5302 Commits
Author SHA1 Message Date
Classic298 d4b9d19645 fix: system prompt and compacted context are lost after approving a tool call (#31501)
With tool approval set to ask, the request sent to the model after approving a tool call left out the system prompt. In a compacted chat it also left out the conversation summary and sent the whole history again. The request after approval now has the same system prompt and compacted context as the one before it, plus the tool call and its result. The system prompt is picked the same way as for any other message: the chat Controls prompt, else your personal Settings prompt, else the admin default. A system prompt sent only in an API request is not kept by the server, so it is still missing after approval.

Fixes #31499
2026-09-28 07:59:43 +04:00
Classic298 b00745c8d0 fix: approved tool results are lost and approved tools can run twice (#31502)
With tool approval set to ask, the result of an approved tool call was dropped from the chat once the reply finished, so the model no longer saw it in later turns. When the model then asked for a second tool, the first call went back to waiting for approval, and approving it again ran the tool a second time. Approved results now stay in the chat and each tool runs once.

Related to #31499
2026-09-28 07:59:20 +04:00
Classic298 fc9ad75164 fix: admins can still read and change other users' chats with ENABLE_ADMIN_CHAT_ACCESS off (#31416)
With ENABLE_ADMIN_CHAT_ACCESS turned off, opening another user's chat was refused, but through direct API requests an admin could still get the whole chat back in the reply to editing or deleting one of its messages, grant themselves read access in the chat's share settings, clone a chat someone shared privately with another user, or delete the chat. They could also send messages into it, attach it as context to their own chat, approve its tool calls, and list or stop its running replies. All of these are now refused for an admin on another user's chat, the same as opening it. With the setting on, admins keep full access as before.

Fixes #31413
2026-09-28 01:51:59 +04:00
Classic298 e8d6a8734a fix: model upload, download and unload ignore a connection's custom headers and auth type (#31490)
Uploading or downloading a GGUF model to an Ollama connection sent neither the key nor the connection's custom headers, so it failed behind gateways such as Cloudflare Access and on servers that need a key. Unloading a model dropped the custom headers and sent the key as a Bearer token even with the authentication type set to None, for Ollama and llama.cpp connections alike. These requests now use the connection's headers and authentication type the same as chatting and the Manage Ollama dialog already do. Follow-up to #31489.
2026-09-28 01:48:26 +04:00
Timothy Jaeryang Baek af6b82a18c refac 2026-09-28 00:11:04 +04:00
Classic298 00a245b9fa fix: Manage Ollama ignores a connection's custom headers and auth type (#31489)
Listing, pulling, creating, copying and deleting models from the Manage Ollama dialog ignored the connection's custom headers and authentication type, so the dialog failed behind gateways such as Cloudflare Access and sent the key as a Bearer token even with the authentication type set to None. Checking a single connection's version sent no key at all. All of these, and the other requests to an Ollama connection such as text generation and embeddings, now use the connection's headers and authentication type, matching what verifying the connection and chatting already do.

Fixes #31487
2026-09-28 00:04:18 +04:00
Timothy Jaeryang Baek bc2416c5db refac 2026-09-27 23:29:38 +04:00
Classic298 1c813902ec fix: keep relevance scores on knowledge tool citations (#31307)
With native function calling, citations produced by query_knowledge_files and query_chat_files never showed the relevance percentage badge, while the same knowledge base queried through classic RAG did.

The tools already return a distance per chunk, but the step that groups tool results into citation sources dropped it. Each grouped source now carries a distances list aligned with its documents, the same shape the classic RAG path emits, so the existing citation UI shows the badge without frontend changes. Chunks without a score (notes) leave the list empty, which the UI already treats as no score.

Fixes #29776
2026-09-27 23:21:21 +04:00
Classic298 0fe9ed0d3c fix: Anthropic API streams report a failed response as a finished one (#31405)
When the provider failed partway through a streaming request to the Anthropic Messages endpoint, the stream still ended like a normally finished answer, so Claude Code and the Anthropic SDKs took the cut-off text as complete. The stream now ends with an Anthropic error event, with the provider's error message if it sent one, so clients raise an error. Successful streams are unchanged.

Fixes #31403
2026-09-27 23:20:50 +04:00
Classic298 6e5e5fe6e9 feat: add a Tavily search depth setting (#31308)
Tavily web search always ran at Tavily's default depth (basic), because the search request never sent `search_depth`. The only Tavily depth control in Admin > Settings > Web Search, "Tavily Extract Depth", applies to the Extract API used by the web loader, never to search.

This adds `TAVILY_SEARCH_DEPTH` (env var and persisted setting, default `basic`) and a "Tavily Search Depth" select (ultra-fast, fast, basic, advanced) under the Tavily search engine settings. The value is sent as `search_depth` on every Tavily search request, so admins can set search and extract depth independently, for example fast search with advanced extraction.

The default matches Tavily's own default, so existing setups keep the same behaviour until the setting is changed.

Fixes #29891
2026-09-27 23:15:09 +04:00
Classic298 b8de508dbc fix: keep arena model access after editing it in Settings > Models (#31309)
Saving an arena model in Admin Settings > Models (for example to set default tools or capabilities) creates a model entry with the arena id. That entry replaced the arena model's metadata wholesale, dropping the access grants, model_ids and filter_mode configured in Admin Settings > Evaluations. From then on every non-admin user lost the arena model, even when it was public, and chats through it ignored the configured model pool.

The override now keeps those three keys from the evaluation config, which is where arena access and the model pool are managed. Everything else set in Settings > Models (tools, capabilities, description, profile image) still applies.

Verified end to end on base and patched: after the override a user sees and can chat with a public arena model (base: hidden, 400), private arena models stay hidden, and 20 admin chats all route to the configured pool (base: spread across all models).

Fixes #29564
2026-09-27 23:14:47 +04:00
Classic298 35dda256f0 fix: approve every tool call from a multi-call turn in ask mode (#31315)
In "Ask for approval" mode, when the model requested several tools in one turn, only the first call got an approval card. The others stayed on "Executing..." forever, never ran, could not be approved (the server answered "already resolved"), and the model was called again without their results. The stuck state was saved to the chat.

Once streaming finishes, every call in the turn is marked as completed (arguments done, nothing run yet). The approval pause only queued siblings that were still in progress, so these were skipped. They are now queued as well, and each one gets its own approval card in turn after the previous one is resolved.

Calls that already have a result and rejected calls are untouched, and single-call turns behave as before. Verified against the real approval functions with same-name, mixed-name, reject and ask_user batches, plus the tests-repo unit suite (identical results before and after).

Fixes #29293
2026-09-27 23:14:30 +04:00
Classic298 b91a558c9d fix: stop forwarding empty tools arrays from the Anthropic Messages endpoint (#31343)
Anthropic clients such as Claude Code send "tools": [] on text-only requests like prompt-hook evaluation. The Anthropic Messages endpoint carried that empty array into the converted OpenAI request, and vLLM and the OpenAI API reject it with HTTP 400, so those requests failed while normal chats with tools kept working. A "tools": null body crashed the converter with a 500.

The converter now only emits tools when the list is non-empty, and only emits tool_choice when tools were emitted. Dropping tools alone is not enough: the same backends also reject tool_choice without tools, so a request sending an empty tool list plus a tool_choice would still fail.

Requests with real tools are converted exactly as before. Verified end to end against a mock backend enforcing vLLM's validation: empty, null and tool_choice-only requests went from 400/500 to 200 with end_turn, streaming included.

Fixes #31341
2026-09-27 23:11:45 +04:00
Classic298 91fb33ef57 fix(retrieval): name the link when process/url cannot fetch it (#31354)
Attaching a link in chat or to a knowledge base that cannot be fetched (closed port, blocked by the fetch filter, an HTTP error such as 404) showed the toast "Error processing URL", which never said which link failed or that fetching it was the problem.

The fetch step now answers with "Could not read content from <url>", the same message process/web gives for a link it cannot read, so both endpoints report a dead link the same way. The too-large 413 still passes through unchanged, and a working link returns exactly what it did before.

The new handler covers only the fetch. Rewording the endpoint's existing catch-all would be one line, but that handler also receives database errors from the config and file lookups, which would then be reported as an unreadable link.

Related to #31347
2026-09-27 23:11:20 +04:00
Classic298 5d4f9b957e fix: foreground sub-agents cannot use personal tool servers like Open Terminal (#31424)
With a personal tool server connection such as Open Terminal, the main model could call its tools but a foreground sub-agent it delegated to got none of them. Chats resuming after a tool approval lost those tools the same way. Setting up the tools for the main model emptied the list those later steps read from. It now works on a copy, so sub-agents and resumed chats get the same tools as the parent.

Fixes #29893
2026-09-27 23:10:16 +04:00
Classic298 d6b19dcaa1 fix: on PostgreSQL, searching automations or filtering models by a non-ASCII word finds nothing (#31423)
On PostgreSQL with ENABLE_ORJSON off (the default), searching automations by a word from their prompt, or filtering models by a tag, found nothing when the word was non-ASCII, for example Chinese. SQLite, and PostgreSQL with ENABLE_ORJSON on, were fine. With the default setting non-ASCII text is saved as \uXXXX codes, and PostgreSQL reads the backslash in a search pattern as a special character, so the search never matched. Special characters in the search text are now taken literally, so these searches work on both databases, and a % or _ typed into them now matches only itself.

Fixes #31422
2026-09-27 23:09:54 +04:00
Classic298 59ea3b7c2c fix: backslashes in uploaded HTML files turn into line breaks or break the upload (#31450)
With the default content extraction engine, backslashes in an uploaded .html or .htm file were read as escape sequences. A path like C:\new\table was saved with a line break and a tab in it, and a page containing C:\Users failed to upload with a 'unicodeescape' codec error. HTML files are now read the same way as .txt and .md uploads, so the saved text matches the page.

Fixes #31440
2026-09-27 23:08:14 +04:00
Classic298 31a09a1eeb refac: check the owner's role before continuing a chat after a subagent finishes (#31451)
The parent chat now only continues with a finished subagent's result while its owner still has a verified role, the same check timers already make.
2026-09-27 22:59:11 +04:00
Classic298 eda8d85361 fix: hybrid search finds nothing when a collection cannot be read (#31460)
With hybrid search on and a vector database without built-in hybrid search, a collection that failed to load (for example Qdrant strict mode rejecting the request) was skipped quietly, so retrieval returned no documents and never fell back to normal vector search. A failed load now counts as a failed collection, so when every collection fails retrieval falls back to vector search, the same way it already does when the search itself fails. The retrieval API returns its usual error in that case.

Part of #31459
2026-09-27 22:59:02 +04:00
Classic298 8a90f0fc93 fix: file uploads and hybrid search fail on Qdrant with strict mode enabled (#31461)
With Qdrant strict mode on and a max_query_limit below 999999999, Qdrant rejects Open WebUI's reads with "Limit exceeded", so every file upload after the first fails in the default multitenancy mode, and hybrid search finds nothing. Reads now go in pages of 1000 points, so any strict-mode limit of 1000 or more works. Without strict mode the results are the same as before.

Tested against Qdrant 1.19.1 with max_query_limit 1000, for both multitenancy on and off: collections of up to 2500 points come back complete, limits are respected, and tenants stay separated.

Fixes #31459
2026-09-27 22:58:42 +04:00
Classic298 b0650d04b2 fix: failed timer leaves a blank, unfinished reply in the chat (#31483)
When a scheduled timer failed before the model started answering, for example because its model had been removed, the chat showed the timer's prompt with a blank reply that looked stuck, and the error never appeared in the chat. The reply now shows the error and stops loading, like any other failed message.

Fixes #31481
2026-09-27 22:56:20 +04:00
Classic298 420b4a2797 fix(retrieval): name the link when process/web cannot fetch it (#31351)
A link whose host refuses the connection, such as a closed port, still came back from POST /api/v1/retrieval/process/web as "Error querying knowledge base", so the caller was told the knowledge base failed when the link was the problem.

The web loaders log a failed fetch and return no documents. That empty result then failed while being saved to the vector store, and the save error was the one reported.

process_web now answers with the existing "Could not read content from <url>" 400 as soon as the loader returns no documents, the same message a link refused by the fetch filter already gets. The check sits in the endpoint so web search and the other users of the loaders keep their current behaviour.

With process=false or embedding bypassed, an unreachable link now gets the same 400 where it used to return 200 with empty content.

Fixes #31347
2026-09-26 07:28:13 +04:00
G30 ffe21bef8d fix: remove the share links of chats deleted along with their folder (#31306) 2026-09-26 07:27:49 +04:00
Classic298 42cd4f0ec0 refactor: check shared chat access before loading the snapshot on clone (#30388)
The clone endpoint now resolves and checks the share before reading its snapshot, matching the order used by the shared chat view endpoint.
2026-09-26 07:20:14 +04:00
Classic298 fe8b30438a fix: stray <|end_of_solution|> marker left in the reply (#31436)
When a model wraps its answer in <|begin_of_solution|> and <|end_of_solution|>, only the opening marker was removed. The closing marker stayed visible in the reply and was saved with the message, and anything the model wrote after it was glued onto the answer. Now both markers are removed and text after the answer shows up as a normal part of the reply.

Fixes #31434
2026-09-26 07:19:09 +04:00
Classic298 25604d7070 fix: chats keep failing on Anthropic and Bedrock after a tool call is saved incorrectly (#31431)
Sometimes a reply where the model used tools gets saved with a tool result that no call in that reply asked for, or with a tool call that never got its result. The chat history was then sent to the provider unchanged, Anthropic and Bedrock rejected it, and every following message in that chat failed until the user deleted the broken reply. Now each tool call is only kept together with its own result from the same reply, and the unmatched calls and results are left out of what gets sent to the model. The chat itself is not changed, and correctly saved chats are sent exactly as before.

Fixes #28937
2026-09-26 07:19:00 +04:00
Classic298 583f5a66d2 fix: max_tokens sent through the API is ignored for Ollama models (#31437)
When an API request to an Ollama model set max_tokens, Open WebUI passed it on in a place Ollama does not read, so Ollama ignored it and replies ran to full length. The limit now reaches Ollama as its own output length setting, so replies stop at the requested length. It also wins over a max_tokens value saved in the model's advanced parameters, as the API docs describe. Chats in the web UI were not affected, since their limit already reached Ollama correctly.

Fixes #31432
2026-09-26 07:18:43 +04:00
Classic298 8081ac299f fix: missing space in reasoning model answers right after the thinking block (#31438)
With reasoning models, when the first part of the answer arrived together with the end of the thinking block and ended with a space, that space went missing, so "The answer is 4." was shown and saved as "The answeris 4.". That space is now kept.

Fixes #31435
2026-09-26 07:18:35 +04:00
Classic298 9d6b17ffbc fix: errors on Responses API connections are not shown or not kept after a reload (#31439)
With a connection set to the Responses API, when the provider reported a reply as failed, the error showed while streaming but was gone after a reload, leaving an empty reply. Some other provider errors never showed up at all, not even while streaming. Both kinds of error now show up and are still there after a reload, the same as on Chat Completions connections.

Fixes #31433
2026-09-26 07:18:23 +04:00
Classic298 ac00d40e36 fix: model sync no longer fails with "database is locked" on SQLite (#31349)
On the default SQLite setup (session sharing off), a POST to /api/v1/models/sync containing any model that already exists answered 200 with an empty list and stored nothing. After a 5 second stall, the only trace was "database is locked" in the server log.

The sync wrote each model's access grants while the model update was still uncommitted. Without session sharing the grant writes run on a second database session, and SQLite allows one writer at a time, so that write waited on the same request's uncommitted update until the busy timeout expired and the whole sync was dropped.

Grants are now written after the model changes are committed, the same order model create and update already use. A failed model commit now also leaves every grant untouched. PostgreSQL and setups with session sharing on behave as before.

Fixes #31346
2026-09-25 01:06:56 -04:00
Classic298 fcb0af3fd4 fix: skip blocked OAuth groups when auto-creating groups (#31316)
With ENABLE_OAUTH_GROUP_CREATION on, every group in a user's OAuth claim was created on login, including groups matching OAUTH_BLOCKED_GROUPS. Membership sync already ignored those groups, so the result was empty groups nobody could join. With IdPs that send a user's full directory membership (Keycloak backed by LDAP/AD), one login could fill the group table with thousands of them.

Group creation now applies the same blocklist check as the membership add and remove steps, so a blocked group is never created, joined or left through OAuth. Groups that are not blocked are created as before.

Fixes #29558
2026-09-25 00:08:01 -04:00
Classic298 3c47f0d7e7 fix: stop decoding Korean and Japanese text uploads as Chinese (#31356)
Korean EUC-KR and Japanese Shift-JIS text files were stored as garbled Chinese characters, so retrieval, knowledge bases and the model context all worked on text that is not in the file.

Encoding detection puts chardet's guess in front of a fixed GB18030, Big5, EUC-KR, EUC-JP try order, and GB18030 decodes almost any double-byte text without an error. The guess map was written for chardet 5. Since the bump to chardet 7 in v0.10.0, Korean text is reported as CP949 and Japanese text as cp932 or SHIFT_JIS, which the map either did not know or dropped because the codec was not in the try order, so these files fell through to GB18030.

The map now covers CP949 and cp932, and a mapped guess is always tried first. SHIFT_JIS maps to cp932, the Windows superset, because chardet also reports SHIFT_JIS for ordinary Japanese files containing characters such as ① or ㈱ that plain Shift-JIS cannot decode; this is the same subset-to-superset rule the map already applies to GB2312.

Korean and Japanese files now decode correctly, and Chinese, EUC-JP, UTF-8 and Western files decode as before. The one trade-off of trusting the guess: chardet 7 labels some files holding only a few Chinese characters (a short label or a one-line comment) as CP949, and those now read as Korean. No regressions were found in files with more Chinese text than that.

Fixes #31352
2026-09-25 00:01:38 -04:00
Classic298 3f5881c520 fix: load terminal AGENTS.md on Windows Open Terminal hosts (#31342)
Fixes #31340

When the attached Open Terminal runs on Windows, the AGENTS.md in its home directory was never handed to the model. The home check only accepted POSIX absolute paths, so a drive-letter or UNC home such as C:\ProgramData\OpenTerminal\inst was treated as invalid and the file was skipped without any log line.

The check now also accepts Windows absolute paths. Relative and drive-relative homes are still skipped, and POSIX homes send byte-identical requests.

The file path keeps its forward-slash join. Open Terminal normalises the path on the host, so C:\Users\bob/AGENTS.md opens C:\Users\bob\AGENTS.md. Picking ntpath.join for Windows homes would give native separators on the wire but adds a second branch for no change in which file gets read.

Verified against Open Terminal's own path resolution with Windows semantics for drive-letter, forward-slash, drive-root, trailing-backslash and UNC homes, over both the backend request and the browser direct-connection path.
2026-09-25 00:00:59 -04:00
Classic298 fccd755684 fix: send the saved title in the chat:title event when title generation is off (#31355)
Fixes #31348

With title generation turned off (per user or by the admin), the chat is saved with the first user message as its title, but the live title event sent the assistant message instead. A new chat therefore kept showing "New Chat" in the header and tab until a reload, because the assistant message is still empty at that point. In a note's chat panel the whole model reply showed up as the title.

The fallback branch now sends the title it just saved, the same way the generated-title branch above it already does. The sidebar was never affected because it reloads titles from the database.
2026-09-24 15:58:50 -04:00
Timothy Jaeryang Baek 7ad0ae4687 refac 2026-09-24 12:34:04 -04:00
G30 9836367ab2 fix: apply the group filter to the Analytics hourly chart (#30978) 2026-09-24 12:11:13 -04:00
Timothy Jaeryang Baek f412538756 refac 2026-09-24 12:10:30 -04:00
G30 a046e07044 fix: save a file edit made through write access to a shared knowledge base (#30448) 2026-09-23 23:05:37 -05:00
Classic298 d9dff09c30 refac: build the SQLite LIKE regex from wildcard-split segments (#30393)
Each '%'-separated segment of the LIKE pattern is now matched with an atomic group.
2026-09-23 23:55:57 -04:00
Classic298 14c5b65704 refac: tighten details and image patterns in background task message cleanup (#30394)
The patterns that remove details blocks and inline images from task messages now stop at the next details tag, bracket or parenthesis.
2026-09-23 23:55:07 -04:00
Classic298 f7294161fa fix: show ComfyUI images saved by the Save Image (Advanced) node (#30420)
When a ComfyUI workflow ends in the core "Save Image (Advanced)" node, ComfyUI finishes the job and saves the image, but Open WebUI returns an empty result, so the chat shows nothing. Image editing workflows such as the Qwen Image Edit template use this node by default.

Open WebUI only collects images from output nodes of type SaveImage and PreviewImage. This adds SaveImageAdvanced to that list. The node reports its files in the same format as SaveImage, so the rest of the download and storage path works unchanged. Generation and editing share this code, so both are fixed.

Fixes #30404
2026-09-23 23:54:58 -04:00
Classic298 b6191a0510 fix: stop storing MCP image/audio base64 in file metadata (#30419)
When an MCP tool returns an image or audio item, the file is uploaded to storage, but the whole MCP item, including its base64 payload, was also passed as upload metadata. That metadata is persisted in the file table's meta column, so every such result was stored twice: once in storage and once as base64 in the database, growing the DB and every file query that loads meta.

The MCP path now passes only chat_id, message_id and session_id, the same metadata the non-MCP tool image path already stores. Nothing reads the removed key.

Fixes #30411
2026-09-23 23:54:23 -04:00
Classic298 f7ce4024d6 fix: keep requested MCP OAuth scope when DCR response omits it (#30384)
MCP tool servers using OAuth 2.1 with dynamic client registration authorized without any scope when the authorization server left scope out of its registration response, which RFC 7591 allows (Atlassian and Notion do). Consent completed and the tool showed as connected, but the issued token lacked the scopes the resource requires, so every tool call was refused. Discovered scopes and the custom OAuth Scopes field were both affected.

The stored client now falls back to the scope sent in the registration request when the response has none. A scope the server does return is kept as is.

Connections registered before this fix already have a null scope stored. The protected resource metadata recovery that static-credential clients already use now also runs for dynamically registered clients, so those connections pick up the discovered scopes on the next load without registering again.

Fixes #29967
2026-09-23 23:52:29 -04:00
Classic298 60ded561a9 fix: load models before resolving automation model defaults (#30379)
Automations lost their model's tool bindings (including MCP servers), default features such as web search, default filters and terminal on the first run after a restart. The model then answered that it had no tools. Later runs and a manual Regenerate worked. Automations on the base models cache were not affected.

The run read the model from app.state.MODELS before anything had loaded it. After a restart or a connection settings save, that cache stays empty until a browser loads the model list or a chat completion runs. The completion runs only after the automation has already built its request.

execute_automation now loads the models when the cache is empty, using the same guard chat_completion uses, before either the chat or the channel target reads it. This also fixes channel automations showing the raw model ID in place of the model name on a cold cache.

Verified end to end on a restarted instance with a mock upstream: before, both chat and channel runs reached the pipeline without tool_ids or features. After, both carry the model's tools and web search, and the upstream receives the tool.

Fixes #27694
2026-09-23 23:51:29 -04:00
Classic298 744ce6cbfe fix: send the configured USER_AGENT on the Attach Webpage pre-check (#30385)
Attach Webpage fails with 403 Forbidden on sites that reject the bare aiohttp user agent, Wikipedia among them, even when USER_AGENT is set. The web loader sends USER_AGENT, but the request that runs first to decide whether the URL is a page or a file does not, so the attachment fails before the loader is ever reached.

The pre-check now sends USER_AGENT as the request User-Agent when it is set. With it unset the request is unchanged and keeps the aiohttp default.

Verified against the real _fetch_url with https://en.wikipedia.org/wiki/OpenAI: 403 before, page detected after; USER_AGENT unset still returns the same 403 as before, and a direct PDF URL is still detected as a file.

Fixes #29617
2026-09-23 23:50:08 -04:00
Classic298 2867f7225b refac: sync channel room on member removal (#30446)
Removing members from a group or DM channel now also removes their sessions from the channel room, matching how access grant changes are handled.
2026-09-23 23:43:20 -04:00
Classic298 443736e1fe refactor: use secrets module for generated secret key (#30441)
Generates the default WEBUI_SECRET_KEY file with secrets.token_bytes, matching how the start scripts read from the OS random source.
2026-09-23 23:36:26 -04:00
Classic298 a973e77cfa refac: folder file checks (#30442)
Folder file entries are also checked against the user making the change.
2026-09-23 23:36:15 -04:00
Classic298 4caf255389 fix: refresh an expiring OAuth token once across workers and replicas (#30450)
#30426 stopped concurrent requests from refreshing the same OAuth session twice, but its lock only lives inside one process. With several uvicorn workers or replicas, two requests on different workers still send the same refresh token, a rotating provider rejects the second with invalid_grant, and the session gets deleted, so the user's OAuth session is logged out again.

When Redis is configured, which multi-worker and multi-replica deployments require, the refresh now takes a Redis lock per session instead of the in-process one. Single-process deployments without Redis keep the in-process lock. The waiter re-reads the session inside the lock as before and uses the token that was just stored.

It uses redis-py's own async lock because the existing RedisLock is synchronous and never waits. The Sentinel proxy now passes `lock` through unwrapped like `pipeline` and `pubsub`; otherwise it returned a coroutine and every refresh behind Sentinel would fail.

Tested with separate OS processes on one sqlite DB, a real Redis and a rotating mock provider: 2 and 5 processes (and 5 processes x 3 requests) now cause 1 refresh, every caller gets the new token and the session is kept (before: one refresh per process, session deleted every run). Single refresh, failed refresh, valid token and the single-process path without Redis are unchanged.

Follow-up to #30426, refs #30416
2026-09-23 23:33:09 -04:00
G30 0ab3a2b335 fix: restore tag rows after unarchiving all chats and remove unused ones after deleting all chats (#30453) 2026-09-23 23:32:54 -04:00