From 8da29566a1f81c38e80009bdea3ce4d9be860605 Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Wed, 11 Mar 2026 15:22:51 -0500 Subject: [PATCH] refac: safer tool server handling --- backend/open_webui/routers/tools.py | 12 +++++++++--- backend/open_webui/utils/tools.py | 13 ++++++++----- 2 files changed, 17 insertions(+), 8 deletions(-) diff --git a/backend/open_webui/routers/tools.py b/backend/open_webui/routers/tools.py index 351c491bd..0569414d4 100644 --- a/backend/open_webui/routers/tools.py +++ b/backend/open_webui/routers/tools.py @@ -88,9 +88,15 @@ async def get_tools( # OpenAPI Tool Servers server_access_grants = {} for server in await get_tool_servers(request): - connection = request.app.state.config.TOOL_SERVER_CONNECTIONS[ - server.get("idx", 0) - ] + server_idx = server.get("idx", 0) + connections = request.app.state.config.TOOL_SERVER_CONNECTIONS + if server_idx >= len(connections): + log.warning( + f"Tool server index {server_idx} out of range " + f"(have {len(connections)} connections), skipping server {server.get('id')}" + ) + continue + connection = connections[server_idx] server_config = connection.get("config", {}) server_id = f"server:{server.get('id')}" diff --git a/backend/open_webui/utils/tools.py b/backend/open_webui/utils/tools.py index e525a8284..e60544261 100644 --- a/backend/open_webui/utils/tools.py +++ b/backend/open_webui/utils/tools.py @@ -275,11 +275,14 @@ async def get_tools( continue tool_server_idx = tool_server_data.get("idx", 0) - tool_server_connection = ( - request.app.state.config.TOOL_SERVER_CONNECTIONS[ - tool_server_idx - ] - ) + connections = request.app.state.config.TOOL_SERVER_CONNECTIONS + if tool_server_idx >= len(connections): + log.warning( + f"Tool server index {tool_server_idx} out of range " + f"(have {len(connections)} connections), skipping server {server_id}" + ) + continue + tool_server_connection = connections[tool_server_idx] # Check access control for tool server if not has_connection_access(