This commit is contained in:
Timothy Jaeryang Baek
2026-02-09 13:28:14 -06:00
parent 3ae44d11a5
commit f7406ff576
16 changed files with 589 additions and 174 deletions
+17 -6
View File
@@ -42,7 +42,7 @@ from open_webui.utils.auth import decode_token
from open_webui.socket.utils import RedisDict, RedisLock, YdocManager
from open_webui.tasks import create_task, stop_item_tasks
from open_webui.utils.redis import get_redis_connection
from open_webui.utils.access_control import has_access, get_users_with_access
from open_webui.models.access_grants import AccessGrants
from open_webui.env import (
@@ -405,7 +405,12 @@ async def join_note(sid, data):
if (
user.role != "admin"
and user.id != note.user_id
and not has_access(user.id, type="read", access_control=note.access_control)
and not AccessGrants.has_access(
user_id=user.id,
resource_type="note",
resource_id=note.id,
permission="read",
)
):
log.error(f"User {user.id} does not have access to note {data['note_id']}")
return
@@ -467,8 +472,11 @@ async def ydoc_document_join(sid, data):
if (
user.get("role") != "admin"
and user.get("id") != note.user_id
and not has_access(
user.get("id"), type="read", access_control=note.access_control
and not AccessGrants.has_access(
user_id=user.get("id"),
resource_type="note",
resource_id=note.id,
permission="read",
)
):
log.error(
@@ -537,8 +545,11 @@ async def document_save_handler(document_id, data, user):
if (
user.get("role") != "admin"
and user.get("id") != note.user_id
and not has_access(
user.get("id"), type="read", access_control=note.access_control
and not AccessGrants.has_access(
user_id=user.get("id"),
resource_type="note",
resource_id=note.id,
permission="read",
)
):
log.error(f"User {user.get('id')} does not have access to note {note_id}")