Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
79 commits
Select commit Hold shift + click to select a range
ad01bca
fix: repeating calendar events are missing when they began before the…
Classic298 Sep 29, 2026
3819dc2
i18n: ms-MY language translations (#31560)
EllaFr Sep 29, 2026
c1f2458
fix: MCP tool calls ignore AIOHTTP_CLIENT_TIMEOUT_TOOL_SERVER (#31641)
Classic298 Sep 30, 2026
6419eca
chore: bump pycrdt to 0.14.8 (#31636)
Classic298 Sep 30, 2026
e26da43
fix: automation still shows "Last run Never" after "Run now" (#31583)
Classic298 Sep 30, 2026
028dab8
fix: apply the Channels permission to real-time channel messages (#31…
Classic298 Sep 30, 2026
9b45bed
fix: check the Channels permission when a channel automation runs (#3…
Classic298 Sep 30, 2026
fa66b0f
fix: background sub-agent and timer replies only show in the open cha…
Classic298 Sep 30, 2026
3d70d43
fix: members can be added to or removed from a direct message through…
Classic298 Sep 30, 2026
c488f60
fix: temporary chats save sub-agent conversations on the server (#31573)
Classic298 Sep 30, 2026
b6dfa37
fix: chat links in finished and failed webhook notifications open a 4…
Classic298 Sep 30, 2026
6a2aad9
fix: SSO login failures show the email/password error (#31629)
Classic298 Sep 30, 2026
b4ebd0d
refac(hardening): apply the same safety checks to generated image dow…
Classic298 Sep 30, 2026
d3dde36
fix: audit log records new passwords in plain text (#31622)
Classic298 Sep 30, 2026
2062231
fix: apply the usual login check when the app loads its settings (#31…
Classic298 Sep 30, 2026
8b1ae1d
fix: renaming a folder with Enter saves it twice (#31584)
Classic298 Sep 30, 2026
321a24d
fix: non-English text is missed by searches and counted six times aga…
Classic298 Sep 30, 2026
6d409da
refac: apply the Notes permission to live note editing (#31552)
Classic298 Sep 30, 2026
288bf91
fix: tool prompts time out when the user's tab is on another instance…
Classic298 Sep 30, 2026
5338aec
fix: render tilde-fenced code blocks as code blocks (#31543)
silentoplayz Sep 30, 2026
4987711
fix: DEFAULT_LOCALE is ignored on a user's first visit (#31551)
Classic298 Sep 30, 2026
8600ab9
fix: keep a table cell's line breaks inside its row when converting t…
silentoplayz Sep 30, 2026
52533c5
refac: calendar event tools use the calendar's access check (#31537)
Classic298 Sep 30, 2026
710b9f1
fix: exact matches score as the worst result on Weaviate (#31531)
Classic298 Sep 30, 2026
e5b5754
fix: use the moved chat's pinned state when a folder chat is dropped …
silentoplayz Sep 30, 2026
bee06b0
fix: jina-colbert-v2 reranker fails to load and turns hybrid search o…
Classic298 Sep 30, 2026
2f6addf
fix: new chat from the search dialog cuts off or changes text contain…
Classic298 Sep 30, 2026
bff0492
fix: every log line is exported twice to the OpenTelemetry collector …
Classic298 Sep 30, 2026
3d46a59
fix: turn a large channel paste into a file when Paste Large Text as …
silentoplayz Sep 30, 2026
f98ca22
perf: use the faster JSON encoder by default (#31616)
Classic298 Sep 30, 2026
d7a7445
fix: question and answer vanish from the chat when a background sub-a…
Classic298 Sep 30, 2026
32e532b
fix: copy last code block shortcut copies the Artifacts pane instead …
Classic298 Sep 30, 2026
909a207
fix: Scheduled Tasks calendar shows extra runs for automations with a…
Classic298 Sep 30, 2026
e276d33
fix: keep a note's pasted images when the note is rebuilt from HTML (…
silentoplayz Sep 30, 2026
a29c969
fix: SCIM group members are returned with "$ref": null (#31529)
Classic298 Sep 30, 2026
a5176f4
fix: Google MCP connections drop about an hour after signing in (#31395)
Classic298 Sep 30, 2026
d09ab78
fix: typing with an input method breaks in the empty chat input while…
Classic298 Sep 30, 2026
fab58bd
fix: ejecting a model ignores AIOHTTP_CLIENT_SESSION_SSL (#31391)
Classic298 Sep 30, 2026
c7caa14
fix: tool HTML embeds vanish when the HTML contains entities like &qu…
Classic298 Sep 30, 2026
d4d04dc
fix: keep a cloned chat in a shared folder the user can write to (#31…
silentoplayz Sep 30, 2026
bb8e986
i18n: translate missing Simplified Chinese settings labels (#31519)
Alex0AI Sep 30, 2026
afeab2e
fix: clear a pending channel reply when switching to another channel …
silentoplayz Sep 30, 2026
e924fa7
fix: re-enable the connection dialog's Save after an invalid Headers …
silentoplayz Sep 30, 2026
6e3ad22
fix: report invalid image Additional Parameters JSON instead of leavi…
silentoplayz Sep 30, 2026
b857eb8
fix: find read-only shared notes when searching the chat's note picke…
silentoplayz Sep 30, 2026
101cdb6
fix: edit a repeating event's series instead of moving its start to t…
silentoplayz Sep 30, 2026
9d2c396
fix: send max_completion_tokens for Bedrock-prefixed OpenAI models (#…
Classic298 Sep 30, 2026
69f64c9
fix: channel mention notification shows raw mention markup with the u…
Classic298 Sep 30, 2026
a5bc783
fix: open the highlighted chat when Enter is pressed in the search di…
silentoplayz Sep 30, 2026
7e317fb
refac
tjbck Sep 30, 2026
f453324
fix: artifact preview sometimes closes the moment it auto-opens (#31653)
Classic298 Sep 30, 2026
1058444
fix: artifact preview closes right after opening when a filter writes…
Classic298 Sep 30, 2026
6c32294
fix: iPhone HEIC photos are rejected by vision models (#31649)
Classic298 Sep 30, 2026
3d43a49
fix: shared chats can't open new files attached together with a file …
Classic298 Sep 30, 2026
75bff4b
feat: native hybrid search for Milvus and Milvus multitenancy (#31645)
Classic298 Sep 30, 2026
4ef7e35
fix: Playwright web loader returns only the site menu for pages with …
Classic298 Sep 30, 2026
aee7c47
feat: Milvus hybrid search without a second text-only copy of every c…
Classic298 Sep 30, 2026
e797a44
fix: don't bring up the keyboard when menus open or close on mobile (…
silentoplayz Sep 30, 2026
f50f9e6
refac
tjbck Sep 30, 2026
3ef0d15
fix: audit log shows passwords that contain a double quote (#31659)
Classic298 Oct 1, 2026
c3fbf36
fix: uploaded files lose Chinese punctuation and quotes (#31655)
Classic298 Oct 1, 2026
bf7b633
i18n: complete and review existing Hindi translations (#31662)
EllaFr Oct 1, 2026
dc713a6
refac
tjbck Oct 1, 2026
1c233f1
fix: sub-agents in folder chats are not limited to the folder's knowl…
Classic298 Oct 1, 2026
e88e1f8
fix: prompt cache misses after a model calls tools one after another …
Classic298 Oct 1, 2026
7cf35be
fix: editing a knowledge file on Elasticsearch keeps its old text sea…
Classic298 Oct 1, 2026
d8177c4
fix: send the query embedding as a vector in external pgvector retrie…
Classic298 Oct 1, 2026
5e1f4d8
fix: subscribe members added to a channel to its live feed (#31113)
Classic298 Oct 1, 2026
5b0a889
fix: apply the custom model fallback to chats sent from the web UI (#…
Classic298 Oct 1, 2026
ecd0ff6
fix: apply the duplicate-content check to knowledge batch add (#31336)
Classic298 Oct 1, 2026
2178777
fix: send signed-out visitors on a shared chat link to the login page…
Classic298 Oct 1, 2026
be35c8f
fix: save list user valves in Chat Controls the way the valves dialog…
silentoplayz Oct 1, 2026
8a45471
refac
tjbck Oct 1, 2026
99f1eaa
fix: keep dollar signs intact when a code block is saved (#31386)
silentoplayz Oct 1, 2026
0f46d60
fix: server memory grows with every chat until a restart (#31534)
Classic298 Oct 1, 2026
015dbc8
refac
tjbck Oct 1, 2026
a7bf64f
fix: remove deleted open chat from sidebar folder
macodev00 Sep 27, 2026
00105e4
i18n: sync locale catalogs with extracted source strings
macodev00 Oct 1, 2026
18768a8
style: satisfy ruff format in get_tools
macodev00 Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,15 @@ ENABLE_KNOWLEDGE_FILE_RETENTION=false
# Comma-separated chunk metadata keys to expose to the model alongside retrieved content.
RAG_SOURCE_METADATA_KEYS=''

# Set to false to disable workspace Tools and Functions.
# Master switch for internal Tools/Functions and external OpenAPI/MCP/Open Terminal plugins.
# All plugin switches require a restart; the master overrides all feature switches.
ENABLE_PLUGINS=true
# Set false to disable workspace Tools and their dependency installation.
ENABLE_TOOLS=true
# Set false to disable Functions (filters, pipes, actions, event functions) and their dependencies.
ENABLE_FUNCTIONS=true
# Set false to disable external tools and terminals, including personal direct connections.
ENABLE_TOOL_SERVERS=true

# For production you should set this to match the proxy configuration (127.0.0.1)
FORWARDED_ALLOW_IPS='*'
Expand Down
1 change: 1 addition & 0 deletions backend/open_webui/constants.py
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,7 @@ def __str__(self) -> str:

INVALID_TOKEN = 'Your session has expired or the token is invalid. Please sign in again.'
INVALID_CRED = 'The email or password provided is incorrect. Please check for typos and try logging in again.'
OAUTH_LOGIN_FAILED = 'Sign-in with your identity provider failed. Please contact your administrator for assistance.'
INVALID_EMAIL_FORMAT = "The email format you entered is invalid. Please double-check and make sure you're using a valid email address (e.g., yourname@example.com)."
INCORRECT_PASSWORD = 'The password provided is incorrect. Please check for typos and try again.'
INVALID_TRUSTED_HEADER = (
Expand Down
6 changes: 5 additions & 1 deletion backend/open_webui/env.py
Original file line number Diff line number Diff line change
Expand Up @@ -159,7 +159,7 @@ def format(self, record: logging.LogRecord) -> str:
# Swap the JSON encoder/decoder used across the app (HTTP request bodies, JSONResponse
# bodies, upstream provider responses, socket.io payloads) from the stdlib `json` module
# to orjson. Faster, but stricter: see open_webui/utils/json_codec.py for the differences.
ENABLE_ORJSON = os.getenv('ENABLE_ORJSON', 'False').lower() == 'true'
ENABLE_ORJSON = os.getenv('ENABLE_ORJSON', 'True').lower() == 'true'


# Function to parse each section
Expand Down Expand Up @@ -1192,6 +1192,10 @@ def _int_env(name: str, default: int) -> int:
####################################

ENABLE_PLUGINS = os.getenv('ENABLE_PLUGINS', 'True').lower() == 'true'
# Deployment controls: the master switch always overrides all feature switches.
ENABLE_TOOLS = ENABLE_PLUGINS and os.getenv('ENABLE_TOOLS', 'True').lower() == 'true'
ENABLE_FUNCTIONS = ENABLE_PLUGINS and os.getenv('ENABLE_FUNCTIONS', 'True').lower() == 'true'
ENABLE_TOOL_SERVERS = ENABLE_PLUGINS and os.getenv('ENABLE_TOOL_SERVERS', 'True').lower() == 'true'

ENABLE_PIP_INSTALL_FRONTMATTER_REQUIREMENTS = (
os.getenv('ENABLE_PIP_INSTALL_FRONTMATTER_REQUIREMENTS', 'True').lower() == 'true'
Expand Down
7 changes: 4 additions & 3 deletions backend/open_webui/events.py
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,10 @@
from types import SimpleNamespace
from typing import Any

from open_webui.env import ENABLE_PLUGINS, VERSION
from open_webui.models.config import Config
from pydantic import BaseModel, ConfigDict, Field, model_validator

from open_webui.env import ENABLE_FUNCTIONS, VERSION
from open_webui.models.config import Config
from open_webui.retrieval.web.utils import validate_url
from open_webui.utils.webhook import post_webhook

Expand Down Expand Up @@ -1103,7 +1104,7 @@ async def handle_event(self, app: Any, event: Event, request: Any | None = None)
async def dispatch_event_functions(
app: Any, event: Event, request: Any | None = None, extra_function_ids: list[str] | None = None
) -> None:
if not ENABLE_PLUGINS:
if not ENABLE_FUNCTIONS:
return

from open_webui.models.functions import Functions
Expand Down
4 changes: 2 additions & 2 deletions backend/open_webui/functions.py
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@

from open_webui.config import BYPASS_ADMIN_ACCESS_CONTROL
from open_webui.constants import ERROR_MESSAGES
from open_webui.env import BYPASS_MODEL_ACCESS_CONTROL, ENABLE_PLUGINS, GLOBAL_LOG_LEVEL
from open_webui.env import BYPASS_MODEL_ACCESS_CONTROL, ENABLE_FUNCTIONS, GLOBAL_LOG_LEVEL
from open_webui.models.functions import Functions
from open_webui.models.models import Models
from open_webui.models.users import UserModel
Expand Down Expand Up @@ -69,7 +69,7 @@ async def get_function_module_by_id(request: Request, pipe_id: str):


async def get_function_models(request):
if not ENABLE_PLUGINS:
if not ENABLE_FUNCTIONS:
return []

pipes = await Functions.get_functions_by_type('pipe', active_only=True)
Expand Down
4 changes: 2 additions & 2 deletions backend/open_webui/internal/db.py
Original file line number Diff line number Diff line change
Expand Up @@ -134,7 +134,7 @@ class JSONField(types.TypeDecorator): # TEXT-backed JSON storage
cache_ok = True

def process_bind_param(self, value: _T | None, dialect: Dialect) -> Any:
return JSONCodec.dumps(value) if value is not None else None
return JSONCodec.dumps(value, ensure_ascii=False) if value is not None else None

def process_result_value(self, value: _T | None, dialect: Dialect) -> Any:
return JSONCodec.loads(value) if value is not None else None
Expand Down Expand Up @@ -265,7 +265,7 @@ def _json_codec_kwargs(kwargs: dict) -> dict:
Unlike ``JSONField``, those serialize through the engine, which otherwise uses
stdlib ``json``. With ``ENABLE_ORJSON`` off JSONCodec is stdlib ``json`` anyway.
"""
kwargs.setdefault('json_serializer', JSONCodec.dumps)
kwargs.setdefault('json_serializer', lambda value: JSONCodec.dumps(value, ensure_ascii=False))
kwargs.setdefault('json_deserializer', JSONCodec.loads)
return kwargs

Expand Down
Loading
Loading