mirror of
https://github.com/open-webui/open-webui.git
synced 2026-09-28 17:08:25 -05:00
Custom metadata attached to a file upload now reaches the vector DB, but the model still never sees it. Both prompt-assembly paths build their output from a fixed field set: the classic RAG <source> tag carries only id, name and resource type, and the retrieval tools return only content, source and file id per chunk. A scraper that records where each document came from therefore cannot get that origin in front of the model, so answers cannot state it. RAG_SOURCE_METADATA_KEYS names the chunk metadata keys allowed through to the model. Configured keys are emitted as extra attributes on the <source> tag and as extra fields on tool result chunks, covering both retrieval paths. It is empty by default, so nothing changes for existing deployments. An allowlist instead of passing everything through, because chunk metadata also carries file hashes, collection names, embedding config and relevance scores, which would then be added to every retrieved chunk of every request. Values are attacker-controllable through an uploaded file, so they are escaped before they go into the tag, and a configured key can never displace a field the tag or the chunk already defines. Reported in open-webui/open-webui#29486.
47 lines
1.6 KiB
Bash
47 lines
1.6 KiB
Bash
# Ollama URL for the backend to connect
|
|
# The path '/ollama' will be redirected to the specified backend URL
|
|
OLLAMA_BASE_URL='http://localhost:11434'
|
|
|
|
OPENAI_API_BASE_URL=''
|
|
OPENAI_API_KEY=''
|
|
|
|
# AUTOMATIC1111_BASE_URL="http://localhost:7860"
|
|
|
|
# For production, you should only need one host as
|
|
# fastapi serves the svelte-kit built frontend and backend from the same host and port.
|
|
# To test with CORS locally, you can set something like
|
|
# CORS_ALLOW_ORIGIN='http://localhost:5173;http://localhost:8080'
|
|
CORS_ALLOW_ORIGIN='*'
|
|
|
|
# Set to false to keep memory tools enabled without adding memory context to the system context.
|
|
ENABLE_MEMORY_SYSTEM_CONTEXT=true
|
|
|
|
# Set to true to add compact row/column stats to parsed CSV retrieval context.
|
|
ENABLE_RAG_CSV_SUMMARY=false
|
|
|
|
# Set to true to preserve backing file records, storage blobs, and per-file vectors when files are removed from knowledge bases.
|
|
ENABLE_KNOWLEDGE_FILE_RETENTION=false
|
|
|
|
# Comma-separated chunk metadata keys to expose to the model alongside retrieved content.
|
|
RAG_SOURCE_METADATA_KEYS=''
|
|
|
|
# Set to false to disable workspace Tools and Functions.
|
|
ENABLE_PLUGINS=true
|
|
|
|
# For production you should set this to match the proxy configuration (127.0.0.1)
|
|
FORWARDED_ALLOW_IPS='*'
|
|
|
|
# DO NOT TRACK
|
|
SCARF_NO_ANALYTICS=true
|
|
DO_NOT_TRACK=true
|
|
ANONYMIZED_TELEMETRY=false
|
|
|
|
# Valkey Vector Store (requires VECTOR_DB=valkey)
|
|
# VALKEY_URL='valkey://localhost:6379'
|
|
# VALKEY_COLLECTION_PREFIX='open_webui'
|
|
# VALKEY_INDEX_TYPE='HNSW'
|
|
# VALKEY_DISTANCE_METRIC='COSINE'
|
|
# VALKEY_HNSW_M='16'
|
|
# VALKEY_HNSW_EF_CONSTRUCTION='200'
|
|
# VALKEY_HNSW_EF_RUNTIME='10'
|