Commit Graph
18635 Commits
Author SHA1 Message Date
Timothy Jaeryang Baek 7f703dcc98 refac 2026-09-21 08:31:27 -04:00
Timothy Jaeryang Baek dc4f5da5a0 refac 2026-09-21 08:28:36 -04:00
G30 c2f11edb2f fix: keep a workspace model's base model when cloning it from the admin Models settings and hide Clone for arena models (#30080) 2026-09-21 08:15:12 -04:00
Classic298 f5967aebd7 fix: restore chat input draft after reload in chats started from the home page (#29762)
Typing a message, uploading a file or toggling web search in a chat started from the home page was lost on reload: the input came back empty and the uploaded files were gone for good.

Drafts are kept per chat in sessionStorage, but the key was built from the route prop, which stays empty for these chats because creating the chat only swaps the URL with history.replaceState and never re-runs the route load. Drafts were written under the new-chat key while a reload of /c/<id> read the per-chat key. Falling back to the active chat id lines the two up, the same fallback loadChat already uses for this reason.

The Placeholder submit handler also cleared the bare key rather than the current one, which left a stale draft behind once a chat's messages had all been deleted.

Verified against the base commit on a local instance: on base the draft lands under chat-input and is lost on reload, with the change it lands under chat-input-<id> and both the text and the uploaded file come back. Image attachments stay excluded from drafts by design.

The model selection half of #29760 has a different cause and is not fixed here.

Refs #29760
2026-09-21 08:08:45 -04:00
Classic298 f16e9eabe3 feat: fall back to an available model when a chat's models are gone (#29757)
Retiring a model leaves every chat that used it stuck. The chat still stores the old model id, so it loads with nothing usable selected and refuses to send until the user picks a replacement by hand, in every old conversation. There is no admin-side way to move those chats across.

Loading a chat now drops model ids that no longer exist, and an empty selection falls into the fallback this function already applies to new chats: the user's default model, then the admin-configured default, then the first available model. A chat that still has one live model keeps it. The filter runs before the single-model permission clamp so a restricted user keeps a live model the chat already has instead of losing it to the clamp.

The model list cannot distinguish a retired model from one whose connection is momentarily unreachable, so during such an outage a chat pinned to that connection will open on the fallback model and record it when saved. Models defined in the workspace are unaffected, since they stay in the list while their connection is down.
2026-09-21 08:08:27 -04:00
G30 5399e3977d fix: enforce the account form's required fields the way the admin user dialog does (#30296) 2026-09-21 08:08:02 -04:00
G30 aa65f55692 fix: insert the whole emoji when its shortcode is a codepoint sequence (#30213) 2026-09-21 08:07:45 -04:00
Classic298 9012bd153d fix: stop sending count to the Staan search API (#30303)
Staan rejects any count other than its fixed page size of 10, so every search 400ed with the default result count of 3. The API always returns 10 results; the local results[:count] slice already applies the configured count, so the request parameter is simply dropped.
2026-09-21 08:04:26 -04:00
G30 7eebbbb891 fix: stop the MinerU API key blocking a save in local mode (#30299) 2026-09-21 08:04:19 -04:00
andreadegiovineandandreadegiovine e9017c7da4 i18n: update and improve it-IT (#30297)
* i18n: update and improve it-IT

* i18n: update and improve it-IT

---------

Co-authored-by: andreadegiovine <andreadegiovine@gmail.com>
2026-09-21 08:04:08 -04:00
G30 702da1e471 fix: stop injecting memories and memory tools when memory is switched off (#30228) 2026-09-21 01:00:08 -04:00
Timothy Jaeryang Baek 85146206f6 refac 2026-09-21 00:59:46 -04:00
G30 14be67348a fix: open the new group dialog empty after a group is created (#30280) 2026-09-21 00:56:53 -04:00
Timothy Jaeryang Baek 97e013a661 refac 2026-09-21 00:51:28 -04:00
G30 394fcc7e24 fix: keep an unsaved code block edit visible after it is collapsed (#30284) 2026-09-20 23:44:16 -05:00
G30 9758f33b6c fix: save a model whose description is switched from default back to custom (#30249) 2026-09-20 23:42:44 -05:00
G30 669d37bea1 fix: stop offering reactions on a channel the viewer may only read (#30241) 2026-09-20 23:42:32 -05:00
G30 b256115fa2 fix: save the context compaction threshold from general settings (#30270) 2026-09-20 23:42:22 -05:00
G30 402a187e82 fix: return no chats when a folder search term matches no folder (#30273) 2026-09-20 23:39:54 -05:00
G30 f2220d2e40 fix: keep citation chips inside bold, italic and linked text (#30278) 2026-09-21 00:33:47 -04:00
G30 4c00e08aa1 fix: keep a message's attachments when its edit is cancelled (#30281) 2026-09-21 00:31:26 -04:00
Classic298 8e4cc946ce fix: emit the resolved file path in terminal file events (#30282)
When a model calls display_file, write_file or replace_file_content with a relative path, Open Terminal resolves it against the session working directory and returns the absolute path, but the event sent to the browser carried the raw argument instead. The file panel matches that string against the file browser root, a relative path never matches, so the preview never opens, the panel jumps to the root and the session working directory is rewritten to the root. With the root turned off (OPEN_TERMINAL_FILE_BROWSER_ROOT=filesystem) there is nothing to clamp to and the relative string is sent to the terminal as the new working directory, moving it silently. The tool call itself succeeds either way, so the failure only shows up as a panel that will not open the file the model just wrote.

Both events now carry the path from the tool result and fall back to the argument when the result cannot be read, which is what build_terminal_file_tool_result already does for the chat file attachment. The same one-line rule is applied to the direct tool server path in the frontend, where the browser runs the tool itself and the write_file branch beside it was already correct.

Checked against a live Open Terminal: relative arguments now emit the absolute path, absolute ones are unchanged, non-existent files and inline displays still emit nothing, unreadable or error results still fall back to the argument, and run_command is untouched.

Related to #30051
2026-09-21 00:31:14 -04:00
G30 17e7e8f5e9 fix: show a code run's error output alongside what it printed (#30286) 2026-09-21 00:30:55 -04:00
G30 f847c6a588 fix: apply the new text to speech engine's default voice and model when the engine changes (#30289) 2026-09-21 00:30:26 -04:00
Classic298 043784c2d0 fix: route external webhook avatar URLs through the profile image endpoint (#29892)
The channel webhooks modal rendered a webhook's stored profile_image_url straight into an img tag, so opening it sent every viewer's browser to whatever external host that URL named, leaking client IP, User-Agent and Referer no matter how the server was configured.

External URLs now render through the same webhook profile image endpoint the message list already uses, leaving it to the server to decide whether the browser is sent to that host. Locally picked images and the paths Open WebUI assigns itself still render inline, so previewing an upload before saving is unchanged, and the value written back on save is untouched.

This only takes effect together with the companion backend change that gates the endpoint on ENABLE_PROFILE_IMAGE_URL_FORWARDING. Until that lands the endpoint still redirects and the browser still reaches the external host. Also worth knowing: the endpoint matches the scheme case-sensitively, so a URL stored as HTTPS:// falls back to the default image here, which is already what the message list shows for it.

Verified in a browser against a local origin standing in for the external host: with forwarding on the avatar still renders through the endpoint in both places it appears, with forwarding off the browser makes no request to that origin, and picking a new file still previews immediately before saving.
2026-09-19 17:03:15 -05:00
Classic298 7fa705f3b8 feat: let operators expose chosen file metadata to the model in retrieved sources (#29696)
Custom metadata attached to a file upload now reaches the vector DB, but the model still never sees it. Both prompt-assembly paths build their output from a fixed field set: the classic RAG <source> tag carries only id, name and resource type, and the retrieval tools return only content, source and file id per chunk. A scraper that records where each document came from therefore cannot get that origin in front of the model, so answers cannot state it.

RAG_SOURCE_METADATA_KEYS names the chunk metadata keys allowed through to the model. Configured keys are emitted as extra attributes on the <source> tag and as extra fields on tool result chunks, covering both retrieval paths. It is empty by default, so nothing changes for existing deployments.

An allowlist instead of passing everything through, because chunk metadata also carries file hashes, collection names, embedding config and relevance scores, which would then be added to every retrieved chunk of every request. Values are attacker-controllable through an uploaded file, so they are escaped before they go into the tag, and a configured key can never displace a field the tag or the chunk already defines.

Reported in open-webui/open-webui#29486.
2026-09-19 17:02:59 -05:00
Timothy Jaeryang BaekandClassic298 3a6d0fd203 refac
Co-Authored-By: Classic298 <27028174+Classic298@users.noreply.github.com>
2026-09-19 17:54:09 -04:00
Timothy Jaeryang Baek 8b3ee28272 refac 2026-09-19 17:45:05 -04:00
G30 65a3a115eb fix: keep the speech-to-text extension allowlist when the Audio settings are saved (#30208) 2026-09-19 17:36:38 -04:00
G30 881f7c9400 fix: save only the changed key when pinning, reordering or picking a default outside the Settings modal (#30183) 2026-09-19 17:34:02 -04:00
Timothy Jaeryang Baek f6922a4c42 refac 2026-09-19 17:33:41 -04:00
Timothy Jaeryang BaekandG30 67adde3193 refac
Co-Authored-By: G30 <50341825+silentoplayz@users.noreply.github.com>
2026-09-19 17:26:40 -04:00
Timothy Jaeryang Baek 10d1cfe637 refac 2026-09-19 17:26:18 -04:00
G30 c1a35b4691 fix: sort the feedback history by user when the User column is clicked (#30191) 2026-09-19 17:21:51 -04:00
G30 76bd90c832 fix: discard unsaved edits when the admin Edit User dialog is closed (#30193) 2026-09-19 17:21:44 -04:00
G30 4922b91c07 fix: stop the Model Defaults save from reverting the selected, pinned and ordered models (#30206) 2026-09-19 17:17:57 -04:00
G30 27dd191332 fix: let a calendar event's repeat, description and location be cleared again (#30204) 2026-09-19 17:17:43 -04:00
G30 757ee8132e fix: stop collapsing the task list from sending the message being typed (#30202) 2026-09-19 17:17:30 -04:00
G30 5e1f995f01 fix: show a custom gender back in the account form instead of an empty dropdown (#30215) 2026-09-19 17:16:56 -04:00
G30 b64cb06043 fix: let a user without the chat delete permission delete a folder while keeping its chats (#30163) 2026-09-19 16:07:34 -05:00
Timothy Jaeryang Baek 946be43237 refac 2026-09-19 17:05:57 -04:00
G30 25948ea213 fix: block saving a prompt's input form when a required dropdown has no option chosen (#30078) 2026-09-19 15:42:39 -05:00
G30 3fbc39a9dc fix: save a new feedback entry when rating a reply whose entry was deleted (#30077) 2026-09-19 15:42:25 -05:00
G30 a63ddb36d2 fix: clear a reply's score and reason when its rating switches thumbs (#30075) 2026-09-19 15:42:15 -05:00
G30 57063aaad8 fix: dropping a folder onto the folder it is already in no longer fails with Folder already exists (#30169) 2026-09-19 15:41:10 -05:00
G30 2690d04cac fix: clean up orphan tags for the chat's owner, not the admin, when an admin deletes another user's chat (#30171) 2026-09-19 15:40:58 -05:00
G30 af9ef1dcbc fix: hide the group picker from users who may not share with groups (#30189) 2026-09-19 15:34:33 -05:00
G30 621ed6de7f fix: export every prompt and model from the workspace, not only the page on screen (#30187) 2026-09-19 10:03:17 -05:00
G30 9e293a58ea fix: label the search modal's archive action Unarchive for archived chats and report what happened (#30177) 2026-09-19 10:02:11 -05:00
G30 dbe538c033 fix: keep a note's sharing when a collaborator saves it (#30175) 2026-09-19 10:00:39 -05:00