Files
open-webui/backend/open_webui
Classic298andclassic298 0f8846b7fc fix: convert SecurityHeadersMiddleware to pure ASGI (#26924)
SecurityHeadersMiddleware was the last middleware in the stack still
subclassing BaseHTTPMiddleware, after CommitSession, AuthToken,
WebsocketUpgradeGuard and Redirect were all moved to pure ASGI in
utils/asgi_middleware.py. BaseHTTPMiddleware re-buffers the response
body through an anyio task group, which has known issues with
streaming and Content-Length-bearing responses (e.g. the FileResponse
returned by /api/v1/audio/speech).

Reimplement it as a pure-ASGI middleware that stamps the configured
security headers onto the http.response.start message via
MutableHeaders and forwards all body chunks untouched, matching the
pattern already used by its four siblings. set_security_headers() and
all its helpers are unchanged.

Co-authored-by: classic298 <classic298@users.noreply.github.com>
2026-07-10 13:29:14 -05:00
..
…
2026-06-29 12:40:20 -05:00
2026-07-01 03:37:35 -05:00
2026-07-01 03:01:46 -05:00
2026-07-01 02:20:16 -05:00
2026-07-09 17:59:17 -05:00
2026-06-29 03:58:00 -05:00
2026-06-01 14:10:40 -07:00
2026-07-09 17:31:43 -05:00
2026-06-17 03:01:11 +02:00
2026-07-09 18:02:37 -05:00
2026-06-29 05:46:51 -05:00
2026-07-09 17:28:05 -05:00
2026-07-09 17:28:34 -05:00
2026-07-09 17:28:34 -05:00
2026-07-09 17:28:34 -05:00