Skip to content

Commit f8c0d2f

Browse files
Classic298claude
andauthored
fix: don't mutate caller's payload when resolving a pipe base model (open-webui#26906)
generate_function_chat_completion rewrote form_data['model'] to the base model id in place. Because that dict is the same object process_chat_response later re-submits for the post-tool-call continuation, the continuation was access-checked against the base model instead of the user-facing preset. For a public preset over a private/unregistered pipe base, a non-admin's first message succeeded but the continuation after a native tool call was denied and silently swallowed, aborting the response (admins skip the user-only check, so they were unaffected). Operate on a shallow copy of form_data, mirroring the openai/ollama routers which already substitute the base model on a copy. The continuation now re-checks the preset the user actually has access to. Claude-Session: https://claude.ai/code/session_018toPfJW1hMXAhokGaL43Ep Co-authored-by: Claude <noreply@anthropic.com>
1 parent 274729a commit f8c0d2f

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

backend/open_webui/functions.py

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -206,6 +206,10 @@ async def get_function_params(function_module, form_data, user, extra_params=Non
206206

207207
return params
208208

209+
# Copy so the base-model substitution below doesn't leak into the caller's
210+
# payload, which the tool-call continuation re-submits. Mirrors the routers.
211+
form_data = {**form_data}
212+
209213
model_id = form_data.get('model')
210214
model_info = await Models.get_model_by_id(model_id)
211215

0 commit comments

Comments
 (0)