Files
open-webui/backend/open_webui/utils/json_codec.py
Classic298 1d6735ff0b fix: escape line separators in orjson output (#27819)
orjson emits U+2028, U+2029 and U+0085 raw, where stdlib `json.dumps` escapes them under its default `ensure_ascii=True`. Python treats all three as line boundaries, so with `ENABLE_ORJSON` set, one of them inside model output splits a `data: {...}` SSE frame in half. Both halves then fail to parse and the delta is dropped with no error.

`utils/middleware.py` reassembles frames with `splitlines()`, so an affected response silently loses content on the direct API path. External clients are exposed as well: httpx's `LineDecoder` reimplements the same line-boundary semantics, so any SDK reading the OpenAI-compatible stream through `aiter_lines` breaks on a raw separator.

The three characters are escaped on the way out of `ORJSONCodec.dumps`. That restores parity with stdlib and fixes every reader at once, rather than patching one consumer and leaving external clients broken. They are the complete set: of the ten code points `splitlines()` treats as boundaries, the other seven are below U+0020, where JSON already forces an escape.

The membership guard is load bearing. Calling `translate` unconditionally costs roughly 1.5 us on a typical SSE chunk against 0.115 us for the serialization it wraps, so it would spend more than orjson saves. The three scans cost about 0.04 us.

Payloads containing none of the three are returned unchanged, byte for byte. With `ENABLE_ORJSON` unset, which is the default, none of this code runs.

U+2028 and U+2029 are common in text extracted from PDFs and word processor documents, so the realistic trigger is a model quoting an uploaded file back to the user.
2026-07-31 17:25:30 -04:00

59 lines
2.2 KiB
Python

"""The app-wide JSON codec, selected by the ``ENABLE_ORJSON`` env var.
Every module that would otherwise reach for stdlib ``json`` imports ``JSONCodec``
from here, so the whole app switches implementation from a single flag. With the
flag off these are stdlib ``json`` and engineio's codec verbatim, so the default
behaviour is exactly what it was before orjson entered the picture.
"""
from __future__ import annotations
import json as stdlib_json
from engineio import json as engineio_json
from open_webui.env import ENABLE_ORJSON
if ENABLE_ORJSON:
import orjson
# stdlib escapes these, orjson emits them raw, and Python treats all three as
# line boundaries: one raw separator splits an SSE frame that a reader
# reassembles with ``splitlines()``.
LINE_SEPARATOR_ESCAPES = str.maketrans({'\u2028': '\\u2028', '\u2029': '\\u2029', '\x85': '\\u0085'})
class ORJSONCodec:
"""stdlib-``json``-compatible codec backed by orjson.
Anything orjson rejects (non-str dict keys, ints beyond 64 bits, ``NaN``
literals) falls back to engineio's stdlib-based codec, which keeps its
oversized-integer guard for untrusted client payloads.
"""
JSONDecodeError = engineio_json.JSONDecodeError
@staticmethod
def dumps(obj, *args, **kwargs):
try:
serialized = orjson.dumps(obj).decode('utf-8')
except (TypeError, ValueError):
return engineio_json.dumps(obj, *args, **kwargs)
if '\u2028' in serialized or '\u2029' in serialized or '\x85' in serialized:
return serialized.translate(LINE_SEPARATOR_ESCAPES)
return serialized
@staticmethod
def loads(s, *args, **kwargs):
try:
return orjson.loads(s)
except (TypeError, ValueError):
return engineio_json.loads(s, *args, **kwargs)
# Drop-in for stdlib ``json``: ``JSONCodec.dumps`` / ``JSONCodec.loads``.
JSONCodec = ORJSONCodec
# Codec handed to the socket.io/engineio managers, which default to their own.
SOCKETIO_JSON = ORJSONCodec
else:
JSONCodec = stdlib_json
SOCKETIO_JSON = engineio_json