Commit Graph
3680 Commits
Author SHA1 Message Date
Timothy Jaeryang Baek 809d9f29f3 refac 2026-07-14 01:47:50 -04:00
Timothy Jaeryang Baek bcf449d5ad refac 2026-07-14 01:44:00 -04:00
Timothy Jaeryang Baek a62ba97467 refac 2026-07-14 01:41:40 -04:00
Timothy Jaeryang Baek b012d683d8 refac 2026-07-14 01:40:58 -04:00
Timothy Jaeryang Baek 6e14d0d627 refac 2026-07-14 01:39:40 -04:00
Timothy Jaeryang Baek 410ebb05d4 refac 2026-07-14 00:54:01 -04:00
Timothy Jaeryang Baek d38c953608 refac 2026-07-14 00:49:30 -04:00
Timothy Jaeryang Baek f1584b5a37 refac 2026-07-14 00:48:40 -04:00
Timothy Jaeryang Baek 009715cd63 refac 2026-07-14 00:22:00 -04:00
Timothy Jaeryang Baek 6a7068c3a4 refac 2026-07-14 00:21:47 -04:00
Timothy Jaeryang Baek 797293c749 refac 2026-07-14 00:19:41 -04:00
Timothy Jaeryang Baek 7088d245bb refac 2026-07-14 00:10:28 -04:00
Timothy Jaeryang Baek 8f07c0c8ee refac 2026-07-13 23:34:54 -04:00
Classic298 274729aa47 fix: socket reconnect recovery never runs for chats started from the home page (#26913)
When a chat is started from the home page, the URL is switched to /c/{id} with
history.replaceState, so the Chat component is never remounted and chatIdProp
stays empty for the lifetime of that view. Both websocket recovery paths,
handleSocketConnect and the chat:active fallback, are gated on chatIdProp and
therefore never run for these chats. After any websocket drop during a response
(mobile backgrounding, VPN or IP change, wake from sleep) the completed response
is never fetched and the chat stays stuck in a loading state until a manual page
refresh. Chats opened directly via /c/{id} recover fine, which is why the bug
only reproduces reliably on freshly started chats.

Gate both recovery paths on the chatId store instead, which is set for every
persisted chat, and let loadChat fall back to it so the recovery reload also
works when chatIdProp is empty. Chats opened via /c/{id} behave exactly as
before and temporary chats stay excluded.

The same gate likely explains the remaining reports in #26315.

Fixes #26844
2026-07-10 13:30:55 -05:00
Classic298andmanus-use 65a5fad7b9 fix: gate allow-same-origin on the terminal file-preview iframe to prevent same-origin XSS (#26907)
The system-terminal HTML file preview (FilePreview.svelte, serveUrl branch) rendered served HTML in an iframe that hardcoded allow-same-origin. The terminal proxy serves the file root-relative (same origin as the app) and injects no CSP, and there is no default global CSP, so script in a previewed HTML file executed in the application's own origin and could read localStorage (the session token), enabling account takeover and, for admin or workspace.functions victims, server-side RCE via Functions. The sibling srcdoc branch already gates allow-same-origin behind the iframeSandboxAllowSameOrigin setting (off by default) and injects a CSP; the serveUrl branch never received that defense. Gate allow-same-origin on the serveUrl branch identically, so by default the preview runs at an opaque origin and its scripts cannot reach the parent context. Legitimate HTML preview rendering is unaffected.

Co-authored-by: manus-use <manus-use@users.noreply.github.com>
2026-07-10 13:30:18 -05:00
Classic298 42f5c3d6f7 Merge pull request #26914 from Classic298/srcdoc-embed-prompt-confirmation
fix: restore prompt confirmation for sandboxed tool result embeds
2026-07-10 13:28:39 -05:00
Timothy Jaeryang Baek 6e030e892b refac 2026-07-09 18:28:38 -05:00
Timothy Jaeryang Baek 285379d489 refac 2026-07-09 17:43:13 -05:00
Timothy Jaeryang Baek 5ab012e7ae refac 2026-07-09 17:38:52 -05:00
Timothy Jaeryang Baek 975f7b868a refac 2026-07-09 17:32:45 -05:00
Algorithm5838 0e5540c2b2 fix: derive content from output for search (#26405) 2026-07-01 03:05:47 -05:00
Timothy Jaeryang Baek 4b08d65597 refac 2026-07-01 02:53:22 -05:00
Timothy Jaeryang Baek af1c0eee89 refac 2026-06-30 20:20:15 -05:00
Timothy Jaeryang Baek 6ed56b07c4 refac 2026-06-30 16:55:25 -05:00
Timothy Jaeryang Baek 403392b41b chore: format 2026-06-29 13:35:39 -05:00
Timothy Jaeryang Baek c33fadc266 refac 2026-06-29 13:30:32 -05:00
Timothy Jaeryang Baek 0443ab3a61 refac 2026-06-29 13:30:28 -05:00
Timothy Jaeryang Baek 24b8619f64 refac 2026-06-29 13:15:11 -05:00
Timothy Jaeryang Baek 55cb98ff56 refac 2026-06-29 13:03:30 -05:00
Timothy Jaeryang Baek 517cd8d102 refac 2026-06-29 13:03:14 -05:00
Timothy Jaeryang Baek 2c804b0ac4 refac 2026-06-29 12:55:10 -05:00
Timothy Jaeryang Baek 589b62b529 refac 2026-06-29 12:52:51 -05:00
Timothy Jaeryang Baek 21ac7e95a3 refac 2026-06-29 12:51:20 -05:00
Timothy Jaeryang Baek fb27716186 refac 2026-06-29 12:46:37 -05:00
Timothy Jaeryang Baek 37a9da50df refac 2026-06-29 12:46:32 -05:00
Timothy Jaeryang Baek db9977926c refac 2026-06-29 12:43:32 -05:00
Timothy Jaeryang Baek ae5d23f226 refac 2026-06-29 12:38:04 -05:00
G30 c584a4270c perf(ui): non-blocking model and tool server loading for unreachable connections (#26289)
- Move setModels() and setToolServers() out of the loaded gate in
  +layout.svelte so the page renders immediately instead of blocking
  behind slow/unreachable connection timeouts
- Track failed Ollama backend URLs from /api/tags and skip them in the
  subsequent /api/ps fan-out, eliminating a redundant second timeout
- Silence the autocomplete toast that fires during the transient empty
  model state
2026-06-29 12:34:00 -05:00
Timothy Jaeryang Baek c89fd237b8 refac 2026-06-29 12:16:05 -05:00
Timothy Jaeryang Baek 2856def6c0 refac 2026-06-29 12:12:23 -05:00
Timothy Jaeryang Baek 6f8221df58 refac 2026-06-29 11:59:29 -05:00
Algorithm5838 7572283517 fix: persist control revert to loaded value (#25793) 2026-06-29 11:37:30 -05:00
Timothy Jaeryang Baek 4ed45ce843 refac 2026-06-29 10:58:57 -05:00
Timothy Jaeryang Baek c7e634776d refac 2026-06-29 10:40:42 -05:00
Timothy Jaeryang Baek 260f3c3a22 refac 2026-06-29 05:56:08 -05:00
Timothy Jaeryang Baek e6d35fc4cc refac 2026-06-29 05:39:17 -05:00
Timothy Jaeryang Baek edf2c6c8f7 refac 2026-06-29 05:23:20 -05:00
Timothy Jaeryang Baek aa851d93c6 refac 2026-06-29 05:18:12 -05:00
Timothy Jaeryang Baek fa76764c3b refac 2026-06-29 05:16:57 -05:00
G30 4fa3a74827 fix(chat): prevent sortable sidebar drags from triggering file upload overlay (#25675)
Add a custom MIME type (application/x-open-webui-drag) to intentional
chat and folder drag sources. The onDragOver handler in MessageInput
now checks for this type instead of the generic text/plain, which
SortableJS also sets during reorder operations for pinned menu items
(Notes, Workspace) and pinned Models.
2026-06-29 04:58:30 -05:00