diff --git a/backend/open_webui/routers/knowledge.py b/backend/open_webui/routers/knowledge.py index af4417844..36d20bdf5 100644 --- a/backend/open_webui/routers/knowledge.py +++ b/backend/open_webui/routers/knowledge.py @@ -826,7 +826,11 @@ async def remove_file_from_knowledge_by_id( log.debug(e) pass - if delete_file: + # Only the file owner or an admin may permanently delete the underlying + # file. Collaborators with KB write access can unlink a file from the + # knowledge base but must not be able to destroy files they do not own, + # as the same file may be referenced by other KBs and chats. + if delete_file and (file.user_id == user.id or user.role == 'admin'): try: # Remove the file's collection from vector database file_collection = f'file-{form_data.file_id}'