Files
open-webui/backend/open_webui/routers
Classic298andbogdancherniy11-sudo 3fe829acc2 fix: strip model params for read-only callers in the model list endpoint (#27004)
The per-id model endpoint (GET /api/v1/models/model) strips params, the system
prompt and other curated model config, for callers who only have read access.
The list endpoint (GET /api/v1/models/list) did not: it returned each
read-accessible model's full params, so a read-shared model exposed its
params.system to non-owner read-grant holders.

Mirror the per-id behaviour: compute write_access per item and drop params
before serialising when the caller lacks write access (not the owner, not an
admin under BYPASS_ADMIN_ACCESS_CONTROL and holding no write grant). The
model-card list UI does not render params, so this does not change
functionality.

Co-authored-by: bogdancherniy11-sudo <229690748+bogdancherniy11-sudo@users.noreply.github.com>
2026-07-27 01:51:29 -04:00
..
2026-06-29 01:38:41 -05:00
2026-07-26 19:34:41 -04:00
2026-06-29 13:03:14 -05:00
2026-07-27 00:12:47 -04:00
2026-07-24 02:36:10 -04:00
2026-07-20 22:11:42 -04:00
2026-07-26 19:10:41 -04:00
2026-06-29 05:47:21 -05:00
2026-07-23 21:29:33 -04:00
2026-06-29 13:03:14 -05:00
2026-07-20 22:11:42 -04:00
2026-07-16 01:27:52 -04:00
2026-07-23 21:29:33 -04:00
2026-06-29 13:03:14 -05:00
2026-06-25 03:31:45 +01:00
2026-07-17 04:11:11 -04:00
2026-07-16 21:57:43 -04:00
2026-07-24 01:44:30 -04:00
2026-06-17 02:52:35 +02:00