Commit Graph
9857 Commits
Author SHA1 Message Date
G30 bcb50fe7b0 fix: derive integrations toggle state from the selected ids (#28807) 2026-08-19 12:46:17 -05:00
Classic298 21e390561d fix: revoke existing sessions when a password changes (#28725)
Changing a password left every other logged-in device working until the JWT expired on its own, up to four weeks with the default settings. The hardening docs already promise the opposite: with Redis configured a password change is supposed to put the user's tokens on the revocation list, but only sign-out and OIDC back-channel logout ever wrote to it.

Both password-change paths, self-service and an admin resetting someone's password, now stamp the per-user revocation marker that token validation already checks, so every session issued before the change stops working. The acting device is signed out as well and asked to sign in again, which is the safer default when the password is being changed precisely because the old one may be compromised. Without Redis nothing can be revoked, as before, and the backend now logs a warning saying so.

The marker is written through one shared helper, so its lifetime follows the configured JWT lifetime instead of a fixed 30 days and never expires at all when JWT_EXPIRES_IN disables expiry. Back-channel logout picks that up too, where a long or disabled JWT lifetime previously let the marker expire while the tokens it revoked were still valid. API keys keep working, they are separate credentials with their own lifecycle.

Discussed in #28647.
2026-08-17 13:56:29 -07:00
G30 7ea46a37d0 fix: clip settings modal contents to its rounded corners (#27617) 2026-08-17 02:12:26 -06:00
Timothy Jaeryang Baek b1dc945bd6 refac 2026-08-17 00:59:13 -07:00
Timothy Jaeryang Baek 87d9b7e84e refac 2026-08-17 00:51:04 -07:00
Timothy Jaeryang Baek 6e468c5b95 refac 2026-08-17 00:50:54 -07:00
Timothy Jaeryang Baek 76d0160295 refac 2026-08-17 00:31:01 -07:00
G30 695d33aa7c fix: let the chat column shrink so the collapsed sidebar rail is not pushed off screen (#28501) 2026-08-17 01:23:25 -06:00
G30 31897b7e34 fix: stop channel message hover actions overlapping code and table toolbars (#27737) 2026-08-17 01:20:54 -06:00
Timothy Jaeryang Baek ad8c79f686 refac 2026-08-17 00:18:35 -07:00
Timothy Jaeryang Baek 0007369f4e refac 2026-08-17 00:16:11 -07:00
Timothy Jaeryang Baek d2af19ae3c refac 2026-08-17 00:15:36 -07:00
Timothy Jaeryang Baek f100edb708 refac 2026-08-17 00:12:13 -07:00
G30 90724cdee0 fix: drop the white backdrop behind model icons in the admin Models list (#27612) 2026-08-17 01:03:37 -06:00
Classic298 3df485582d fix: reject skill IDs that are not URL path safe (#27660)
A skill ID goes straight into the path of every mutating skill endpoint (/api/v1/skills/id/{id}/...), but create only replaced spaces with hyphens. An ID containing a "/" was stored verbatim as the primary key, so the route never matched, the request fell through to the SPA static mount and the client got 405 Method Not Allowed. The skill could not be opened, edited, toggled or deleted, by admins either, and since skill.name is UNIQUE it could not be recreated under a corrected ID. Percent-encoding does not help: uvicorn decodes the path before Starlette routes it, so the only remaining fix was a direct database write.

Create now rejects any ID outside [a-z0-9_-] with 400 instead of silently storing an unreachable one. Two frontend paths that fed unsanitized IDs into it are fixed as well: the manual "Skill ID" field, which was bound with no sanitization at all and is the path that reproduces on every version, and the markdown import, which put the raw frontmatter name into the ID before opening the editor in clone mode, where the reactive slugify is disabled.

Existing rows with an unreachable ID are not repaired here; rewriting a primary key would also have to re-point the access grants keyed on it.

Fixes #27655
2026-08-17 00:52:16 -06:00
Timothy Jaeryang Baek 954613944b refac 2026-08-16 23:51:38 -07:00
Timothy Jaeryang Baek 75df30c0ea refac 2026-08-16 23:47:02 -07:00
G30 2813eb44f2 fix: stop the What's New modal drawing two bullets per changelog entry (#28676) 2026-08-17 00:40:57 -06:00
G30 ad72dc6658 fix: scroll to the top of a chat on the first click of Scroll to Top (#28659) 2026-08-17 00:40:14 -06:00
G30 884388cac3 fix(search): wire up mark as unread in the search chats modal (#28136) 2026-08-17 00:34:49 -06:00
Timothy Jaeryang Baek 736e38338e refac 2026-08-16 23:32:23 -07:00
Timothy Jaeryang Baek a40f6f2860 refac 2026-08-16 23:28:48 -07:00
Timothy Jaeryang Baek b5da50f3df refac 2026-08-16 23:26:24 -07:00
Classic298 1756c9d5d2 fix: default pinned models stop applying after a user's first page load (#28069)
Changing "Default Pinned Models" in admin settings had no effect for anyone who had already opened Open WebUI once. The sidebar copied the admin default into that user's own settings the first time it rendered and saved it to the server, which marked them as having customized their pins, so every later change to the default was ignored for them. Merely loading the page was enough, the user never had to touch a pin.

The default is now resolved for display only, through a shared store that falls back to the admin list while the user has no pins of their own, the same way default models already work. Nothing is written to the user's settings until they actually pin, unpin or reorder something, at which point their choice takes over for good. Unpinning everything still persists an empty list rather than snapping back to the default.

Users whose settings were already overwritten by the old behaviour keep that copy, since a stored pin list cannot be told apart from a deliberate one.

Fixes a drag-reorder path that mixed sidebar positions with stored ones, and stops the sidebar section reopening itself after any unrelated settings change.
2026-08-17 00:22:51 -06:00
Timothy Jaeryang Baek b211c407f4 refac 2026-08-16 23:14:08 -07:00
Timothy Jaeryang Baek e4694d6c3f refac 2026-08-16 22:59:10 -07:00
Timothy Jaeryang Baek f7a533cda6 refac 2026-08-16 22:57:01 -07:00
Timothy Jaeryang Baek 62fc436999 refac 2026-08-16 22:52:24 -07:00
Timothy Jaeryang Baek 31d08d592c refac 2026-08-15 01:10:14 -06:00
Timothy Jaeryang Baek 467be93e6d refac 2026-08-15 01:09:39 -06:00
Timothy Jaeryang Baek 7fc5fa1ff3 refac 2026-08-15 01:02:06 -06:00
Timothy Jaeryang Baek 3eb65f4715 refac 2026-08-15 00:06:38 -06:00
Timothy Jaeryang Baek 30f82788bc refac 2026-08-15 00:05:45 -06:00
Timothy Jaeryang Baek bbfdbd59f2 refac 2026-08-15 00:05:37 -06:00
Timothy Jaeryang Baek 98b9df0398 refac 2026-08-15 00:05:11 -06:00
Timothy Jaeryang Baek 0f821398ca refac 2026-08-14 23:52:13 -06:00
Timothy Jaeryang Baek 1b39ff352a refac 2026-08-14 23:50:34 -06:00
Timothy Jaeryang Baek a5ea732c1e refac 2026-08-14 23:47:00 -06:00
Timothy Jaeryang Baek 516cf1a9a6 refac 2026-08-14 21:44:13 -06:00
Timothy Jaeryang Baek a1579a01ff refac 2026-08-14 00:22:17 -06:00
Timothy Jaeryang Baek f7767d6be7 refac 2026-08-13 22:08:42 -06:00
Timothy Jaeryang Baek d9014b3483 refac 2026-08-13 22:01:33 -06:00
Timothy Jaeryang Baek 57bd08304e refac 2026-08-13 22:01:17 -06:00
Timothy Jaeryang Baek 14e4d72d9a refac 2026-08-13 22:01:15 -06:00
Timothy Jaeryang Baek 256cce505b refac 2026-08-13 21:51:04 -06:00
Timothy Jaeryang Baek 55c202e841 refac 2026-08-13 21:48:01 -06:00
Timothy Jaeryang Baek b4738d1a2e refac 2026-08-13 21:31:49 -06:00
Timothy Jaeryang Baek 083e351441 refac 2026-08-13 21:02:17 -06:00
Timothy Jaeryang Baek 7d99b2716a refac 2026-08-13 19:59:11 -06:00
Timothy Jaeryang Baek b018feb741 refac 2026-08-13 18:33:51 -06:00