Skip to content

fix: remove deleted open chat from sidebar folder - #7

Draft
macodev00 wants to merge 79 commits into
devfrom
fix/sidebar-delete-open-chat-folder-31321
Draft

macodev00 wants to merge 79 commits into
devfrom
fix/sidebar-delete-open-chat-folder-31321

Conversation

@macodev00

Copy link
Copy Markdown
Owner

This draft on macodev00/open-webui prepares Closes #31321 for an upstream pull request later. It is not a pull request against open-webui/open-webui.

Summary

Deleting the open chat with the Delete Chat shortcut (Ctrl+Shift+Backspace) removes the chat, but the entry stays under its expanded sidebar folder until a full reload. Clicking that leftover entry opens a chat that no longer exists.

Since open-webui#30165 the shortcut clicks the hidden navbar #delete-chat-button, which confirms through confirmDeleteChat in Chat.svelte. That handler refreshed the recent and pinned lists, but not sidebar folder chat lists. Deleting the same chat from its sidebar row still reloads folder items, and archiving from the navbar already calls refreshFolderChatLists().

Change

After a successful delete, call refreshFolderChatLists() so every open folder reloads its chats. Same call archive and move already use.

Verification

  • Root cause checked on current open-webui/open-webui dev (420b4a279).
  • prettier 3.3.3 leaves this one-line addition unchanged aside from an unrelated pre-existing indent in the same file, which is not part of this commit.
  • ESLint on Chat.svelte reports existing issues only; frontend CI does not run ESLint.
  • The shortcut path was not exercised in a browser in this environment.
Open in Web Open in Cursor 

@macodev00
macodev00 force-pushed the fix/sidebar-delete-open-chat-folder-31321 branch 3 times, most recently from 2d1c5e9 to ec2f04b Compare September 28, 2026 06:28
Classic298 and others added 27 commits September 29, 2026 20:25
… visible dates (open-webui#31606)

A repeating event that was still running when the visible dates began was left out of the calendar. A weekly event from 23:00 to 01:00, for example, did not show on the following day, while the same event without a repeat did. Repeating events are now shown whenever any part of them falls within the visible dates.

Fixes open-webui#31605
* i18n: complete and review Malaysian Malay translations

* i18n: clarify Malay time labels and technical wording
…ebui#31641)

A tool call to an MCP server had no time limit, so a server that hung kept the chat waiting until a reverse proxy or the server itself closed the connection, even with AIOHTTP_CLIENT_TIMEOUT_TOOL_SERVER set. The call now stops after the configured number of seconds and the model sees the timeout as a tool error, which is how OpenAPI tool servers already behave. When the variable is unset it falls back to AIOHTTP_CLIENT_TIMEOUT, and with neither set (or a value of 0 or below) MCP tool calls still have no time limit.

Fixes open-webui#31640
Bumps pycrdt from 0.13.1 to 0.14.8.
…bui#31583)

* fix: automation still shows "Last run Never" after "Run now"

Running an automation with "Run now" added the run to its history, but the automation page and the Automations list kept showing "Last run Never" (or the time of the last scheduled run). Only scheduled runs recorded a last run time. A manual run now records it too, so the automation page and the Automations list show the time of the run you just started.

Fixes open-webui#31580

* fix: show the new last run time right after Run now

The automation page now takes the automation the server returns after Run now, so the last run time updates on the spot and no reload is needed.
…n-webui#31578)

Real-time channel messages are now only delivered to users who have the Channels permission set in the admin user permission settings.
…en-webui#31577)

An automation that posts into a channel now only runs when the user who created it has the Channels permission.
…t after a page reload (open-webui#31576)

When a sub-agent running in the background finished, or a timer the model set went off, the result and the model's follow-up reply were saved but did not show in the chat the user had open. They only appeared after a manual page reload. They now show in the open chat as soon as they arrive.

Fixes open-webui#31566
… the API (open-webui#31575)

The person who started a direct message could add or remove people through the API, although the app only offers this in group channels. Someone added this way could read the whole earlier conversation, and because the original pair no longer matched the conversation, their next message opened a second, empty direct message. Changing the members of a direct message now answers with a 403.

Fixes open-webui#31570
…-webui#31573)

In a temporary chat, when the model handed a task to a sub-agent, the sub-agent's conversation with the task and its answer was saved on the server, although a temporary chat should leave nothing behind. The model is no longer offered sub-agents in temporary chats.

Fixes open-webui#31567
…04 (open-webui#31572)

The link in "chat finished" and "chat failed" webhook notifications was missing the `/c/` part of the chat address, so clicking it opened a 404 page. The link is sent as `/c/<chat id>` again and opens the chat.

Fixes open-webui#31565
When signing in through an OAuth/OIDC provider failed, for example because the provider denied access, the account had no email or its email domain was not allowed, the login page told the user their email or password was wrong, even though they never typed one. Every such failure now shows "Sign-in with your identity provider failed. Please contact your administrator for assistance." The text is the same for every cause so it does not reveal which check failed, and the exact reason is still written to the server log as a warning.

Fixes open-webui#31627
…nloads (open-webui#31623)

When an image generation backend returns a link instead of the image itself, the download now goes through the same safety checks used for other external image downloads. Links on the configured ComfyUI address are still trusted as before, so a ComfyUI server on a local network keeps working.
With request auditing turned on, the audit log only masked fields named exactly "password". The new password from a password change, and passwords entered in admin settings such as YaCy or Jupyter, were written to the log as-is. Any field whose name ends in "password", in any letter case, is now replaced with asterisks.
…n-webui#31621)

Loading the app's settings now uses the same login check as every other request, so a session that is no longer valid gets the logged-out settings.
Renaming a folder in the sidebar and pressing Enter sent the rename to the server twice and showed "Folder updated successfully" twice, because Enter saved the name and closing the text field saved it again. Enter now just closes the text field, which saves the new name once and shows one confirmation.

Fixes open-webui#31582
…inst size limits (open-webui#31615)

With ENABLE_ORJSON off (the default), non-English letters were saved to the database as escape codes, so "Ü" was stored as \u00dc. Searches that ignore upper and lower case compare against that saved text, so they missed any match that differs only in the case of a non-English letter: filtering models by the tag "Überblick" found nothing on Postgres, and searching automations for "отчёт" missed a prompt containing "Отчёт" on SQLite and Postgres. The 100,000 character size limit for user and chat variables counted the escape codes too, so Cyrillic or Chinese variables were refused as too large (or chat variables silently came out empty in the system prompt) at about a sixth of that size. Non-English text is now saved as written, which is how it is already saved with ENABLE_ORJSON on, so nothing changes for those instances, and the limit counts real characters. Anything saved before this keeps the escape codes until it is next edited.
)

Opening a note for live collaborative editing now follows the same Notes permission as the rest of the Notes feature.
…open-webui#31620)

With WEBSOCKET_MANAGER=redis and several instances or workers, an instance only subscribed to Redis once a browser tab had connected to it. Until then, when a tool or Function asked the user something (a confirmation or an input dialog) and the user's tab was connected to another instance, the user's reply never reached the tool and it waited until it timed out. Every instance now subscribes at startup, so the reply arrives whichever instance the tab is on.
)

Since v0.11.4 a new visitor always got their browser's language even when an admin set DEFAULT_LOCALE, because the browser language was remembered as if the user had picked it, so the configured default never applied. The configured default now applies on the first visit again, as it did up to v0.11.3. A language the user picks in Settings and a ?lang= link still take precedence, and instances without DEFAULT_LOCALE keep following the browser language.

Fixes open-webui#31548
…ui#31537)

Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does.
…31531)

With Weaviate as the vector database, a chunk identical to the query (distance 0) was treated as having no distance and got a relevance score of 0. Perfect matches could land at the bottom of the results or fall below the relevance threshold. They now score 1 as expected.

Fixes open-webui#31527
…ff (open-webui#31532)

Choosing jinaai/jina-colbert-v2 as the reranking model failed on the current transformers release with "'HF_ColBERT' object has no attribute 'all_tied_weights_keys'", and saving the Documents settings quietly switched hybrid search back off. The ColBERT reranker now finishes loading, reranks search results and hybrid search stays on after saving.

Fixes open-webui#31522
…ing #, & or + (open-webui#31592)

Starting a new chat from the search dialog with "Start a new conversation" sent a different message than the one typed: everything from a # or & onwards was dropped and + turned into a space. The typed text now reaches the new chat unchanged.

Fixes open-webui#31469
Classic298 and others added 28 commits September 30, 2026 21:02
…-webui#31653)

When a reply contained an artifact and the preview opened automatically, it could check for artifacts before they had been picked up from that reply, find none and close again. This happens occasionally in normal chats, with or without filters, and is older than 0.11.1. The preview now looks for artifacts again at the moment it opens, so it stays open. It is a separate cause from open-webui#31643, found while looking into that issue.
… the reply (open-webui#31652)

Since 0.11.1, when a filter function wrote part of the reply before the model answered (for example some text and an HTML block), the artifact preview opened and then closed straight away. The page showed the filter text but was never sent it as part of the reply, so the model's first output overwrote it, the page briefly saw no HTML block and closed the preview. The filter text is now sent to the page before the model's output, so the preview stays open.

Fixes open-webui#31643
iPhone photos were only converted to JPEG when the browser reported their type as exactly image/heic. Firefox reports image/heif and some browsers report no type at all, so those photos were uploaded as HEIC and vision models failed with an error. When conversion did run, the JPEG was still uploaded with the HEIC file name and type, so the model was told it was HEIC anyway. HEIC and HEIF photos are now converted whatever type the browser reports and are uploaded as a .jpg with the JPEG type, in chats, channels and notes.

Fixes open-webui#28411
…already in the chat (open-webui#31650)

When files were attached to a chat message and one of them was already attached to that chat (on the same message or another one), none of the new files were recorded as part of the chat, and nothing showed up in the logs. The sender still saw every file in their own chat, but anyone opening a shared copy of the chat could not open the new ones. Files already attached to the chat are now skipped and the new ones are recorded normally.

Fixes open-webui#31648
…ebui#31645)

With hybrid search on, Milvus installs fetch every chunk of a collection and score BM25 in Python for each search. In both Milvus modes, one collection per knowledge base and multitenancy, Milvus now runs the keyword half itself with its built-in BM25 full-text search and merges it with the vector results, as pgvector already does. Milvus cannot add a BM25 index to an existing collection, so each collection gets a second, text-only collection next to it; existing installs build these once during startup when ENABLE_DB_MIGRATIONS is on, which copies the chunk text (extra storage roughly the size of that text) and leaves the original vectors and indexes untouched. On one standalone Milvus server the copy ran at about 11,000 chunks per second, around 40 minutes for 200 GB with 1536-dimension embeddings. Collections that cannot be copied, and Milvus servers older than 2.5, which have no BM25, keep using the existing hybrid search.

Fixes open-webui#26243
…more than one <main> element (open-webui#31644)

Some pages, like the Ubiquiti tech specs pages, have more than one <main> element. The Playwright web loader only read the first one, so these pages came back as just their site menu and the actual content was lost. When a page has more than one, the loader now ignores those tags and reads the whole page. Pages with a single <main> load the same as before.

Fixes open-webui#28643
…ollection (open-webui#31660)

Native hybrid search on Milvus kept a second, text-only collection beside every Milvus collection and searched both. Each Milvus collection now holds its vectors, its text and its BM25 keyword index together, and results rank exactly as before, with the BM25 weight setting working the same way it does on pgvector. Existing data moves on the first start with ENABLE_DB_MIGRATIONS on: startup waits while every collection is copied once (vectors included, nothing is re-embedded) and the originals are only dropped after every copy succeeded, so a failed run changes nothing and is retried on the next start. The copy needs free disk space for a second copy of the data until it finishes, and on one 16-thread machine with Milvus's official docker compose setup it ran at 11 to 22 MB/s, so 200 GB takes about 2.5 to 5 hours depending on chunk size. Milvus servers older than 2.5 are detected and keep the existing hybrid search.
…i#31659)

* fix: audit log shows passwords that contain a double quote

With AUDIT_LOG_LEVEL set to REQUEST or REQUEST_RESPONSE, a password containing a double quote was only masked up to that quote, so a new password like Q"secret was logged as "********"secret. A request with whitespace before the colon, such as "new_password" : "secret", was not masked at all. Any field whose name ends in "password" is now masked through its closing quote in both cases.

* fix: audit log records passwords sent back in responses

With AUDIT_LOG_LEVEL set to REQUEST_RESPONSE, fields whose name ends in "password" were masked in request bodies, but response bodies were logged unmasked. Saving or opening the LDAP server settings therefore wrote the Application DN Password to the audit log in plain text, because the settings come back in the response, and the Jupyter passwords in the code execution settings leaked the same way. Responses now get the same masking as requests.
…1655)

Text extracted from any uploaded file had full-width punctuation like :(),!? turned into ASCII :(),!? and curly quotes like “ ” turned into straight quotes, so both the file preview and the model saw altered text. Extracted text now keeps these characters as written, while garbled text from wrong encodings (like café becoming café) is still repaired. Files uploaded before this change keep the altered text until they are uploaded again.

Fixes open-webui#17087
…edge (open-webui#31574)

In a chat inside a folder with knowledge attached, the chat only searches the folder's knowledge, but a sub-agent it started could list and search every knowledge base the user can read. Sub-agents now get the folder's knowledge like the chat that started them. They already receive the folder's system prompt as part of the chat's instructions, so it is not added a second time.

Fixes open-webui#31569
…pen-webui#31593)

When a model called one tool, got its result and then called a second tool with no text in between, the next request merged both calls into an earlier assistant message that the provider had already seen. That changed the conversation's beginning, so the provider's prompt cache stopped matching from there for the rest of the chat. Each tool call and its result are now sent as their own messages, so the start of the conversation stays identical from one request to the next.

Fixes open-webui#31588
…rchable (open-webui#31530)

With VECTOR_DB=elasticsearch, changing a file's content in a knowledge base added the new text but never removed the old chunks, so searches and chats kept returning the old text next to the new. The old chunks are now found and removed after the edit, the same as on the default store.

Fixes open-webui#31523
…val (open-webui#31112)

External knowledge bases on the pgvector provider failed on every search with "operator does not exist: vector <=> double precision[]", so they looked empty to users. This happened regardless of the VECTOR_DB setting.

The query embedding was bound as a plain Python list. register_vector only adapts pgvector's own Vector type and numpy arrays, so psycopg sent the list as a float array, which the <=> operator does not accept. Wrapping the embedding in pgvector.Vector sends it as a real vector.

Vector is imported from the package root, which works on the pinned pgvector 0.4.2 and on 0.5.x, where the pgvector.psycopg re-export no longer exists.

Verified against a pgvector Postgres: before the fix the reported error reproduces; after it, results come back ranked by cosine distance and filtered to the collection, including schema-qualified tables, halfvec columns and 1536-dimension embeddings.

Fixes open-webui#26663
…i#31113)

A user added to an existing group or DM channel saw nothing from it until they reloaded the page: the channel did not appear in their sidebar, and opening it by URL showed the history but no new messages, edits, pins or reactions.

Adding members now does what channel creation already does for its participants: the newly inserted members get a `channel:created` event so their sidebar refreshes, and their open sessions join the channel room so live updates reach them. Standard channels are skipped because their access comes from access grants, matching the membership-removal path.

Verified against a running server with two live Socket.IO clients: the added user's open session now gets the sidebar refresh and the next message immediately; re-adding an existing member, removal and standard channels behave as before.

Fixes open-webui#30432
…pen-webui#31353)

With ENABLE_CUSTOM_MODEL_FALLBACK on, a workspace model whose base model is gone should be answered by the first default model. That worked for plain API calls, but every chat sent from the web UI failed with "Model not found" for users and "Model '' was not found" for admins, and no model was called.

Web UI chats carry a chat id and a socket session, so the request is split into one task per selected model. Each task was rebuilt with the originally requested model id, which dropped the fallback chosen earlier in the handler. The task for the requested model now keeps the fallback model when one was chosen. The chat still records the workspace model the user picked.

Tested end to end against a mock upstream, as user and admin, in new and existing chats: before, every web UI send with such a model errored; after, the default model answers. Healthy models, workspace models with a valid base and multi-model sends behave as before, and with the fallback disabled the chat still fails with "Model not found".

Fixes open-webui#31345
…ebui#31336)

Adding files through `POST /api/v1/knowledge/{id}/files/batch/add` accepted a file whose extracted text was already in the knowledge base under another file, and linked both, while the single-file add rejects the same file with "Duplicate content detected". The same text was then embedded twice and retrieval returned the same passages twice.

The batch path now runs each file's content hash through the same check the single-file path uses, now shared by both, and also against the earlier files of the same batch. A duplicate is reported as a failed file in the batch result and is not linked, while the other files of the batch still go through. Batch-added chunks now carry the content hash in their metadata, so later adds through either endpoint detect them.

Chunks written by batch add before this change have no hash, so content added that way earlier is still not detected as a duplicate.

Verified on a running instance: two files with identical text now end up with exactly one linked in every order and combination (one batch call, separate batch calls, batch mixed with single add), and re-adding the same file is still accepted.

Fixes open-webui#31333
…open-webui#31337)

Opening a shared chat link while signed out landed on the home page with a blank screen. Only a manual refresh reached the login page, and after signing in the visitor ended up on the home page, so the link had to be opened again. This happened with every sign-in method, OAuth included.

When the share could not be loaded, the share page navigated home twice. The second navigation cancelled the login redirect the first one had started, and since the app shell was already on screen, nothing checked the session again.

The share page now navigates once. Signed-out visitors go to the login page with the share as the redirect target, so they land on the shared chat after signing in, OAuth included, since the login page keeps the target across the provider round trip. Signed-in users on a dead or forbidden link still go home, and open shares still render without signing in.

Fixes open-webui#31334
…31534)

Every chat that got a reply left a small lock behind in the server process, so a long-running server kept one for every chat it had ever answered and only a restart gave the memory back. The lock is now dropped as soon as nothing is using it, so a finished reply leaves nothing behind per chat, while replies, sub-agent results and timers for the same chat still wait for each other as before.

Fixes open-webui#31521
The Delete Chat shortcut confirms through the navbar handler, which
refreshed the recent and pinned lists but not open sidebar folders.
Format & Build runs i18n:parse and fails when the tree is dirty.
Upstream dev is missing keys the parser extracts from current source.
@cursor
cursor Bot force-pushed the fix/sidebar-delete-open-chat-folder-31321 branch from ec2f04b to 00105e4 Compare October 1, 2026 06:10
Python CI on current dev fails because the enabled tool id filter is
wrapped. Ruff wants that comprehension on one line.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants