Files
open-webui/backend/open_webui/routers
Classic298andwhyiug 707efeaed7 fix: scope knowledge sync cleanup deletions to the target knowledge base (#26722)
POST /knowledge/{id}/sync/cleanup verified write access to the knowledge base in the URL but then acted on the caller-supplied file_ids and dir_ids without checking they belong to that knowledge base. A user with write access to any knowledge base could pass another knowledge base's directory id to delete its directory subtree and knowledge_file associations, or another file's id to drop its file-{file_id} vector collection. Fetch each directory and skip any whose knowledge_id does not match the URL id (matching the explicit directory-delete endpoint), and gate the per-file vector cleanup on Knowledges.has_file(id, file_id) so a foreign file id cannot trigger collection deletion. Legitimate same-knowledge-base cleanup is unchanged.

Co-authored-by: whyiug <whyiug@users.noreply.github.com>
2026-07-27 02:18:38 -04:00
..
2026-06-29 01:38:41 -05:00
2026-07-26 19:34:41 -04:00
2026-06-29 13:03:14 -05:00
2026-07-27 00:12:47 -04:00
2026-07-24 02:36:10 -04:00
2026-07-20 22:11:42 -04:00
2026-07-26 19:10:41 -04:00
2026-06-29 05:47:21 -05:00
2026-07-23 21:29:33 -04:00
2026-07-27 01:59:17 -04:00
2026-07-20 22:11:42 -04:00
2026-07-16 01:27:52 -04:00
2026-07-23 21:29:33 -04:00
2026-06-29 13:03:14 -05:00
2026-06-25 03:31:45 +01:00
2026-07-17 04:11:11 -04:00
2026-07-16 21:57:43 -04:00
2026-07-24 01:44:30 -04:00
2026-06-17 02:52:35 +02:00