Commit Graph
18498 Commits
Author SHA1 Message Date
Timothy Jaeryang Baek 5bb321de06 refac 2026-09-12 17:43:01 -04:00
Classic298 08578557de refac: share one community origin allowlist across window message handlers (#29918)
The three community origins were repeated inline in five window message handlers and now come from a single COMMUNITY_ORIGINS constant in constants.ts.

The sync stats modal uses that same list in both directions: it reads messages only from a community origin, replies to the origin the message came from, and names the community origins as the targets of the messages it sends. Its chat id goes into the request as one encoded path segment.
2026-09-12 16:35:16 -05:00
G30 887372aca5 fix: apply the selection highlight only when the editor is unfocused and keep it out of the chat input (#29952) 2026-09-12 16:19:09 -05:00
Timothy Jaeryang Baek 0edd731c74 refac 2026-09-12 17:11:37 -04:00
Classic298 2a44c9d384 refac: validate the URL scheme before rendering a link href (#29890)
Link URLs rendered from markdown, citations and web search results now pass a scheme check before they reach an anchor. A new safeLinkUrl helper sits beside isValidHttpUrl and keeps http, https, mailto, tel and relative URLs, returning undefined for anything else so the label renders without a link. Markdown links with an unusual scheme (ftp, sms, and application deep links such as obsidian or vscode) render as plain text from now on.

The citation checks move off a substring test for "http" onto isValidHttpUrl, which is what Citations.svelte already uses for the same question. That also drops two long-standing quirks: an uppercase HTTP:// source never rendered as a link, and a filename merely containing "http" rendered as a dead external one.
2026-09-12 16:06:58 -05:00
Classic298 746caa7c78 fix: honor ENABLE_PROFILE_IMAGE_URL_FORWARDING for channel webhook profile images (#29889)
Setting ENABLE_PROFILE_IMAGE_URL_FORWARDING=false stops the user and model profile image endpoints from redirecting browsers to external avatar URLs, but channel webhook avatars kept redirecting regardless. An operator who turned the setting off precisely to stop clients leaking their IP, User-Agent and Referer to outside origins still leaked all three whenever anyone viewed a channel message posted by a webhook with an external profile image URL.

The webhook profile image endpoint now reads the same setting the user and model endpoints already read, and serves the bundled default image instead of the redirect when forwarding is off. Stored URLs are untouched, so turning the setting back on restores the previous behaviour.

Verified against the real handler with seeded webhook rows: with the setting unset or true the endpoint still returns the 302 with the original Location, with it false it returns the default favicon as image/png with no Location and no header carrying the external host, and the data URI, no image and unknown webhook responses are byte identical in both states.
2026-09-12 16:06:34 -05:00
G30 ee4834e299 fix: only log a reranking model change when the request carries one (#29922) 2026-09-12 16:04:14 -05:00
Timothy Jaeryang Baek a910b0d8f6 refac 2026-09-12 17:02:44 -04:00
Classic298 75b1836322 fix: drop thinking blocks when converting Anthropic Messages requests to Chat Completions (#29849)
* fix: drop thinking blocks when converting Anthropic Messages requests to Chat Completions

Claude Code and other Anthropic SDK clients pointed at /api/v1/messages send the assistant's earlier thinking blocks back with every follow-up request. Since 0.11.0 those blocks were copied into the OpenAI assistant message as content parts of type thinking, a part type Chat Completions does not define. Strict OpenAI-compatible servers such as NVIDIA Dynamo reject the whole request with 400 "data did not match any variant of untagged enum ChatCompletionRequestAssistantMessageContent", so a conversation with a reasoning model died on its second turn. The error reports its position at the very end of the body, which made the request look cut off; it was complete.

Thinking and redacted_thinking blocks are now skipped in the conversion, which is what happened before 0.11.0. An assistant turn that held only thinking blocks is kept as an empty assistant message so the turn order survives. Native Anthropic and LiteLLM connections are unaffected because they receive the request untouched, and thinking blocks in responses are still produced.

Fixes #29799

* fix: keep signed thinking blocks when converting Anthropic Messages requests

Dropping every thinking block also removed the signed ones. Those are the blocks a gateway such as LiteLLM forwards to Anthropic, which needs the signed thinking block of the previous assistant turn when a tool-use turn continues with extended thinking. Only the unsigned blocks are the problem: Open WebUI creates them itself from reasoning_content, and strict Chat Completions backends reject them because thinking is not a content part type they know.

Unsigned thinking blocks are now dropped while signed thinking and redacted_thinking blocks are kept, the same rule LiteLLM applies before forwarding to Anthropic and the rule the native chat path already uses for Anthropic reasoning details. Backends that never emit a signature, such as NVIDIA Dynamo and vLLM, keep receiving requests without thinking parts, so the original failure stays fixed.
2026-09-12 15:56:59 -05:00
Timothy Jaeryang Baek c78ad89934 refac 2026-09-12 16:56:26 -04:00
Timothy Jaeryang Baek 7a4a4b93dc refac 2026-09-12 15:41:57 -04:00
Timothy Jaeryang Baek ffae4116a8 refac 2026-09-12 14:57:22 -04:00
Classic298 0313ea0238 fix: stop every task of a chat when stopping a response without Redis (#29844)
Pressing Stop on a chat that has more than one running task (a multi-model
response, or a follow-up sent from another tab or device while a response
is still streaming) reported success but only cancelled the first task.
The survivors kept streaming and kept executing tool calls until the
iteration limit, which is the runaway reported in the issue.

Without Redis the stop loop iterates the live task-id list of the chat.
Each awaited cancellation runs that task's cleanup, which removes its id
from the same list mid-iteration, so the loop runs out one element early
and the last task is never cancelled. Returning a snapshot of the list to
callers keeps the loop on the ids it started with. Redis deployments
already got a fresh list from the set and were not affected.

Verified against a mock upstream that calls a tool on every turn: with three
tasks on one chat, stop left one or two alive before the change and cancels
all of them after it.

Fixes #29816
2026-09-12 13:55:13 -05:00
Dolores af54ea6283 i18n: update zh-TW (#29885) 2026-09-12 13:54:00 -05:00
G30 4ee53e051e fix: sanitize user-typed notification target ids the same way generated ones are (#29947) 2026-09-12 13:50:19 -05:00
Timothy Jaeryang BaekandG30 7aaa4a692e refac
Co-Authored-By: G30 <50341825+silentoplayz@users.noreply.github.com>
2026-09-10 19:05:36 -04:00
joaoback 5e7e38c035 i18n: add pt-BR translations for newly added UI items and consistency pass (#29870)
New **pt-BR** translations for items introduced in the latest releases, plus a consistency/quality pass across existing strings (grammar, tone, capitalization, pluralization). Placeholders and hotkeys preserved. No logic changes.
2026-09-10 13:57:43 -04:00
Timothy Jaeryang Baek 4948842bea chore: i18n 2026-09-09 23:34:25 -04:00
G30 eb9b7b659f fix: render mentions whose ID contains any non-whitespace character as chips (#29864)
* fix: render channel mentions whose ID contains spaces or parentheses, such as workspace model IDs

* fix: accept any non-whitespace mention ID, matching the model ID rule on dev
2026-09-09 19:27:35 -04:00
Timothy Jaeryang Baek 540467b90a refac 2026-09-09 19:16:16 -04:00
Timothy Jaeryang Baek 17dbc6f001 refac 2026-09-09 17:09:53 -04:00
Timothy Jaeryang Baek 8a19e2f867 refac 2026-09-09 17:09:45 -04:00
G30 14e30933af fix: render code blocks in channel model replies with the same editor as every other message (#29861) 2026-09-09 16:56:48 -04:00
Timothy Jaeryang Baek e35b907f73 refac 2026-09-09 16:39:44 -04:00
Classic298 44f9a4f7f9 fix: stop forwarding upstream Server and Date headers from the OpenAI and Ollama proxies (#29843)
Streamed chat completions and the other proxied OpenAI and Ollama responses
went out with two Server and two Date headers: the upstream's copies, forwarded
verbatim, plus uvicorn's own. nginx in front of Open WebUI logs "upstream sent
duplicate header line" for both on every streamed request.

Server and Date belong to whoever terminates the connection, so both proxies now
drop the upstream's copies next to the encoding headers they already stripped.
The filter also compares header names case-insensitively. Before, it matched
title-case names only, so uvicorn-based upstreams such as vLLM and LiteLLM,
which send lowercase header names, had none of their headers stripped at all,
including the Content-Encoding entry the filter exists for.

Same fix as #29824 for the terminal proxy, applied to the other two proxy paths.
2026-09-09 16:35:48 -04:00
G30 b198c94efb fix: open the thread when a notification toast for a thread reply is clicked (#29856) 2026-09-09 16:24:10 -04:00
G30 5b0f8a73ca fix: keep the select chevron clear of the text in shrink-to-fit selects (#29866) 2026-09-09 16:22:00 -04:00
Classic298 8383bc708c fix: show the right error when a model cannot be loaded for editing (#29694)
Opening the workspace model editor with an id that cannot be loaded redirected back to the model list and then fell through into the write-access check on the same empty model, so a plain not-found id produced "You do not have permission to edit this model". The message pointed people at their permissions for something that was never a permission problem.

The editor now stops after the redirect, so that message only appears when the model loaded and the user really cannot edit it.

Refs #29629
2026-09-09 12:55:38 -04:00
Timothy Jaeryang Baek ee46e2664a refac 2026-09-09 12:51:59 -04:00
Timothy Jaeryang Baek d70053e449 refac 2026-09-09 12:51:29 -04:00
Classic298 c955cbd2c5 fix: stop forwarding upstream Server and Date headers from the terminal proxy (#29841)
Proxied terminal responses (GET /api/v1/terminals/{id}/ports and every other
proxied route) went out with two Server and two Date headers: the terminal
server's copies, forwarded verbatim, plus uvicorn's own. nginx in front of Open
WebUI logs "upstream sent duplicate header line" for both on every request, and
the ports route is polled often enough to fill gigabytes of error log per day.

Server and Date belong to whoever terminates the connection, so the proxy now
drops the upstream's copies next to the framing headers it already stripped.
uvicorn's own values still go out, once. Everything else, including custom
upstream headers and TERMINAL_PROXY_HEADERS, passes through unchanged.

The OpenAI and Ollama proxies forward upstream Server and Date the same way and
are left for a separate change.

Fixes #29824
2026-09-09 12:31:02 -04:00
Classic298 1b67da7004 feat: sort flags for kb_exec file listings (#29840)
kb_exec silently ignored ls -t. It accepted the flag, dropped it and
returned the same undefined database order as a plain ls, so the model
believed it had a newest-first list when it did not. With a few thousand
files in a knowledge base there was no way to ask what changed recently
without reading the whole listing and comparing dates by eye.

ls, tree and find now sort their file lines by name by default, so the
same knowledge base always lists the same way. -t sorts newest first,
-S largest first and -r reverses, combinable like -at or -tr, matching
the flags the model already knows from a shell. Directories keep their
existing name order and stay grouped first. No query changes: the
timestamps and sizes were already loaded for the date and size columns.
2026-09-09 12:30:47 -04:00
G30 a253bf0c32 fix: drop tool IDs from the tools and tool-ids URL parameters that do not match a known tool (#29803) 2026-09-09 12:30:32 -04:00
G30 b38755b21c fix: keep sticky code block headers at the top of channel scroll containers (#29836)
* fix: keep sticky code block headers at the top of channel scroll containers

* fix: clip the sticky code block header to the block's rounded corners

* fix: give channel scroll containers their own layer so firefox clips sticky code headers
2026-09-09 12:12:15 -04:00
G30 babf08e301 fix: stamp docker builds with the build hash so stale clients reload (#29832) 2026-09-09 12:11:52 -04:00
G30 e4d65d0351 fix: close modal shortcut closes only the top modal (#29830) 2026-09-09 12:11:38 -04:00
Timothy Jaeryang Baek 12b14124b9 refac 2026-09-08 23:18:48 -04:00
Timothy Jaeryang Baek 31b272d3c9 refac 2026-09-08 22:20:33 -04:00
Timothy Jaeryang Baek 307b9b9133 refac 2026-09-08 21:16:10 -04:00
Timothy Jaeryang Baek a23b579233 refac 2026-09-08 21:01:26 -04:00
Timothy Jaeryang Baek 3808eace6c refac 2026-09-08 20:44:23 -04:00
Timothy Jaeryang Baek 8556033c6b refac 2026-09-08 20:34:42 -04:00
Timothy Jaeryang Baek 674760bfc1 refac 2026-09-08 16:54:15 -04:00
Timothy Jaeryang Baek 4cc0d48b4d refac 2026-09-08 16:49:54 -04:00
Timothy Jaeryang Baek f80ef8bd00 refac 2026-09-08 16:47:01 -04:00
spoofy 94073b1f16 i18n: complete Japanese translations (ja-JP) (#29798)
* i18n: fill empty Japanese translations

* i18n: restore Japanese translation placeholders

* i18n: polish Japanese UI wording for clarity
2026-09-08 15:59:23 -04:00
Timothy Jaeryang Baek d8f27e745b refac 2026-09-08 13:25:16 -04:00
spoofy 56de6dd792 i18n: es es new UI strings (#29795)
* i18n: translate new UI strings into Spanish

* i18n: use precise Spanish term for Shell
2026-09-08 13:23:51 -04:00
spoofy 02efa6ed10 i18n: ru uk new UI strings (#29794)
* i18n: translate new UI strings into Russian and Ukrainian

* i18n: preserve established Ukrainian Valves terminology

* i18n: shorten Russian Modified label

* i18n: shorten Ukrainian Modified label

* i18n: shorten Russian and Ukrainian default labels
2026-09-08 13:23:41 -04:00
Timothy Jaeryang Baek 254e29b9af refac 2026-09-08 13:19:14 -04:00