Merge pull request #26388 from open-webui/dev

0.10.1
This commit is contained in:
Tim Baek
2026-06-29 14:38:32 -05:00
committed by GitHub
4 changed files with 25 additions and 4 deletions

View File

@@ -5,6 +5,12 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## [0.10.1] - 2026-06-29
### Fixed
- 🤝 **Shared folder read-only chats no longer sign users out.** Opening or reading chats from shared folders now keeps the current session active when a resource-level access error is returned, instead of incorrectly showing "Session expired. Please sign in again."
## [0.10.0] - 2026-06-29
### Added

4
package-lock.json generated
View File

@@ -1,12 +1,12 @@
{
"name": "open-webui",
"version": "0.10.0",
"version": "0.10.1",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "open-webui",
"version": "0.10.0",
"version": "0.10.1",
"dependencies": {
"@azure/msal-browser": "^4.5.0",
"@codemirror/lang-javascript": "^6.2.2",

View File

@@ -1,6 +1,6 @@
{
"name": "open-webui",
"version": "0.10.0",
"version": "0.10.1",
"private": true,
"scripts": {
"dev": "npm run pyodide:fetch && vite dev --host",

View File

@@ -810,6 +810,20 @@
});
};
const isAuthFailureResponse = async (response) => {
try {
const data = await response.clone().json();
const detail = data?.detail;
return (
detail === '401 Unauthorized' ||
detail === 'Not authenticated' ||
detail === 'Your session has expired or the token is invalid. Please sign in again.'
);
} catch {
return true;
}
};
const checkTokenExpiry = async () => {
const exp = $user?.expires_at; // token expiry time in unix timestamp
const now = Math.floor(Date.now() / 1000); // current time in unix timestamp
@@ -939,7 +953,8 @@
if (
response.status === 401 &&
localStorage.token &&
isAuthenticatedBackendFetch(input, init)
isAuthenticatedBackendFetch(input, init) &&
(await isAuthFailureResponse(response))
) {
redirectToAuthAfterUnauthorized();
}