From 914ccf07ef158afe5588b97ed42778c93c439938 Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Fri, 17 Apr 2026 13:37:52 +0900 Subject: [PATCH] refac --- backend/open_webui/routers/knowledge.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/backend/open_webui/routers/knowledge.py b/backend/open_webui/routers/knowledge.py index af4417844..36d20bdf5 100644 --- a/backend/open_webui/routers/knowledge.py +++ b/backend/open_webui/routers/knowledge.py @@ -826,7 +826,11 @@ async def remove_file_from_knowledge_by_id( log.debug(e) pass - if delete_file: + # Only the file owner or an admin may permanently delete the underlying + # file. Collaborators with KB write access can unlink a file from the + # knowledge base but must not be able to destroy files they do not own, + # as the same file may be referenced by other KBs and chats. + if delete_file and (file.user_id == user.id or user.role == 'admin'): try: # Remove the file's collection from vector database file_collection = f'file-{form_data.file_id}'