Files
open-webui/backend/open_webui
Classic298andwhyiug 707efeaed7 fix: scope knowledge sync cleanup deletions to the target knowledge base (#26722)
POST /knowledge/{id}/sync/cleanup verified write access to the knowledge base in the URL but then acted on the caller-supplied file_ids and dir_ids without checking they belong to that knowledge base. A user with write access to any knowledge base could pass another knowledge base's directory id to delete its directory subtree and knowledge_file associations, or another file's id to drop its file-{file_id} vector collection. Fetch each directory and skip any whose knowledge_id does not match the URL id (matching the explicit directory-delete endpoint), and gate the per-file vector cleanup on Knowledges.has_file(id, file_id) so a foreign file id cannot trigger collection deletion. Legitimate same-knowledge-base cleanup is unchanged.

Co-authored-by: whyiug <whyiug@users.noreply.github.com>
2026-07-27 02:18:38 -04:00
..
2026-07-27 00:12:47 -04:00
2026-07-27 02:11:10 -04:00
2026-07-27 02:17:16 -04:00
2026-07-26 23:49:03 -04:00
2026-07-20 22:27:13 -04:00
2026-07-27 02:17:11 -04:00
2026-06-17 03:01:11 +02:00
2026-07-27 00:12:47 -04:00
2026-06-29 05:46:51 -05:00
2026-07-27 01:21:32 -04:00
2026-07-26 19:10:41 -04:00
2026-07-23 03:39:56 -04:00
2026-07-26 22:45:11 -04:00