This commit is contained in:
Timothy Jaeryang Baek
2026-03-22 06:58:58 -05:00
parent 2e165926de
commit 945275faae
5 changed files with 56 additions and 6 deletions
@@ -192,6 +192,16 @@ def has_public_read_access_grant(access_grants: Optional[list]) -> bool:
return False
def has_public_write_access_grant(access_grants: Optional[list]) -> bool:
"""
Returns True when a direct grant list includes wildcard public-write.
"""
for grant in normalize_access_grants(access_grants):
if grant['principal_type'] == 'user' and grant['principal_id'] == '*' and grant['permission'] == 'write':
return True
return False
def has_user_access_grant(access_grants: Optional[list]) -> bool:
"""
Returns True when a direct grant list includes any non-wildcard user grant.
+2 -2
View File
@@ -36,7 +36,7 @@ from open_webui.models.channels import (
ChannelWebhookModel,
ChannelWebhookForm,
)
from open_webui.models.access_grants import AccessGrants, has_public_read_access_grant
from open_webui.models.access_grants import AccessGrants, has_public_read_access_grant, has_public_write_access_grant
from open_webui.models.messages import (
Messages,
MessageModel,
@@ -88,7 +88,7 @@ def channel_has_access(
):
return True
if not strict and permission == 'write' and has_public_read_access_grant(channel.access_grants):
if not strict and permission == 'write' and has_public_write_access_grant(channel.access_grants):
return True
return False
+2 -1
View File
@@ -30,6 +30,7 @@ from open_webui.utils.auth import get_admin_user, get_verified_user
from open_webui.utils.access_control import (
has_permission,
has_public_read_access_grant,
has_public_write_access_grant,
filter_allowed_access_grants,
)
from open_webui.models.access_grants import AccessGrants
@@ -234,7 +235,7 @@ async def get_note_by_id(
permission='write',
db=db,
)
or has_public_read_access_grant(note.access_grants)
or has_public_write_access_grant(note.access_grants)
)
return NoteResponse(**note.model_dump(), write_access=write_access)
@@ -5,6 +5,7 @@ from open_webui.models.users import UserModel
from open_webui.models.groups import Groups
from open_webui.models.access_grants import (
has_public_read_access_grant,
has_public_write_access_grant,
has_user_access_grant,
strip_user_access_grants,
)
@@ -225,7 +226,7 @@ def filter_allowed_access_grants(
return access_grants
# Check if user can share publicly
if has_public_read_access_grant(access_grants) and not has_permission(
if (has_public_read_access_grant(access_grants) or has_public_write_access_grant(access_grants)) and not has_permission(
user_id,
public_permission_key,
default_permissions,