/auths.py b/backend/open_webui/models/auths.py index 96f6c39703..00985c97b8 100644 --- a/backend/open_webui/models/auths.py +++ b/backend/open_webui/models/auths.py @@ -6,9 +6,9 @@ import logging import uuid from typing import Optional +import bcrypt from open_webui.internal.db import Base, JSONField, get_async_db_context from open_webui.models.users import User, UserModel, UserProfileImageResponse, Users -from open_webui.utils.auth import PLACEHOLDER_HASH from open_webui.utils.validate import validate_profile_image_url from pydantic import BaseModel, field_validator from sqlalchemy import Boolean, Column, String, Text, delete, select, update @@ -16,6 +16,11 @@ from sqlalchemy.ext.asyncio import AsyncSession log = logging.getLogger(__name__) +# Pre-computed hash verified on signin paths that lack a real credential +# (unknown user, inactive account) so response timing cannot reveal +# whether an account exists (CWE-208). +PLACEHOLDER_HASH = bcrypt.hashpw(b'placeholder', bcrypt.gensalt()).decode('utf-8') + class Auth(Base): # credential ↔ user linkage """Maps a user ID to an email/password pair with an active flag.""" diff --git a/backend/open_webui/utils/auth.py b/backend/open_webui/utils/auth.py index 85e6706d95..26cea6b45f 100644 --- a/backend/open_webui/utils/auth.py +++ b/backend/open_webui/utils/auth.py @@ -162,12 +162,6 @@ def get_password_hash(password: str) -> str: return bcrypt.hashpw(password.encode('utf-8'), bcrypt.gensalt()).decode('utf-8') -# Pre-computed hash verified on signin paths that lack a real credential -# (unknown user, inactive account) so response timing cannot reveal -# whether an account exists (CWE-208). -PLACEHOLDER_HASH = get_password_hash('placeholder') - - def validate_password(password: str) -> bool: # The password passed to bcrypt must be 72 bytes or fewer. If it is longer, it will be truncated before hashing. if len(password.encode('utf-8')) > 72: