Files
open-webui/backend/open_webui
Classic298andbogdancherniy11-sudo 3fe829acc2 fix: strip model params for read-only callers in the model list endpoint (#27004)
The per-id model endpoint (GET /api/v1/models/model) strips params, the system
prompt and other curated model config, for callers who only have read access.
The list endpoint (GET /api/v1/models/list) did not: it returned each
read-accessible model's full params, so a read-shared model exposed its
params.system to non-owner read-grant holders.

Mirror the per-id behaviour: compute write_access per item and drop params
before serialising when the caller lacks write access (not the owner, not an
admin under BYPASS_ADMIN_ACCESS_CONTROL and holding no write grant). The
model-card list UI does not render params, so this does not change
functionality.

Co-authored-by: bogdancherniy11-sudo <229690748+bogdancherniy11-sudo@users.noreply.github.com>
2026-07-27 01:51:29 -04:00
..
…
2026-07-27 00:12:47 -04:00
2026-07-27 00:12:47 -04:00
2026-07-27 01:21:32 -04:00
2026-07-26 23:49:03 -04:00
2026-07-20 22:27:13 -04:00
2026-07-27 00:27:38 -04:00
2026-06-17 03:01:11 +02:00
2026-07-27 00:12:47 -04:00
2026-06-29 05:46:51 -05:00
2026-07-27 01:21:32 -04:00
2026-07-26 19:10:41 -04:00
2026-07-23 03:39:56 -04:00
2026-07-27 01:46:10 -04:00
2026-07-26 22:45:11 -04:00