Files
open-webui/backend/open_webui
Classic298andGabrielGomesAL 4f93c3e36c fix: authorize before cancelling tasks in the chat delete endpoint (#27006)
DELETE /api/v1/chats/{id} called stop_item_tasks(id) before checking the
caller's chat.delete permission or ownership of the target chat. An
authenticated user who knew another user's chat id could therefore cancel that
chat's in-flight generation (streaming response, title or tag generation) even
though the deletion was then rejected. The chat id is discoverable through
legitimate read-only access to a shared chat or folder.

Reorder the handler to authorize first (admin, or owner holding chat.delete) and
only then cancel tasks and delete, matching the dedicated task-stop endpoint.
Legitimate deletions are unchanged; an unauthorized caller now returns 404 or 401
before any cancellation. The duplicated tag-cleanup and event-publish blocks are
merged.

Co-authored-by: GabrielGomesAL <193945687+GabrielGomesAL@users.noreply.github.com>
2026-07-26 18:57:35 -04:00
..
…
2026-07-24 01:54:36 -04:00
2026-07-26 18:46:39 -04:00
2026-07-26 18:54:17 -04:00
2026-07-20 22:27:13 -04:00
2026-06-17 03:01:11 +02:00
2026-06-29 05:46:51 -05:00
2026-07-26 18:36:49 -04:00
2026-07-23 03:39:56 -04:00
2026-07-26 18:46:39 -04:00
2026-07-16 21:57:43 -04:00