Files
open-webui/backend/open_webui/routers
Classic298andrexpository 6d4c02a89e refac: owner-bind ephemeral web-search RAG collections (#26706)
The web-search-* namespace was the one collection namespace filter_accessible_collections admitted unconditionally for any non-admin user, on both read and write, unlike file-*, user-memory-* and knowledge bases which are owner-scoped. process_web_search now mints these ephemeral per-query collections as web-search-{user.id}-<hash>, and the access helper only admits web-search-{requester.id}-* names, so a web-search collection is readable and writable only by the user who created it (admins keep their bypass). The collections hold transient public web-search results and their names are non-enumerable query hashes, so there was no demonstrated cross-user access path; this removes the namespace exception so the per-user scoping the other namespaces enforce also covers web-search.

Co-authored-by: rexpository <rexpository@users.noreply.github.com>
2026-07-27 02:08:04 -04:00
..
2026-06-29 01:38:41 -05:00
2026-07-26 19:34:41 -04:00
2026-06-29 13:03:14 -05:00
2026-07-27 00:12:47 -04:00
2026-07-24 02:36:10 -04:00
2026-07-20 22:11:42 -04:00
2026-07-26 19:10:41 -04:00
2026-06-29 05:47:21 -05:00
2026-07-23 21:29:33 -04:00
2026-07-27 01:59:17 -04:00
2026-07-27 01:59:17 -04:00
2026-07-20 22:11:42 -04:00
2026-07-16 01:27:52 -04:00
2026-07-23 21:29:33 -04:00
2026-06-29 13:03:14 -05:00
2026-06-25 03:31:45 +01:00
2026-07-17 04:11:11 -04:00
2026-07-16 21:57:43 -04:00
2026-07-24 01:44:30 -04:00
2026-06-17 02:52:35 +02:00