Commit Graph
6322 Commits
Author SHA1 Message Date
Classic298 c3394288bb fix: repair Mistral OCR async upload (aiohttp.streams.FilePayload removed) (#25779)
_upload_file_async built its multipart body with
`aiohttp.streams.FilePayload(...)`, which no longer exists in aiohttp
(payload classes live in aiohttp.payload, and there is no FilePayload).
The reference sits inside a lazy closure, so import succeeds and only the
async Mistral OCR file-upload path blows up at runtime with
AttributeError on every call.

Mirror the working sync path: open the file in a context manager and let
MultipartWriter.append(file_obj, {...}) build a streaming
BufferedReaderPayload, with the POST issued inside the open() block so
the handle stays valid for the whole upload. Preserves the streaming /
memory-efficiency intent.

Found via the dependency-contract test suite (unit/deps/test_aiohttp.py),
which pins aiohttp.streams.FilePayload as absent.
2026-06-29 02:05:54 -05:00
Classic298 8a016931f1 refac(telemetry): drop deprecated semconv SpanAttributes subclass (#25784)
constants.py subclassed opentelemetry.semconv.trace.SpanAttributes, which
is deprecated since semconv 1.25.0 (emits a DeprecationWarning; the pinned
0.63b1 has it live). Source the legacy span-attribute keys from the
non-deprecated _incubating attribute modules instead:
  http.url / http.method / http.status_code  <- _incubating http_attributes
  db.name / db.statement / db.operation      <- _incubating db_attributes
The stable http module renamed these (http.request.method, ...), so only
the incubating module preserves the original values. Custom keys
(db.instance/type/ip/port, error.*, result.*) stay literals.

Verified: emitted attribute keys are byte-identical before/after for every
key instrumentors.py reads, and importing constants no longer emits a
DeprecationWarning.
2026-06-29 02:05:34 -05:00
G30 e69ce6e1c6 perf(channels): batch N+1 queries for reactions and thread replies (#25831)
Replace per-message database queries with batch IN-clause queries in
channel message handlers. This eliminates the N+1 query pattern that
caused ~102 queries per channel page load (50 messages × 2 queries each).

Changes:
- Add get_reactions_by_message_ids() to MessageTable: single query
  fetches all reactions for multiple messages using IN clause with
  User JOIN, returns dict[message_id, list[Reactions]]
- Add get_thread_reply_counts_by_message_ids() to MessageTable: single
  GROUP BY aggregate query returns (count, max_created_at) per parent,
  replacing full object loads just to call len()
- Refactor get_channel_messages(): 102 → 4 queries per page
- Refactor get_pinned_channel_messages(): 22 → 3 queries per page
- Refactor get_channel_thread_messages(): 53 → 4 queries per page
- Refactor send_notification(): N+1 membership check → batch set lookup
2026-06-29 02:05:16 -05:00
Timothy Jaeryang Baek 6050a94d77 refac 2026-06-29 02:03:58 -05:00
Classic298 5fd26b7549 docs: note pydub/audioop Python 3.13 constraint at the import (#25785)
pydub imports the stdlib `audioop`, removed in Python 3.13, so audio
preprocessing would break there. requires-python is already capped at
< 3.13; this one-line pointer flags what to handle (audioop-lts, or drop
pydub) before raising that cap.
2026-06-29 02:03:11 -05:00
Classic298andClaude Opus 4.8 b295a20b9d chore: bump Python backend dependencies, drop unused peewee (#25786)
* chore: bump Python backend dependencies, drop unused peewee

Minor/patch + reviewed major bumps across requirements.txt,
requirements-min.txt, pyproject.toml and uv.lock; playwright image bumped in
docker-compose.playwright.yaml. peewee/peewee-migrate removed (zero imports).

Security-relevant: cryptography 46->48, authlib 1.6.10->1.7.2, PyJWT 2.11->2.13,
requests 2.33.1->2.34.2, RestrictedPython 8.1->8.2, pillow 12.1.1->12.2.0.
Reviewed majors: redis 7->8, pymilvus ->2.6.14, azure-search-documents 11->12,
chardet 5->7, unstructured 0.18->0.22, pycrdt 0.12->0.13.

Testing:
- Resolution: `uv lock` resolves the full bumped set with no conflicts; uv.lock
  regenerated to match (peewee dropped, every pin including
  azure-search-documents==12.0.0 resolves).
- Per-dependency contract tests (external tests repo, unit/deps/): 105 files,
  2205 passed / 6 skipped, ruff-clean. One file per dependency pins the symbols,
  signatures and behaviour the backend actually uses, so an API removal/rename in
  a bumped version fails loudly instead of at runtime. Offline/deterministic.
- End-to-end embed->retrieve test driving transformers + sentence-transformers +
  chromadb together through Open WebUI's real RAG path (cached model, in-memory
  chroma, semantic retrieval asserted).
- Install/startup/health resolution gate added to the dep-bump workflow and the
  integration suite (uv/pip resolve + uvicorn /health + Playwright dev visibility).
- Bugs surfaced while testing each got an isolated fix branch + regression test:
  Mistral OCR aiohttp FilePayload (#25779), chroma has_collection (#25780),
  aiocache per-user model-cache key (security), otel semconv deprecation,
  pydub/audioop <3.13 note.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Bump python-multipart 0.0.22 -> 0.0.27 (CVE-2026-42561, CVE-2026-40347)

0.0.22 is affected by two DoS CVEs in the multipart parser that
Starlette/FastAPI run for every multipart/form-data request, so any
authenticated user hitting an upload endpoint can trigger them:
- CVE-2026-42561: unbounded part-header count/size -> CPU exhaustion (fixed 0.0.27)
- CVE-2026-40347: large multipart preamble/epilogue DoS (fixed 0.0.26)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 02:02:18 -05:00
G30 3c67774eb3 fix(auth): enforce settings.interface permission on /user/settings/update endpoint (#25996) 2026-06-29 01:53:20 -05:00
Timothy Jaeryang Baek ce4a323f43 refac 2026-06-29 01:52:07 -05:00
Timothy Jaeryang Baek 46c1d6591b refac 2026-06-29 01:41:43 -05:00
Timothy Jaeryang Baek 3730a9eaac refac 2026-06-29 01:38:41 -05:00
G30 677e164f29 feat(permissions): add workspace.skills_import and workspace.skills_export permissions (#25921) 2026-06-29 01:36:27 -05:00
Timothy Jaeryang Baek 7240517807 refac 2026-06-29 01:01:27 -05:00
Hrushikesh Yadav 1f6336fd98 fix: strip whitespace from user info headers to prevent MCP connection failures (#26182) 2026-06-29 00:57:07 -05:00
alvarellos 368b4a5b22 solve-valves-icon-disappear-issue (#26256) 2026-06-29 00:56:44 -05:00
Timothy Jaeryang Baek b854eb09b1 refac 2026-06-29 00:46:45 -05:00
Timothy Jaeryang Baek 7292cee868 refac 2026-06-29 00:42:39 -05:00
Timothy Jaeryang Baek bc70696f4f refac 2026-06-29 00:40:28 -05:00
Timothy Jaeryang Baek dbdcfd8c60 refac 2026-06-29 00:35:54 -05:00
Timothy Jaeryang Baek 7e13fd7ad1 refac 2026-06-29 00:26:35 -05:00
Timothy Jaeryang Baek 124c7a3283 refac 2026-06-29 00:21:37 -05:00
Timothy Jaeryang Baek cfb49c4c18 refac 2026-06-29 00:19:47 -05:00
Timothy Jaeryang Baek 2560533c1a refac 2026-06-29 00:18:40 -05:00
Timothy Jaeryang Baek 5b1c42e81a refac 2026-06-29 00:05:10 -05:00
Timothy Jaeryang Baek 97901220f2 refac 2026-06-28 23:28:03 -05:00
Timothy Jaeryang Baek 8977a10a2b refac 2026-06-28 23:24:24 -05:00
Timothy Jaeryang Baek ef8c9c063c refac 2026-06-28 23:22:10 -05:00
Timothy Jaeryang Baek dd4f43bfdb refac 2026-06-28 23:21:05 -05:00
Timothy Jaeryang Baek 3a232f5e9a refac 2026-06-28 23:20:54 -05:00
Timothy Jaeryang Baek 23d03d6aae refac 2026-06-28 23:10:14 -05:00
Timothy Jaeryang Baek d99ac7d3f8 refac 2026-06-28 23:02:38 -05:00
Timothy Jaeryang Baek 464e703e47 refac 2026-06-28 22:50:31 -05:00
Timothy Jaeryang Baek 516051304e refac 2026-06-28 22:33:59 -05:00
Timothy Jaeryang Baek 0130b49514 refac 2026-06-28 22:32:10 -05:00
Timothy Jaeryang Baek df634bb64f refac 2026-06-28 22:11:01 -05:00
Timothy Jaeryang Baek ea3f5f22d2 refac 2026-06-28 22:09:15 -05:00
Timothy Jaeryang Baek e3ba698453 refac 2026-06-25 17:34:41 -04:00
Timothy Jaeryang Baek 741b64edb6 refac 2026-06-25 17:23:53 -04:00
Timothy Jaeryang Baek 8f890f0b43 refac 2026-06-25 15:56:10 +01:00
Timothy Jaeryang Baek ede39d82de refac 2026-06-25 15:49:36 +01:00
Timothy Jaeryang Baek 1a8e1a9939 refac 2026-06-25 15:22:31 +01:00
Timothy Jaeryang Baek e124c2656a refac 2026-06-25 14:37:05 +01:00
Timothy Jaeryang Baek 5576e6ed8a refac 2026-06-25 14:34:22 +01:00
Timothy Jaeryang Baek 7453968678 refac 2026-06-25 14:19:30 +01:00
Timothy Jaeryang Baek b5c43968db refac 2026-06-25 03:31:45 +01:00
Timothy Jaeryang Baek 1111a3a222 refac 2026-06-25 03:26:07 +01:00
Timothy Jaeryang Baek f812072215 refac 2026-06-25 03:24:50 +01:00
Timothy Jaeryang Baek 8934bfb04b refac 2026-06-24 14:13:58 +02:00
Timothy Jaeryang Baek fd56086e79 refac 2026-06-24 13:19:55 +02:00
Timothy Jaeryang Baek 95391221df refac 2026-06-23 23:35:44 +02:00
Timothy Jaeryang Baek 19db873603 refac 2026-06-23 23:35:40 +02:00