mirror of
https://github.com/open-webui/open-webui.git
synced 2025-12-12 04:15:25 +00:00
Fix admin model access (#17)
* Update models.py * Update models.py * Update models.py * Update ollama.py * Update openai.py * Update models.py * Update openai.py * Update ollama.py
This commit is contained in:
parent
62506b1955
commit
d8c4dd6f79
2 changed files with 58 additions and 40 deletions
|
|
@ -117,7 +117,7 @@ async def get_model_by_id(id: str, user=Depends(get_verified_user)):
|
||||||
model = Models.get_model_by_id(id)
|
model = Models.get_model_by_id(id)
|
||||||
if model:
|
if model:
|
||||||
if (
|
if (
|
||||||
user.role == "admin"
|
(user.role == "admin" and ENABLE_ADMIN_WORKSPACE_CONTENT_ACCESS)
|
||||||
or model.user_id == user.id
|
or model.user_id == user.id
|
||||||
or has_access(user.id, "read", model.access_control)
|
or has_access(user.id, "read", model.access_control)
|
||||||
):
|
):
|
||||||
|
|
|
||||||
|
|
@ -23,6 +23,7 @@ from open_webui.utils.access_control import has_access
|
||||||
|
|
||||||
from open_webui.config import (
|
from open_webui.config import (
|
||||||
DEFAULT_ARENA_MODEL,
|
DEFAULT_ARENA_MODEL,
|
||||||
|
ENABLE_ADMIN_WORKSPACE_CONTENT_ACCESS,
|
||||||
)
|
)
|
||||||
|
|
||||||
from open_webui.env import SRC_LOG_LEVELS, GLOBAL_LOG_LEVEL
|
from open_webui.env import SRC_LOG_LEVELS, GLOBAL_LOG_LEVEL
|
||||||
|
|
@ -181,45 +182,62 @@ async def get_all_models(request, refresh: bool = False, user: UserModel = None)
|
||||||
elif custom_model.is_active and (
|
elif custom_model.is_active and (
|
||||||
custom_model.id not in [model["id"] for model in models]
|
custom_model.id not in [model["id"] for model in models]
|
||||||
):
|
):
|
||||||
owned_by = "openai"
|
# Check access control for custom models
|
||||||
pipe = None
|
should_include = False
|
||||||
|
|
||||||
action_ids = []
|
if user and user.role == "admin" and ENABLE_ADMIN_WORKSPACE_CONTENT_ACCESS:
|
||||||
filter_ids = []
|
# Admin with full workspace access
|
||||||
|
should_include = True
|
||||||
|
elif user and user.id == custom_model.user_id:
|
||||||
|
# Owner always has access
|
||||||
|
should_include = True
|
||||||
|
elif user and has_access(user.id, "read", custom_model.access_control):
|
||||||
|
# User has explicit read access
|
||||||
|
should_include = True
|
||||||
|
elif not user:
|
||||||
|
# No user context - include for backwards compatibility
|
||||||
|
should_include = True
|
||||||
|
|
||||||
for model in models:
|
if should_include:
|
||||||
if (
|
owned_by = "openai"
|
||||||
custom_model.base_model_id == model["id"]
|
pipe = None
|
||||||
or custom_model.base_model_id == model["id"].split(":")[0]
|
|
||||||
):
|
|
||||||
owned_by = model.get("owned_by", "unknown owner")
|
|
||||||
if "pipe" in model:
|
|
||||||
pipe = model["pipe"]
|
|
||||||
break
|
|
||||||
|
|
||||||
if custom_model.meta:
|
action_ids = []
|
||||||
meta = custom_model.meta.model_dump()
|
filter_ids = []
|
||||||
|
|
||||||
if "actionIds" in meta:
|
for model in models:
|
||||||
action_ids.extend(meta["actionIds"])
|
if (
|
||||||
|
custom_model.base_model_id == model["id"]
|
||||||
|
or custom_model.base_model_id == model["id"].split(":")[0]
|
||||||
|
):
|
||||||
|
owned_by = model.get("owned_by", "unknown owner")
|
||||||
|
if "pipe" in model:
|
||||||
|
pipe = model["pipe"]
|
||||||
|
break
|
||||||
|
|
||||||
if "filterIds" in meta:
|
if custom_model.meta:
|
||||||
filter_ids.extend(meta["filterIds"])
|
meta = custom_model.meta.model_dump()
|
||||||
|
|
||||||
models.append(
|
if "actionIds" in meta:
|
||||||
{
|
action_ids.extend(meta["actionIds"])
|
||||||
"id": f"{custom_model.id}",
|
|
||||||
"name": custom_model.name,
|
if "filterIds" in meta:
|
||||||
"object": "model",
|
filter_ids.extend(meta["filterIds"])
|
||||||
"created": custom_model.created_at,
|
|
||||||
"owned_by": owned_by,
|
models.append(
|
||||||
"info": custom_model.model_dump(),
|
{
|
||||||
"preset": True,
|
"id": f"{custom_model.id}",
|
||||||
**({"pipe": pipe} if pipe is not None else {}),
|
"name": custom_model.name,
|
||||||
"action_ids": action_ids,
|
"object": "model",
|
||||||
"filter_ids": filter_ids,
|
"created": custom_model.created_at,
|
||||||
}
|
"owned_by": owned_by,
|
||||||
)
|
"info": custom_model.model_dump(),
|
||||||
|
"preset": True,
|
||||||
|
**({"pipe": pipe} if pipe is not None else {}),
|
||||||
|
"action_ids": action_ids,
|
||||||
|
"filter_ids": filter_ids,
|
||||||
|
}
|
||||||
|
)
|
||||||
|
|
||||||
# Process action_ids to get the actions
|
# Process action_ids to get the actions
|
||||||
def get_action_items_from_module(function, module):
|
def get_action_items_from_module(function, module):
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue