From 345f3e35592206552ad685e053c31e5844f6dbc2 Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Wed, 25 Feb 2026 15:15:59 -0600 Subject: [PATCH] refac --- backend/open_webui/config.py | 3 ++- backend/open_webui/env.py | 10 ++++------ backend/open_webui/models/access_grants.py | 14 ++++++++++++-- backend/open_webui/routers/knowledge.py | 2 +- backend/open_webui/routers/models.py | 2 +- backend/open_webui/routers/notes.py | 2 +- backend/open_webui/routers/prompts.py | 2 +- backend/open_webui/routers/skills.py | 2 +- backend/open_webui/routers/tools.py | 2 +- backend/open_webui/utils/access_control.py | 16 +++++++++++++--- backend/open_webui/utils/middleware.py | 6 ++---- backend/open_webui/utils/misc.py | 4 +--- 12 files changed, 40 insertions(+), 25 deletions(-) diff --git a/backend/open_webui/config.py b/backend/open_webui/config.py index 0760b4b81..ea2cbebd2 100644 --- a/backend/open_webui/config.py +++ b/backend/open_webui/config.py @@ -1446,7 +1446,8 @@ USER_PERMISSIONS_NOTES_ALLOW_PUBLIC_SHARING = ( ) USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_USERS = ( - os.environ.get("USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_USERS", "True").lower() == "true" + os.environ.get("USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_USERS", "True").lower() + == "true" ) diff --git a/backend/open_webui/env.py b/backend/open_webui/env.py index 30d202137..61f296012 100644 --- a/backend/open_webui/env.py +++ b/backend/open_webui/env.py @@ -1048,11 +1048,9 @@ EXTERNAL_PWA_MANIFEST_URL = os.environ.get("EXTERNAL_PWA_MANIFEST_URL") # Controls the default "Who can share to this group" setting for new groups. # Env var values: "true" (anyone), "false" (no one), "members" (only group members). -_default_group_share = os.environ.get( - "DEFAULT_GROUP_SHARE_PERMISSION", "members" -).strip().lower() +_default_group_share = ( + os.environ.get("DEFAULT_GROUP_SHARE_PERMISSION", "members").strip().lower() +) DEFAULT_GROUP_SHARE_PERMISSION = ( - "members" - if _default_group_share == "members" - else _default_group_share == "true" + "members" if _default_group_share == "members" else _default_group_share == "true" ) diff --git a/backend/open_webui/models/access_grants.py b/backend/open_webui/models/access_grants.py index 93563bec8..4519abc96 100644 --- a/backend/open_webui/models/access_grants.py +++ b/backend/open_webui/models/access_grants.py @@ -225,8 +225,18 @@ def strip_user_access_grants(access_grants: Optional[list]) -> list: grant for grant in access_grants if not ( - (grant.get("principal_type") if isinstance(grant, dict) else getattr(grant, "principal_type", None)) == "user" - and (grant.get("principal_id") if isinstance(grant, dict) else getattr(grant, "principal_id", None)) != "*" + ( + grant.get("principal_type") + if isinstance(grant, dict) + else getattr(grant, "principal_type", None) + ) + == "user" + and ( + grant.get("principal_id") + if isinstance(grant, dict) + else getattr(grant, "principal_id", None) + ) + != "*" ) ] diff --git a/backend/open_webui/routers/knowledge.py b/backend/open_webui/routers/knowledge.py index 2531f8b92..0d4770560 100644 --- a/backend/open_webui/routers/knowledge.py +++ b/backend/open_webui/routers/knowledge.py @@ -551,7 +551,7 @@ async def update_knowledge_access_by_id( user.id, user.role, form_data.access_grants, - "sharing.public_knowledge" + "sharing.public_knowledge", ) AccessGrants.set_access_grants("knowledge", id, form_data.access_grants, db=db) diff --git a/backend/open_webui/routers/models.py b/backend/open_webui/routers/models.py index ce89eb5af..95279bc37 100644 --- a/backend/open_webui/routers/models.py +++ b/backend/open_webui/routers/models.py @@ -570,7 +570,7 @@ async def update_model_access_by_id( user.id, user.role, form_data.access_grants, - "sharing.public_models" + "sharing.public_models", ) AccessGrants.set_access_grants( diff --git a/backend/open_webui/routers/notes.py b/backend/open_webui/routers/notes.py index f25a5dcfd..de8c18e93 100644 --- a/backend/open_webui/routers/notes.py +++ b/backend/open_webui/routers/notes.py @@ -358,7 +358,7 @@ async def update_note_access_by_id( user.id, user.role, form_data.access_grants, - "sharing.public_notes" + "sharing.public_notes", ) AccessGrants.set_access_grants("note", id, form_data.access_grants, db=db) diff --git a/backend/open_webui/routers/prompts.py b/backend/open_webui/routers/prompts.py index 0e2799d7b..1f3342dad 100644 --- a/backend/open_webui/routers/prompts.py +++ b/backend/open_webui/routers/prompts.py @@ -478,7 +478,7 @@ async def update_prompt_access_by_id( user.id, user.role, form_data.access_grants, - "sharing.public_prompts" + "sharing.public_prompts", ) AccessGrants.set_access_grants("prompt", prompt_id, form_data.access_grants, db=db) diff --git a/backend/open_webui/routers/skills.py b/backend/open_webui/routers/skills.py index c91dbc5b7..f2594ae5d 100644 --- a/backend/open_webui/routers/skills.py +++ b/backend/open_webui/routers/skills.py @@ -346,7 +346,7 @@ async def update_skill_access_by_id( user.id, user.role, form_data.access_grants, - "sharing.public_skills" + "sharing.public_skills", ) AccessGrants.set_access_grants("skill", id, form_data.access_grants, db=db) diff --git a/backend/open_webui/routers/tools.py b/backend/open_webui/routers/tools.py index 7032b1b4b..e5b2daad5 100644 --- a/backend/open_webui/routers/tools.py +++ b/backend/open_webui/routers/tools.py @@ -581,7 +581,7 @@ async def update_tool_access_by_id( user.id, user.role, form_data.access_grants, - "sharing.public_tools" + "sharing.public_tools", ) AccessGrants.set_access_grants("tool", id, form_data.access_grants, db=db) diff --git a/backend/open_webui/utils/access_control.py b/backend/open_webui/utils/access_control.py index 63fa8b26c..fa26e7e34 100644 --- a/backend/open_webui/utils/access_control.py +++ b/backend/open_webui/utils/access_control.py @@ -195,6 +195,7 @@ def migrate_access_control( data[grants_key] = grants data.pop(ac_key, None) + from open_webui.models.access_grants import ( has_public_read_access_grant, has_user_access_grant, @@ -228,8 +229,18 @@ def filter_allowed_access_grants( grant for grant in access_grants if not ( - (grant.get("principal_type") if isinstance(grant, dict) else getattr(grant, "principal_type", None)) == "user" - and (grant.get("principal_id") if isinstance(grant, dict) else getattr(grant, "principal_id", None)) == "*" + ( + grant.get("principal_type") + if isinstance(grant, dict) + else getattr(grant, "principal_type", None) + ) + == "user" + and ( + grant.get("principal_id") + if isinstance(grant, dict) + else getattr(grant, "principal_id", None) + ) + == "*" ) ] @@ -243,4 +254,3 @@ def filter_allowed_access_grants( access_grants = strip_user_access_grants(access_grants) return access_grants - diff --git a/backend/open_webui/utils/middleware.py b/backend/open_webui/utils/middleware.py index 2823df675..e58645c92 100644 --- a/backend/open_webui/utils/middleware.py +++ b/backend/open_webui/utils/middleware.py @@ -4321,8 +4321,7 @@ async def streaming_chat_response_handler(response, ctx): code = sanitize_code(code) if CODE_INTERPRETER_BLOCKED_MODULES: - blocking_code = textwrap.dedent( - f""" + blocking_code = textwrap.dedent(f""" import builtins BLOCKED_MODULES = {CODE_INTERPRETER_BLOCKED_MODULES} @@ -4338,8 +4337,7 @@ async def streaming_chat_response_handler(response, ctx): return _real_import(name, globals, locals, fromlist, level) builtins.__import__ = restricted_import - """ - ) + """) code = blocking_code + "\n" + code if ( diff --git a/backend/open_webui/utils/misc.py b/backend/open_webui/utils/misc.py index ced6fd74a..72baf3015 100644 --- a/backend/open_webui/utils/misc.py +++ b/backend/open_webui/utils/misc.py @@ -277,9 +277,7 @@ def get_last_user_message(messages: list[dict]) -> Optional[str]: return get_content_from_message(message) -def set_last_user_message_content( - content: str, messages: list[dict] -) -> list[dict]: +def set_last_user_message_content(content: str, messages: list[dict]) -> list[dict]: """ Replace the text content of the last user message in-place. Handles both plain-string and list-of-parts content formats.