open-webui v0.11.0 版本更新介绍
发布日期: 2026-07-27
版本号: v0.11.0
此次Open WebUI更新带来了全面的功能增强与问题修复,主要涵盖以下方面:界面进行了彻底重新设计,提供更整洁、一致的视觉体验;新增子代理、文件夹页面、聊天计时器、通知目标、完整频道回复等核心功能,并改进了共享、变量、LDAP集成和未读管理;性能方面,通过流式传输、缓存优化、查询精简等多处改进,显著提升了响应速度与资源效率;安全性得到强化,修复了包括文件预览隔离、权限验证、会话管理等多处漏洞;同时调整了管理设置位置、自动化管理方式等部分行为,并强调升级前需备份数据库。整体上,本次更新在用户体验、功能深度、运行效能和安全防护上均有大幅提升。
更新内容 (中文)
新增内容
- 🎨 重新设计的界面。 Open WebUI 的用户界面已从头开始视觉重建。涵盖了从聊天视图到管理面板的所有方面。现在采用了更窄的对话列、更轻的字体排版、更整洁的间距、一致的菜单和下拉框、清晰轮廓的文本框,以及重新排列的设置。提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、提交、#27178、提交、提交
- 🤖 子代理。 管理员现在可以启用子代理,它允许模型将任务的某些部分交给后台辅助代理执行。这些代理运行自己基于工具的对话,并将结果报告回主聊天中,可通过新的 “ENABLE_SUBAGENTS”、并发、迭代和系统提示设置进行调优。提交、提交、提交、提交
- 📂 文件夹页面。 现在打开一个文件夹会带你进入其自己的页面,其中的聊天分页加载,可以按标题或最后更新时间排序,并且你可以直接从文件夹开始新的聊天。提交
- ⏲️ 聊天计时器。 助手现在可以设置一个计时器,在延迟后或在设定时间将提示重新带回对话中,如果你在触发前阅读了聊天或进行回复,它还可以自动取消该提示。提交
- 🔔 通知目标。 通知现在有自己的设置选项卡,你可以将其发送到多个 webhook 目的地,每个目的地选择它想要的事件(从聊天完成或失败到频道消息和日历提醒),带有一个测试按钮以及在“始终通知”或“仅当您离开时”之间的选择,并且您已有的任何 webhook 会自动迁移。提交、提交、提交、#24750
- 🗯️ 频道中的完整回复。 助手在频道中的回复现在会完整保存和显示,包括其推理、工具调用和其他结构化部分,而之前这些内容可能是空白的。提交、#26720、#27409、#26707、#26656
- 📣 来自助手的通知。 当有值得关注的事情时,助手现在可以自己向您发送通知,因此即使您已转向其他事务,长时间运行的任务也能在完成后通知您。提交、提交
- 🌎 与任何持有链接的人共享聊天。 共享聊天现在可以设置为“开放”状态,这样无需登录即可打开,访问者在进入时不再被重定向到登录页面(管理员必须首先通过新的“Chats Open Sharing”权限允许此操作,默认情况下该权限处于关闭状态),并且此类页面会要求搜索引擎不要对其建立索引。提交、提交
- 🔖 聊天变量。 模型的系统提示现在可以声明字段,例如文本框和下拉列表,您可以在对话中填写,这些值会与聊天一起保存,并在聊天被分叉或克隆时保留。提交、提交、提交、提交、提交、提交、#26915
- 🗄️ LDAP 组同步。 管理员现在可以从身份验证设置将 LDAP 组映射到 Open WebUI 组,并可以选择自动创建缺失的组,因此用户每次登录时其组成员资格都会与目录保持同步。#27263、#18015
- 👥 通过组限制共享。 管理员现在可以通过新的 “USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_GROUPS” 权限阻止资源与整个组共享,该权限默认启用,因此现有的组共享功能保持不变。提交、提交、提交、提交、#27124
- 🤝 共享文件夹协作。 有权访问共享文件夹的人员现在可以在聊天中使用其文件和系统提示作为知识,并且在有写入权限的情况下,可以重命名和管理文件夹,所有操作均根据其读取或写入权限进行。提交、提交、提交、提交
- 👁️ 侧边栏中的聊天预览。 将鼠标悬停在侧边栏中的聊天上现在会显示其最近消息的紧凑预览,因此您无需打开它即可找到想要的对话。提交、提交、提交、提交
- 🕗 本地消息时间戳。 消息时间戳现在在悬停时以设备本地日期和时间格式显示,并在工具提示中显示完整的星期和日期。提交、提交
- 📇 用户变量。 您现在可以在帐户设置中存储自己的值,例如您的角色或您喜欢的回答方式,模型的系统提示可以在需要的地方插入它们。提交、提交、提交
- 🧺 自动将聊天归档的自动化。 自动化现在可以指向您的某个文件夹(通过对话框、编辑器或要求助手进行设置),这样每次运行都会存放在那里,而不是散落在您的聊天列表中,并且如果文件夹稍后被删除,其中的内容也会自动清除。提交、提交、提交
- 🔵 查看您尚未阅读的内容。 侧边栏中的文件夹现在带有其包含新内容的聊天数量计数,文件夹自己的页面用点标记未读聊天,对仍在生成的聊天显示加载指示器,当您打开一个聊天时清除该点,并且当其他地方的回复完成时自动更新自身状态;未读聊天在文件夹中置顶排序,您可以将单个聊天标记为未读、将文件夹中的所有聊天标记为已读,或者从侧边栏一次性标记所有聊天为已读。提交、提交、提交、提交、提交、提交、提交、提交、提交
- 🗜️ 按需压缩聊天。 在长对话中输入压缩命令现在会立即总结早期的轮次,而不是等待对话超过阈值后再自动进行。提交、提交
- 🌿 分叉聊天。 每个回复现在都有一个分叉按钮,它会将到该点为止的对话复制到一个新的聊天中,并记住分叉的位置,这样您就可以继续沿着不同的路径前进,而无需修改原始对话。提交、提交、提交、提交
- 📌 固定对话映射。 聊天概览现在有一个固定控件,可以防止其在收到新消息时重新居中,这样当回复到来时,您可以继续查看正在阅读的分支。#25736
- 📊 一目了然的聊天状态。 斜杠菜单现在显示上下文窗口的填充程度,新的状态命令打开一个面板,显示上下文使用情况、排队消息、正在运行的任务和聊天 ID。提交、提交
- 🎹 可自定义的键盘快捷键。 大多数键盘快捷键现在可以在设置中重新绑定到您选择的键组合,这些组合会保存到您的帐户中,当两个操作共享一个组合时会发出警告,并提供重置为默认值的选项,同时还可以绑定到上一个/下一个聊天以及打开控制面板。提交、提交、#26624
- ⌨️ 关闭键盘快捷键。 键盘设置中的一个新开关可以禁用所有可配置的快捷键并隐藏其提示,这样与您的浏览器或操作系统冲突的组合就会直接生效。#27300、#1008
- ⌨️ 斜杠命令中的技能。 在消息输入中键入斜杠现在会在提示旁列出您的技能,按标题分组,并在悬停时显示描述,因此您无需离开键盘即可附加技能。提交
- 📎 使用 @ 菜单附加任何内容。 在消息输入中键入 @ 符号现在会搜索您的文件夹、知识集、单个文件以及您的模型,并且粘贴链接时会提供将其作为网页或 YouTube 附件的选项。提交
- 📝 使用笔记进行聊天。 与笔记进行聊天现在为您提供完整的聊天体验,包括模型选择、工具和文件附件,以及建议的提示、将响应直接插入笔记的按钮、助手进行的编辑会实时出现在笔记中,以及您可以为每个笔记保留任意数量的独立对话。提交、提交
- ↕️ 对列表进行排序。 笔记、提示、模型、知识、技能、工具和函数列表现在可以通过单击列标题按标题或最后更新时间以升序或降序排序。提交、提交、#27457、#27456
- 🗒️ 无存储内容的笔记。 内容从未被填写的笔记现在可以正常打开和保存,而不是失败。提交
- 📄 笔记附件。 笔记现在在其菜单中有一个上传选项,并在笔记本身上方显示附件文件,您可以在那里打开或删除它们,而不是仅接受拖放到页面上的文件。提交、提交
- 🗂️ 助手可以搜索您的附件。 一个新的文件能力允许模型列出附加到聊天的文件,并按含义或确切文本进行搜索,然后读取其需要的部分,而不是将它们的全部内容预先推送到对话中;附加到聊天的知识集或笔记现在会向模型通告,以便它可以以相同的方式查询这些内容。提交、提交、#26711、#27232、#26708
- 🔎 在附件菜单中搜索。 附件菜单现在允许您搜索您的知识库、笔记、文件和聊天,而无需滚动查找它们,并为聊天显示匹配文本。提交
- ⚗️ 默认文件上传模式。 您现在可以在设置中选择默认情况下如何处理附件文件,而不是在每次上传时进行选择。#20900、#18431
- ⬇️ 响应自动滚动开关。 一个新的界面设置允许您在生成回复时停止视图跟随,这样您就可以在生成继续时阅读更早的文本。提交、#26826
- 📜 SearXNG 的客户端证书。 网络搜索现在可以向需要客户端证书的 SearXNG 实例出示客户端证书,通过新的 “SEARXNG_CLIENT_CERT_FILE” 和 “SEARXNG_CLIENT_KEY_FILE” 设置。提交、#26992
- 🔭 OpenSERP 网络搜索。 网络搜索现在可以针对自托管的 OpenSERP 实例运行,该实例无需任何 API 密钥即可从多个主要搜索引擎返回结果,通过新的 “OPENSERP_BASE_URL” 设置进行配置。#27437、#27438
- 🥇 模型顺序作为设置。 管理员现在可以通过新的 “MODEL_ORDER_LIST” 变量设置模型出现的顺序,这样即使在不持久化配置的实例上,排序也能在重启后保持不变。#27420、#27206
- ⏱️ 流式回复的空闲上限。 管理员现在可以设置 “AIOHTTP_CLIENT_STREAM_IDLE_TIMEOUT”,当提供程序在指定时间内停止发送任何内容时结束流式回复,而不是将连接一直保持到总超时过期。提交、提交
- 🖼️ 提取引擎可能处理的媒体类型。 管理员现在可以列出配置的内容提取引擎允许处理哪些图像和视频类型,而不是仅当引擎是外部引擎时才将媒体传递给它,这样具有自己文本识别能力的引擎就可以处理图像。提交、#26940、#14768
- 🧵 频道回复的落脚点。 管理员现在可以选择对提及的回复是发布在该消息下的线程中还是直接发布到频道中。提交、#27410
- 📚 知识工具的限制。 管理员现在可以设置知识搜索或文件视图可能返回多少内容、一次搜索可以扫描多少文件、报告多少个匹配项,并且知识命令的整个输出现在受到限制,因此单次调用不会淹没对话。提交、#27524、#27327、#26139
- 🎛️ 文件流分块大小。 管理员现在可以通过新的 “AIOHTTP_FILE_STREAM_CHUNK_SIZE” 设置调整流式文件传输中每个块的大小。提交
- 🪛 用于总结长聊天的模型。 管理员现在可以选择一个专用模型来编写上下文压缩摘要,与任务模型分开,当未选择模型时,则使用对话自己的模型。#26806、#27051
- 📏 上下文压缩令牌上限。 管理员现在可以设置“令牌上限”,以限制每个模型上下文压缩阈值允许达到的高度,从而更精细地控制长对话的摘要。提交、提交、提交
- ⚖️ 压缩后保留的消息。 管理员现在可以设置当长对话被摘要时保留最近消息的比例,范围在十分之一到一半之间。提交、#27050
- 🧠 记忆作为每个模型的功能。 模型是否接收您存储的记忆现在是模型本身上的一个开关,因此可以为日常助手保持开启,而为应该从头开始的助手保持关闭。提交、#26861、#18610
- ☑️ 可搜索的模型选择器。 编辑模型时,工具、技能、知识、语音、过滤器和操作选择器现在允许您就地搜索和切换项目,一次选择或清除所有项目,并一目了然地查看哪些是活动的。提交、提交、提交、提交、提交、提交、#26758
- 🎚️ 单点登录开关。 OAuth 和 OIDC 现在在身份验证设置中有自己独立的开关,与上方的 LDAP 开关匹配,这样可以在不清除配置的情况下关闭通过提供商进行的登录。#26988
- 🖲️ 一次只能进行一次登录尝试。 登录、注册和 LDAP 表单现在会在请求进行时禁用其按钮,因此缓慢的响应不再会导致重复的点击或按回车键变成多个并发尝试。#27416、#27264
- 🛂 用于令牌交换的受信任客户端。 管理员现在可以通过新的 “OAUTH_TOKEN_EXCHANGE_TRUSTED_CLIENT_IDS” 设置列出哪些 OAuth 客户端可以将其令牌交换为会话,这样某人通过登录同一提供商的不相关应用程序获得的令牌就无法再被转换为该人的会话。#27546、提交、提交
- 🚪 令牌交换的限流。 管理员现在可以通过新的 “OAUTH_TOKEN_EXCHANGE_RATE_LIMIT” 和 “OAUTH_TOKEN_EXCHANGE_RATE_LIMIT_WINDOW” 设置限制 OAuth 令牌交换端点被来自一个地址的调用频率,该设置在设置前处于关闭状态,并对使用泄露或猜测的令牌的自动尝试进行限制。提交
- 🔏 适用于所有登录提供商的 PKCE。 代码质询设置现在也适用于 Google、Microsoft 和 GitHub 登录以及 OpenID Connect,因此相同的保护措施覆盖所有提供商。提交、#27302
- 🔤 通过 OpenAI 兼容 API 进行嵌入。 基于 OpenAI 客户端库构建的集成现在可以通过 Ollama 代理创建嵌入,因此嵌入请求会经过与聊天相同的登录和模型访问规则,而无需直接访问 Ollama。#27332、提交、#27328、文档:#1331
- 🎚️ 每个连接的传递参数。 管理员现在可以在连接设置的新“高级”部分下列出应未翻译地传递给连接的请求参数,以便提供商特定的选项能够完整地到达上游 API。提交
- 🅰️ 直接传递的 Anthropic 请求。 现在,针对 Anthropic 或 LiteLLM 连接的 Anthropic 兼容 API 请求会原封不动地到达提供商,而不是在传输过程中被翻译,并且 LiteLLM 可以选择作为连接类型。提交
- 💭 Anthropic 响应中的推理。 来自 Anthropic 兼容 API 的响应现在携带模型的推理作为思考块,在流式和完整响应中均如此。提交
- 🧩 通过 Anthropic 兼容 API 进行结构化输出。 请求现在可以要求 JSON 模式或 JSON 对象响应并设置推理努力程度,这些都会传递给上游模型。提交
- 🪧 转发标头中的组名。 连接上的自定义标头现在可以携带人员所属的组(按名称或 ID),这样上游服务或网关可以按组应用其自己的规则。#27236、#26834
- 🪪 转发到 Mistral OCR 的用户身份。 通过 Mistral OCR 进行的文档提取现在在启用用户信息转发时会携带请求用户的身份,这样其前面的网关就可以像其他出站集成一样按用户归属请求。#27253、#27250
- 🔢 Anthropic 令牌计数端点。 Anthropic 兼容 API 现在提供令牌计数端点,因此集成可以在发送请求之前检查请求将使用多少输入令牌。提交、提交
- 🖲️ 每次读取终端指令。 终端服务器提供的指令现在在每次请求时获取,因此在服务器上更改它们会立即生效,而不是在重新保存连接或重新启动后才生效。#27242
- 🖥️ 实时终端服务器策略。 管理员现在可以直接在连接设置中读取协调器终端服务器的当前策略和生命周期设置,而不是依赖本地缓存的副本。提交、提交
- 🌍 一目了然的模型隐私。 管理员现在可以从模型列表中直接将模型公开或设为私有,其中每个模型都标记为公开、共享或私有。提交
- 📈 个人使用情况仪表板。 设置中的一个新的“使用情况”选项卡显示您随时间推移的活动,包括令牌活动热图、当前和最长连续使用天数、生命周期和峰值令牌数、您最长的活跃聊天以及您最常用的模型和工具。提交
- 🧠 设置中的记忆。 您的记忆现在直接列在个性化设置中,您可以在那里搜索、添加、编辑和删除它们,而不是隐藏在单独的管理对话框后面。提交
- 💾 导入笔记和自动化。 笔记现在可以从文本和 markdown 文件中导入,自动化可以作为文件导出和导入,因此您可以在实例之间移动它们。提交、提交
- 🧮 标签页中的计数。 工作区标签页现在显示您拥有的模型、知识库、提示、技能和工具的数量,管理标签页对用户、组、排行榜条目和反馈执行相同操作,因此您无需打开每个部分即可查看其大小。提交、提交、提交
- 🧾 一目了然的组权限。 组列表现在显示每个组是使用自定义权限还是默认权限,而无需打开它。提交、提交
- 📤 流式文件传输。 上传模型、管道或音频文件现在以分块方式发送,而不是将整个文件保存在内存中,并且读写文件不再阻塞其他请求,因此大文件传输不再会导致内存峰值或服务器停滞。提交、#27351、#27349
- 🧰 内置工具描述只构建一次。 提供给模型的内置工具描述现在在启动时计算一次,而不是在每条消息上重新构建。提交、提交、#27374、#27396
- 🪺 记录无需两次读取。 加载模型、工具、提示、技能、笔记、知识库、频道或日历不再在导出记录时进行两次转换。提交、#27377
- 🔧 更快的工具和知识库列表。 列出工具不再加载每个工具的完整源代码,并且确定您可以查看哪些工具和知识库只需进行一次检查,而不是每个项目都检查一次。#27387
- 🧊 Chroma 上更快的集合检查。 检查集合是否存在现在只请求该集合,而不是列出所有集合,因为随着每个知识库和文件的增加,列出所有集合会越来越慢。提交、#27394
- 🔠 分词器只加载一次。 用于拆分文档的分词器现在在首次使用后保留,而不是在每个文件上重新加载。提交、#27394
- 📗 更快的知识库文件列表。 打开知识库现在只加载文件名和详细信息,而不是每个文档的全部提取文本,因此大型集合几乎可以立即显示。#27386、#26144
- 🗝️ 更快的文件访问检查。 确定您是否可以打开文件不再随工作区模型和知识库的数量而扩展,因此在大型实例上打开文件和列出文件夹内容保持快速。#27383
- 🕰️ 更快的自动化调度。 确定每隔几分钟或几小时重复一次的自动化下一次何时运行现在几乎是即时的,而不是需要二十秒或更长时间,并且每年都会变慢。提交、#26954
- 📁 更快的文件夹加载。 您的文件夹列表不再为每个文件夹运行单独的查找来检查其位置,因此它只需一次加载即可。提交
- 🎯 每次单击文件夹只进行一轮请求。 在侧边栏中选择文件夹现在会一次性获取文件夹、文件夹树和每个展开文件夹的聊天,而不是两到四次。#27540、#27539
- 🎧 无人倾听时不浪费工作。 已关闭选项卡的聊天更新,或通过 API 发出的请求的更新,不再被打包然后丢弃,这在长时间的流式回复中尤为重要。#27366、提交
- 📑 更低成本的审计日志记录。 开启审计日志记录后,每个请求不再进行第二次身份验证仅为记录日志条目,因此经过审计的实例开销显著降低。#27373
- 🪧 每次回复后更低成本的标记。 保存为对话生成的标记现在仅更新该字段,而不是加载、重写和重新读取整个对话,这在聊天越长时成本越高。#27382
- ✍️ 应用内更快的保存。 保存聊天、笔记、提示、工具或用户设置不再重新读取它刚刚写入的记录,因此写操作完成得更快,在长对话中最为明显。#27381、#27379、提交、提交
- 🛢️ 每个请求更少的数据库开销。 SQLite 安装不再在每次数据库调用前运行连接检查,并且从未接触数据库的请求会跳过以前无论如何都会运行的记账工作。#27385
- ⚡ 更快的内存查找。 存储的记忆现在被索引,因此随着您拥有的记忆数量增加,检索它们仍保持快速。提交、#26957
- 🪪 回复开始前更少的检查。 确定您是否可以使用模型现在只需查找一次模型和您的组成员资格,而不是重复两次,包括对于工作区模型所基于的每个模型。#27378
- 👤 更轻量的用户活动检查。 检查某人当前是否活动现在仅读取该时间戳,而不是其整个配置文件,包括其头像。提交、#27224
- 📨 发送消息时更少的设置查找。 发送聊天消息现在只需更少的数据库往返次数即可读取工具、文件检索、语音、技能和代码解释器背后的设置,因此回复开始得更快。#27223
- 🪄 Ollama 请求更轻量的转换。 准备发送给 Ollama 模型的请求现在不再复制整个对话,这在消息增多时成本更高,并在每个工具调用轮次中重复。#27371
- 🦙 Ollama 请求更少的设置查找。 Ollama 聊天、生成和嵌入请求现在只需读取一次其连接设置,而不是最多四次,因此每个请求更快地到达服务器。#27226
- 🧹 每次响应更少的重复工作。 安全标头现在在启动时计算一次,而不是为每个响应重新构建,并且普通的页面请求会跳过它们不需要的重定向处理,因此响应携带更少的开销。#27229
- 🚀 更低的每个请求开销。 请求在处理前不再执行设置查找,从而减少了应用执行的每一项操作的延迟。提交、#27395、提交、提交、#27227
- 💨 流式处理期间更轻量的过滤器处理。 应用于流式回复的过滤器不再为每个块从数据库重新读取其设置和每个插件的完整源代码,因此启用过滤器的响应对服务器的工作量大大减少。#27228、#27372、提交、提交、提交、#27392
- 🚦 无过滤器时无过滤器记账。 流式 API 响应仅在模型实际配置了出口过滤器时才构建完整回复,而不是对每个请求都这样做。提交、#27391
- ✂️ 流式处理期间更低成本的标记检测。 监控回复中的推理和代码块现在只检查新到达的文本,而不是在每个块上重新扫描整个答案,因此随着答案变长,其成本不会成比例增加。#27360
- 🌊 更稳定的长响应。 构建流式回复的成本不再随其增长而增加,因此长答案可以保持速度,而不是在结束时变慢。#27231、#27359、提交、#27390
- 📦 更快的 JSON 处理作为选项。 管理员现在可以通过新的 “ENABLE_ORJSON” 设置将整个应用程序切换到更快的编码器,涵盖请求主体、响应、上游提供商有效负载和实时更新,其中实时更新的编码是处理它们的工作程序在集群部署中的最大单一成本;它默认关闭,因为更快的编码器对其接受的内容更严格。#27583
- ⚙️ 更快的 Redis 处理。 编译后的 “hiredis” 解析器现在作为依赖项提供并自动使用,因此使用 Redis 支持的部署在读取响应时花费的处理器时间显著减少。#27282
- 🔗 每次聊天更少的 Redis 往返。 使用 Redis 支持的部署现在每个请求只需查找一次模型和连接的会话,而不是两次,并且只需一次调用即可获取模型列表。#27225
- 🛰️ 更少的 Sentinel 查找。 Redis Sentinel 部署不再在每个命令前询问哪个服务器是主服务器并打开新连接,这曾导致在高负载下出现大量连接流失和停滞。提交、#27213、#27210
- 📡 更轻量的实时连接处理。 输入指示器、共享文档编辑和重连现在不再每次重新读取您的帐户或复制完整的参与者列表,并且空闲会话不再每几秒重写一次。提交、#27393
- 🏎️ PostgreSQL 上更快的聊天搜索。 在 PostgreSQL 上搜索聊天现在从消息表中读取,而不是逐行解包每个对话的存储数据行,因此随着您的历史记录增长,结果仍保持快速。提交、#27221
- ⚡ 更轻量的模型列表。 模型列表不再在其数据中携带嵌入式头像,因此加载更快。提交、提交
- 🏗️ 构建模型列表时更少的查询。 组装模型列表现在进行更少的数据库往返,并且不再获取每个插件的源代码,因此组合得更快。提交、#27389
- 🪶 模型列表不包含知识文本。 模型列表不再包含附加到模型作为知识的文件的提取文本,因此无论这些知识库有多大,它们都保持很小。提交、#27287
- 🔛 函数可以对切换开启或关闭做出反应。 两个新事件在函数启用或禁用之前触发,并且被启用的函数会收到其自己的事件(即使它尚未激活),以便它可以运行所需的任何设置或清理工作。提交、#26754、#26748
- 🔛 插件中的多选设置。 工具或函数现在可以提供一个设置,您可以在显示时从列表中勾选多个选项(固定或在显示时确定),而不是要求您键入以逗号分隔的允许值列表。#26884、#26848
- 🔌 完全禁用插件。 管理员现在可以通过新的 “ENABLE_PLUGINS” 设置完全关闭内置的工具和函数插件界面,该设置在工作区和管理区域中隐藏它们并移除其执行路径。提交、提交、提交、提交
- 🧵 更轻量的聊天列表和搜索。 构建聊天搜索结果页面或文件夹列表不再复制每个完整对话来读取其标题和日期,因此这些页面组合得更快,并且在构建时使用更少的内存。#27388
- 📮 名称查找脱离线程池。 查找主机名不再占用与其他所有阻塞工作共享的有限线程之一,因此模型调用、搜索、页面获取和工具调用一旦遇到几次查找缓慢就不再相互排队等待。#27440
- 🥬 更快的网页解析。 网络搜索和网络检索获取的页面现在使用更快的解析器读取,将大约十分之一的时间用于十次结果的搜索。#27439
- 🧭 过滤搜索结果时不再进行无意义的查找。 根据域列表过滤网络搜索结果现在不再先将每个结果解析为地址,这曾将三秒钟的搜索变成半分钟(无论解析器多慢或名称无法解析)。提交、#26920
- 🚄 更轻量的直通流。 服务器仅中继的响应现在通过整个网络读取直接传递,而不是逐行分割,这大致上使在这些路由上中转流式回复的工作减半。#27384
- 🧶 网页解析脱离关键路径。 读取这些页面不再阻碍服务器上的其他一切,因此其他人的回复、实时更新和健康检查在搜索期间可以继续流动,而不是停滞一秒钟或更长时间。#27446
- 🈶 更快的非英文文本文件上传。 确定上传文本文件的编码现在采样需要它的部分,而不是扫描整个文件,将四兆字节的日文或中文文档从几秒钟降低到远低于一秒。#27445
- ♿ 改进的 UI 无障碍性。 键盘和屏幕阅读器用户现在可以辨别侧边栏中的哪个聊天是正在查看的,打开回复中的推理和详细信息块,无需鼠标即可展开侧边栏部分并打开文件夹,使用键盘对管理用户列表进行排序并听到按哪列排序,使用键盘打开下拉菜单及其子菜单,再次按 Escape 关闭它们并回到起始位置,听到下拉菜单设置的值(而不仅仅是其标签),听到每个管理设置开关、组权限切换、复选框、API 密钥字段和高级模型参数滑块控件的功能,让消息框以其占位符(而非未命名字段)被宣布,按确认对话框中的取消按钮时按回车不会触发删除,可以访问重新生成控件,使用跳过链接直接跳过侧边栏到对话,了解聊天、通话、文件预览、模态框和管理页面中的纯图标按钮的功能(而不是未标记的按钮),占位符文本、部分标题、字段描述、非活动标签、时间戳、计数器和图标在高对比度模式开启时可读,侧边栏按钮跨笔记、自动化、操场和管理页面宣布其是打开还是关闭侧边栏。#27510、#27513、#27503、#27494、#27491、#27490、#27489、#27488、#27555、#27556、#27554、#27558、#27501、#27492、#27509、#27502、#26769、提交、提交、#26768、#26770、提交、提交、提交、#27508
- 🔄 常规改进。 在整个应用程序中实施了多项改进,以增强性能、稳定性和安全性。
- 🌐 翻译更新。 现在提供斯洛文尼亚语,英语(英国)、芬兰语、德语、日语、葡萄牙语(巴西)和葡萄牙语(葡萄牙)的翻译得到了增强和扩展。
修复内容
- 🛡️ 安全公告: 此版本包含安全和访问控制修复。我们建议在方便时尽快更新生产部署。并非此版本中的所有安全修复都可能在修复部分中列出。有些可能会暂时扣留,以便管理员有时间升级。公告
- 🔒 终端文件预览隔离。 在系统终端中预览 HTML 文件现在默认在隔离的上下文中运行,关闭了一个可能暴露您的登录会话或(对于特权帐户)在服务器上运行代码的跨站脚本漏洞。#26907
- ➗ 消息中格式错误的数学公式。 无法渲染的数学公式现在显示为纯文本,而不是作为标记放入页面中,关闭了一种在聊天、频道或共享对话中构造公式以在任何阅读者的浏览器中运行代码的方法。#26718
- 🔩 更新文件上传解析库。 解析文件上传和表单提交的库已更新到解决该解析路径安全公告的版本。#26991
- 🛑 停用的帐户失去实时访问权限。 实时连接现在应用与应用程序其余部分相同的角色检查,因此被移出用户或管理员角色的帐户无法再使用现有令牌保持其频道和共享笔记的打开状态。#27537
- 🛅 写入他人的聊天。 完成和操作请求现在在写入任何内容之前确认您拥有其命名的聊天,因此过滤器或操作无法再指向另一个人的对话。#27486
- 🎟️ Ollama 版本无法再匿名读取。 读取配置的 Ollama 后端版本现在需要登录,关闭了一条让任何人了解使用版本并计算配置了多少个后端的路径。#27199
- 🔐 文件夹共享权限。 默认权限和组权限中的文件夹共享设置现在会保存,而不是被静默丢弃,因此允许或限制文件夹共享实际上会生效。#27296、#27120
- 🔕 Webhook 权限强制执行。 无权使用 webhook 的人员现在无法将 webhook 通知目标保存到其设置中,因此权限在保存设置时强制执行,而不仅仅在界面中反映。#27297、提交
- 🛎️ 停止他人的生成。 删除聊天现在会先检查您是谁,然后再取消任何操作,因此知道他人的聊天 ID 不再能让你切断他们的回复或标题生成(即使该请求本身会被拒绝)。#27006
- 🚥 聊天中的自动化限制。 助手代您创建或重新安排的自动化现在遵守与您自己设置的相同的最大数量和最小间隔,而不是可以超出两者。#27523、#27121
- ⏲️ 取消他人的计时器。 将聊天标记为已读现在只会清除您自己在其上的待处理计时器,而不是清除所有人的,这曾让另一个人的计划提示在未通知的情况下被静默取消。#27472
- 🗑️ 删除共享文件夹的子文件夹。 删除文件夹现在在每一级都限于其所有者或管理员,因此对共享文件夹有写入权限的人无法再删除子文件夹并带走所有者的聊天。#27003
- 📕 仅使用工具的人员可以看到工具源代码。 打开您拥有读取权限的工具不再返回其源代码,而读取权限从未打算包含源代码。#27005
- 🎯 列表端点中的模型设置。 列出模型不再为仅有读取权限的人员包含每个模型的参数和系统提示,这与打开单个模型已经返回的内容一致。#27004
- 🖌️ 未经许可的图像生成和网络搜索。 通过较旧的请求格式开启图像生成或网络搜索现在会先检查您的权限,因此被拒绝使用这些功能的人无法再通过请求该格式来触发它们以及随之而来的计费。#26703
- 🎗️ 终端单点登录令牌。 转发到终端服务器用于单点登录的令牌现在取自您自己在服务器上的会话,而不是浏览器提供的标头,因此调用者无法再发送他人的令牌作为替代。#26719
- 🫗 网络搜索结果限定于您。 保存网络搜索页面的临时集合现在绑定到执行搜索的人员,关闭了该限定未应用的唯一位置。#26706
- 🧺 知识库清理影响其他集合。 清理知识库现在仅作用于属于它的文件和文件夹,因此对一个知识库有写入权限的人无法再删除属于另一个知识库的文件夹或搜索数据。#26722
- ⌛ 可能使服务器停滞的搜索。 知识库命令中的搜索模式现在在时间预算下运行,因此需要几分钟评估的模式无法再使实例上的其他所有人停滞。#27471
- 🚫 已禁用的终端服务器被拒绝。 管理员关闭的终端连接现在无法通过浏览其文件、打开会话或调用其工具来访问,而不仅仅从界面消失。提交
- 🧫 附加到共享文件夹的文件。 除非文件夹的所有者可以读取它们,否则无法向文件夹添加文件,并且在聊天中用作知识之前,会检查文件夹的文件是否仍可被其所有者读取,因此协作者无法再将文件放入他人的文件夹或继续提供所有者已失去访问权限的文件。#27464、提交
- 🧷 直接连接声称的知识。 在由浏览器为直接连接提供的模型上列为知识的文件现在在检索任何内容之前会根据您自己的访问权限进行过滤,因此构造的请求无法再拉入您无法打开的文档。提交、#26723
- 🪜 通过共享模型访问受限模型。 共享工作区模型现在无法用于访问该人员原本无法使用的底层模型,这在之前当该模型没有自己的条目时曾经通过。#26905、#26900
- 🖌️ 共享图像检查点更改。 只有管理员现在可以更改实例范围的 Automatic1111 检查点,因此普通的图像生成请求不再为所有人切换图像模型。#27244
- 💬 频道消息所有权。 频道消息的作者或管理员现在可以编辑或删除它,而不是任何可以在该频道中发布消息的人。#27197
- 🗄️ 与管理员共享的聊天。 管理员现在可以打开与他们有意共享的聊天,即使对其他人聊天的广泛管理访问已关闭,而不是被拒绝任何其他收件人可以读取的聊天。#27127
- 📓 文件夹知识中的笔记经过访问检查。 附加到文件夹的笔记现在在列表到达助手之前会根据您自己的访问权限进行过滤,而不是依赖后续的更深入检查。#26739
- 🧱 代码解释器模块阻止。 管理员为代码解释器阻止的模块现在确实被阻止,并且解释器代码中的其他导入再次工作。#27245
- 📉 代码解释器中的图表。 绘制图表的代码现在在默认的代码解释器设置中运行,而不是除非开启文件持久化否则会因语法错误而失败。#26800、#26660
- 🎬 聊天操作的可用性。 聊天操作在被禁用、未分配给正在使用的模型或调用者无法访问的模型时无法再触发,这与界面实际提供的操作匹配。#27243
- 🗨️ 缺失的响应文本。 助手回复现在不再在没有文本的情况下存储,因此复制、导出、搜索和重用对话会返回回复而不是空内容。提交、#26799、#26436
- 🧪 在重新加载后保留的过滤器编辑。 过滤器对已完成的响应所做的更改现在会随对话一起保存,而不是显示在屏幕上并在下次打开聊天时恢复。#27414、#27017
- 📃 操作函数接收响应文本。 在响应上运行操作现在将助手的文本传递给函数,而不是传递一个空消息。#26798、#26672
- 🍎 Safari 上的空白消息。 助手响应在 Safari 以及 iPhone 和 iPad 上不再呈现为空白,在那里浏览器绘制错误导致屏幕上的消息未绘制。#26805、#26712、#26844
- ➡️ 从链接打开的提示。 通过链接传递并自动发送的提示现在会等待工具服务器完成加载,因此外部工具在该第一条消息上可用,而不是模型报告它没有任何工具。提交、#24176
- 🪟 工具结果提示提交。 将提示发回聊天的交互式工具结果嵌入再次工作,现在在提交前显示确认对话框,而不是静默地什么都不做。#26914、#26912
- 📻 第二个选项卡中的实时更新。 在已连接的情况下再次打开 Open WebUI 现在会将新选项卡加入到您的事件流中,因此通知和聊天更新会到达每个打开的选项卡,而不仅仅是第一个。提交
- 🔁 新聊天上的连接恢复。 从主页开始的聊天现在可以在连接丢失后自动恢复,例如来自移动后台处理、VPN 或 IP 变更或从睡眠中唤醒,而不是在手动刷新之前卡在加载状态。#26913、#26844
- 🪫 加载时清除终端选择。 您选择的终端现在不会在终端列表仍在加载时被删除,因此它可以在页面刷新后保留。提交、提交、提交、#26775、#26677
- 🔌 保持活动期间断开的会话。 实时连接现在不会在例行的保持活动检查中断开,这曾切断会话,导致服务器需要在您浏览器中运行的任何内容之后失败,最明显的是代码执行工具每次运行时都报告客户端已断开连接。#27553、#27550
- ✂️ 上下文压缩的轮次边界。 长对话压缩现在仅总结已完成的早期轮次,而不是有时切断单个轮次的中间,从而保持当前轮次的工具调用和结果完整。#27035、提交、提交
- 🪆 直接连接上的摘要。 在直接连接上摘要长对话现在可以使用配置的摘要模型,而不是仅限于连接自身的模型。#26806
- 🪟 通过压缩的系统提示。 当长对话被摘要时,系统消息现在保持在对话的开头,而不是被折叠到摘要中并从此丢失。提交、提交、提交、#26713、#26710
- 🧷 上下文压缩的连续性。 压缩后,保留的最近消息现在会保留在每一轮后续的提示中,而不是在第一轮后消失,从而保留对话连续性和提示缓存。#27037、提交、提交
- 🔟 工具调用后的上下文大小。 上下文度量和长对话压缩现在读取最新请求的大小,而不是累加工具循环中的每个调用,并且理解 Ollama 和 llama.cpp 报告的计数以及 OpenAI 样式的计数,因此压缩不再在其阈值以下很远触发,或者根本不触发,并且显示的使用量不再虚高。提交、提交、#27031、#26752、#24410
- 💭 迟到或为空的推理。 提供商在答案开始后发送的推理现在显示在其答案上方的正确位置,而不是追加到答案后面,并且不包含内容的推理注释不再打开一个空的思考块。提交、#26687、#26645
- 📐 工具调用期间丢失的系统提示。 模型的系统提示现在在每一轮工具调用中都保持不变,而不是在第一轮后被丢弃,并且在启用记忆的情况下仅被记忆块替换。#26857、#26836
- 🪶 来自结构化回复的记忆。 以结构化输出形式提供的响应现在在轮次结束后审查记忆时读取,因此不会仅仅因为答案的到达方式而跳过值得记忆的内容。提交、#26705、#26651
- 🎲 稳定的技能排序。 模型可用的技能现在在每个请求上以相同的顺序列出,而不是在请求之间打乱,从而悄然击败了提示缓存。提交、#26986
- 🛑 在答案开始时立即停止。 聊天中的每个答案现在从第一个事件开始就携带其自己的任务标识符,因此在发送后立即停止一个答案不再失败。提交
- ⏸️ 在回复生成时删除。 删除控件现在在响应生成期间或任务运行时在消息上隐藏,因此对话不再可能留下与之前消息分离的已完成回复。提交、#26668
- 🎁 下载准备期间的反馈。 从终端下载文件或文件夹现在会告诉您正在准备,如果您再次点击,不会开始同一存档两次,并且报告失败而不是静默放弃或留下预览旋转。#27421、#27055
- 📥 将已归档的聊天移入文件夹。 将已归档的聊天移入文件夹现在会将其从归档中取出,因此它会出现在那里,并且从菜单移动后文件夹的内容会立即刷新。#27485、#27484
- 📜 文件夹中超过前六十个的聊天。 文件夹列表现在会分页浏览所有聊天,而不是在固定限制处停止,因此一旦文件夹增长超过六十个,较旧的聊天不再看起来消失。#26786、提交
- 📌 侧边栏高亮跟随打开的聊天。 侧边栏不再在您移动到另一个页面后保持聊天高亮,因此在那里删除或归档它不再将您带回到新建聊天,并且克隆不再留下两个看起来被选中的聊天。#26977
- 🔀 回复期间的侧边栏排序。 后台更新(如后续建议、来源和状态)不再将聊天推到侧边栏顶部或更改其最后更新时间,保存聊天变量或设置也不会,新建聊天的自动生成标题也不会。提交、提交
- 🖱️ 一次只有一个悬停预览。 在侧边栏中的聊天之间移动,或在管理用户列表、频道消息和成员列表中的头像之间移动,不再使较早的预览在新的预览后面保持打开状态。#27549、#27548、#27578、#27577
- ✨ 文件夹列表不再闪烁。 单击侧边栏中的文件夹标题不再会在其重新出现之前短暂清空您展开文件夹的聊天列表。#27535、#27533
- 🫧 侧边栏行闪烁。 将指针移过侧边栏中的聊天不再会使其标题和时间戳闪烁出现或消失,或者将时间戳绘制在操作按钮下方。#27474、#27473
- ⭐ 多模型回复中的评级刻度。 反馈面板中的评级刻度在多个模型并排回答时不再被截断,因此每个分数都可以选择。#26846
- 🧑🤝🧑 并排的重复模型。 在并排聊天中添加两次相同的模型现在会在重新加载后保留每个列自己的答案,而不是每个列都折叠到第一个上。#26980
- ⬅️ 打开管理或工作区后的后退按钮。 在浏览器中后退现在会将您带回您来自的页面,而不是再次前进到您刚刚所在的位置。#27478、#27477
- 🎛️ 键入 top_k 值。 高级参数中的 top_k 框现在接受不超过其限制的整数并拒绝其他内容,而不是让滑块和框在允许的内容上产生分歧。提交、#26669
- 🌙 深色模式下的日期选择器。 日期和时间字段上的日历和时钟图标现在在深色模式下可见,跨越日历、自动化计划、帐户设置和分析。#27275、#27274
- 🪞 设置内容保持在窗口内。 “已归档聊天”中的长聊天标题现在会缩短,悬停时显示完整标题,并且管理分析表和图表不再延伸超过设置窗口边缘。#27306、#27305、#27329
- 🔗 在原位打开的设置链接。 指向设置选项卡的链接现在无需刷新页面即可打开,并且终端菜单中的“添加终端”按钮直接跳转到集成选项卡,而不是闪烁管理面板然后无所作为。#27552、#27551
- 🎰 新建聊天时的模型选择。 开始新的聊天现在会在上一个选择不可用时回退到您的默认模型,而不是留下选择器为空,同时链接中指定的模型仍然有效。提交、#26697
- 📱 小屏幕上的模型选择器。 模型列表现在完全保持在屏幕上并根据可用空间调整自身大小,而不是在手机上延伸超过屏幕边缘或隐藏在屏幕键盘后面。提交、提交、提交
- 📲 侧边栏在日历上方保持打开状态。 在手机上从帐户菜单打开日历现在会关闭侧边栏,就像该菜单中的其他条目一样。#26979
- 🗓️ 窄屏幕上的自动化对话框。 自动化对话框底部的按钮现在在手机上位于它们自己的一行,而不是计划和模型选择器换行并将取消按钮推到中间。#27027
- 📐 键盘打开时的输入菜单。 消息输入的附件菜单现在在手机上的屏幕键盘打开时保持在屏幕上并调整大小以适应,而不是超出边缘。提交
- 🎈 跟随其内容的下拉菜单。 菜单现在在其内容增长或缩小时保持原位,而不是当子菜单切换到更高的内容时超出屏幕边缘,并且打开时不再弹跳。#27460、#27458
- 🧾 附件菜单只加载一次。 打开附件菜单的子菜单现在只请求其列表一次,而不是两次。#27461、#27459
- 🔦 PostgreSQL 上的聊天搜索。 在 PostgreSQL 设置上搜索您的聊天现在可以在当前对话中找到匹配项,而不是仅匹配仍以旧格式存储的聊天。提交
- 🧲 基于前缀的嵌入模型的搜索质量。 对外部向量数据库的记忆、知识库描述和搜索现在携带您的嵌入模型期望的查询和内容标记,因此在依赖它们的模型上,结果不再悄悄地比应有的差。提交、#26958、#26353
- 🥄 在知识库命令中计算匹配项。 将文本通过管道传输到知识库命令中的搜索现在尊重计数和仅文件名标志,而不是返回匹配的行(无论数量)。#26721、#26715
- 🔍 知识库文件搜索。 在知识库文件中搜索现在返回具有正确行号的匹配行,并且列出由管道分隔的备选方案的模式可以找到匹配项,而不是静默返回无结果。#27249、提交、提交、#26795、#26781、#26744
- 🖨️ PDF 文本识别。 文本识别包现在再次包含,因此应用程序可以启动,并且启用图像文本提取的 PDF 可以正确上传,而不是失败。#26851、#26646、#26994
- 🧿 股票安装上的 Mistral OCR。 使用 Mistral OCR 提取文档现在可以开箱即用,而不是因为代码假设存在但实际缺失的名称解析库而失败。#27440
- 📧 Outlook 邮件上传。 上传 .msg 邮件现在可以工作,而之前它会失败,因为它依赖的包根本无法与应用程序的其余部分一起安装。#26704、#26690
- 📇️ 选择 PaddleOCR-VL 时的上传。 选择 PaddleOCR-VL 作为文档加载器时,现在只有 PDF 和图像会发送给它,其他所有内容都会回退到常规处理,因此文本、markdown、电子表格和 Word 文件会被索引,而不是被拒绝。#27529、#24988、#26759
- 🪙 包含特殊令牌的文档。 按令牌拆分文本现在不会在内容包含保留标记序列时失败,因此这些页面和文件可以被获取并添加到知识库中。提交、#27094
- 📚 知识库上传可靠性。 直接向知识库添加文件现在在报告成功之前完成文件的处理和链接,因此上传的文件可可靠搜索。提交
- 🛠️ 来自管理面板的 Web 加载器设置。 管理设置中选择的网络加载器现在确实被使用,包括其证书检查、请求控制和代理设置,因此通过外部加载器获取页面的实例再次工作,而不是尝试直接访问互联网(无论启动时配置了什么)。#26749、#26747、提交、#27083、#27025、#27061
- 🚧 网络获取过滤器列表中的带引号的条目。 过滤器条目周围的多余引号(Docker Compose 会原样传递)不再会将列表变成阻止所有网络地址的列表。#26910、#26908
- 🌐 安装某些插件时的网络获取。 获取网页和加载网络搜索结果在工具或函数引入替代网络库的实例上再次工作,这曾导致所有获取失败并返回空结果。#26796、#26791
- 📢 网络搜索失败的解释。 当搜索找到页面但无法存储它们时,聊天现在会说明出了什么问题并指向文档设置,而不是报告已搜索的站点然后未找到来源。#26883
- 🕸️ 混合网页提取。 一次获取多个网页现在会根据其自己的格式读取每个网页,而不是将第一个网页的格式应用于整批网页并弄乱其余部分。#27367
- 🧯 网络获取时的残留浏览器会话。 通过远程 Playwright 服务器获取页面现在会关闭每个页面和浏览器,即使页面超时或搜索中途放弃,而不是留下打开的会话并使每次后续搜索变慢(直到该服务器重启)。#27526、#25880
- 📇️ 安全获取登录头像。 某人通过提供商登录时获取的头像现在通过与其他出站请求相同的受保护路径获取,因此在检查和获取之间更改其地址的主机无法再将其指向内部服务,并带走转发的登录令牌。#26699
- 🪃 终端代理路径中的反斜杠。 包含反斜杠的对终端代理的请求现在被拒绝,关闭了一种将目录遍历偷运过路径检查到将其视为分隔符的上游的方法。#27198
- 🧱 伪装成公共地址的内部地址。 隐藏在 IPv6 地址内部目标(通过映射、6to4、Teredo 或 NAT64 形式)的网络地址现在被识别并拒绝,就像任何其他内部地址一样。提交
- 🪤 获取页面时更严格的检查。 获取的页面发出的每个请求现在都针对地址规则进行检查,而不仅仅是页面本身,重定向的每一跳依次检查,页面尝试打开的后台工作程序和套接字连接被拒绝。提交、#27042、#27008
- 🐢 获取受控速时丢弃页面。 通过 Firecrawl、Tavily、Microsoft Web IQ 或 Playwright 获取的页面现在不会在加载器必须在请求之间暂停时被丢弃,这曾悄悄丢失紧随另一个页面之后的任何页面,有时将其归咎于安全检查失败。#27528、#26079
- 🎙️ 听写重复早期语音。 听写到消息框中不再重新插入您在之前的录音中说过的所有内容,并且取消录音不再无论如何都插入文本。#26793、#26784
- 🧩 长录音的顺序。 为转录而分割成部分的长录音现在按其被讲述的顺序重新组装,而不是有时在转录文本和从它读取的所有内容中部分出现乱序。#27417、#27143
- 🔊 文本转语音的可靠性。 文本转语音播放和其他流式响应现在不会在多个请求同时运行时偶尔中断。#26924、#26922
- 🧮 Anthropic 使用情况报告。 来自 Anthropic 兼容 API 的响应现在报告准确的输入和输出令牌计数,在提供程序提供时传递缓存和服务器工具数据,并且在未知时完全省略输入计数(而不是报告零)。提交、提交、提交、提交、提交、提交、#26790、#27293、文档:#1328
- 📨 发送到严格提供商的非流式请求。 非流式请求不再携带仅流式使用的选项,某些提供商会完全拒绝该选项。
- 🪝 具有结构化参数的工具调用。 将工具调用的参数作为对象发送(或根本不发送)的提供商现在不会在中途破坏回复。#27195
- 🧬 共享管道模型的工具调用。 基于管道或流形模型的共享模型的非管理员用户现在不会在工具调用后立即看到响应静默停止。#26906、#26900
- 🧑🔧 以任意用户身份启动。 以非 root 帐户运行映像(如 OpenShift 和类似设置所做的那样)现在不会在启动日志中填充权限错误(当它写入自己的图标和清单时)。#26664、#26662
- 🩹 在没有所有者的工具或函数情况下启动。 没有所有者的工具或函数现在不会阻止应用程序启动,这曾阻塞所有聊天响应直到其被移除。#26850、#26843
- 🏷️ 包含连接前缀的模型名称。 设置在连接上的前缀现在仅从模型名称的前面移除,因此其自身名称包含该文本的模型在请求发送前不再被损坏。提交
- 🦙 新拉取的 Ollama 模型。 向在列表上次构建后拉取的模型发送消息现在会刷新列表并继续,而不是报告模型未找到。提交、#27353
- 🗑️ 从选择器中删除模型。 从模型选择器菜单中删除工作区模型现在仅删除该模型并保留底层模型,而不是因未找到错误而失败。#26819
- 🔑 通过 OAuth 连接远程 MCP 服务器。 设置远程 MCP 服务器现在会在其登录详细信息无法发现时明确报告,而不是保存一个不可用的连接(该连接在您尝试授权时会因服务器错误而失败)。#26654、#26647
- 🪢 具有交叉引用类型的工具服务器。 其描述定义了相互引用的类型的工具服务器现在会加载其工具,而不是完全失败,因此集成再次出现在模型和工具选择中。#27413、#27239
- 👥 预览某人可以使用的内容。 人员访问权限的预览现在包括其拥有的模型、知识库和工具,而不仅仅是与他们共享的。提交、#27423、#27407
- 🧰 模型编辑器加载。 模型编辑器现在在无法加载其工具列表时不再无法打开,而是优雅地回退。提交
- 🗃️ Milvus Lite 集合创建。 在嵌入式 Milvus Lite 上设置集合现在成功,而之前在创建资源索引时可能会失败。#26911
- 🧽 Milvus 日志噪音。 由 Milvus 支持的实例在索引和检索期间不再用弃用警告填充其日志,并且可以继续使用未来完全放弃旧接口的 PyMilvus 版本。#27521、#26978
- 🚏 残留的终端容器。 使用策略的终端协调器连接现在通过该策略发送每个请求,因此每个人不再会在预期容器旁边最终有一个意外的容器。#26945、提交
- 🔦 加固实例上的连接。 在关闭管理访问绕过的情况下,尚未获得访问权限的连接现在可以再次被管理员访问,而不是对所有人隐藏(包括创建它的管理员)。#27581、#27580、#27064
- ♻️ 连接更改立即生效。 保存连接设置现在会立即刷新模型列表,而不是将以前的模型保留在原处直到服务器重启。
- 🚫 禁用的 OpenAI 连接得到强制执行。 关闭 OpenAI API 现在会阻止对其的聊天请求并清除其模型,而不仅仅从界面隐藏它。
- 🪛 删除 Ollama 连接。 移除 Ollama 连接现在会立即保存,而不是在之后切换 Ollama API 开关之前重新出现。#27483、#27482
- 🧹 孤立的会话得到清理。 收割由崩溃的工作程序留下的会话的实例现在会在另一个实例持有该作业时继续尝试,而不是一个实例永远放弃并留下陈旧的会话堆积,并且它使用的锁无法再被不持有它的实例释放或续订。提交、提交
- 🧊 Redis 集群连接。 使用 Redis 集群模式的部署现在不再被传递为单服务器构建的连接,或者反之亦然(当两者指向同一地址时)。提交
- 🚏 配置 Redis 时停止回复。 停止按钮现在确实停止由 Redis 支持的部署上的生成,其中在实例之间传递停止请求的监听器在几次空闲秒后静默死亡并留下令牌继续流动,新的 “REDIS_SOCKET_TIMEOUT” 设置控制该超时。#27104、#26779
- 🛟 超时时的 Redis 故障转移。 超时的 Redis 连接现在会重试新解析的主服务器,而不是失败,因此 Sentinel 设置可以从故障转移中恢复,而不是报错。提交、#27210
- 👣 通过受信任标头的首次登录。 两个同时到达的通过受信任标头首次登录的请求不再为同一人创建两个帐户,并且数据库现在拒绝为已存在的地址创建第二个帐户(无论其大小写)。提交、提交、#27571、#27117
- 🔧 来自环境变量的单点登录设置。 通过环境变量提供的单点登录设置不再被首次启动时保存的陈旧值覆盖,因此更改它们会生效。#26928、#26917
- 🎫 发送给工具的过期身份令牌。 登录会话现在在其最早令牌过期前刷新,因此转发您身份的工具和管道不再向下游服务传递其拒绝的令牌。#27520、#27066
- 🎫 永不过期的登录令牌。 返回没有过期时间且没有刷新方式的提供商现在被如实对待,而不是被赋予一个虚构的一小时寿命(这会使会话在之后无法使用)。提交、#26802、#26141
- 🔓 密钥轮换后的单点登录。 使用 OIDC 登录现在可以在提供商轮换其签名密钥时恢复,刷新缓存的密钥并重试,而不是因无效凭证错误而失败。#27310、#26407
- 🔑 会话过期后登录。 过期的会话现在会将您干净地返回到登录页面,然后返回到您之后所在的位置,而不是将您从登录页面弹开或留下陈旧的会话。提交、提交、#26751、#26731
- 🫥 临时聊天和频道不写入任何内容。 在临时聊天或频道消息中生成或编辑图像以及状态更新不再尝试针对从未存储过的对话保存自己,并且任务列表工具根本不再提供在那里(而不是提供然后失败)。提交、提交、提交、提交、#27432
- 🎞️ 工件面板重新打开自身。 工件面板现在在检测到已完成的块时打开一次,因此在回复中途关闭它不再会在后续的每个词上被强制重新打开。提交、#27399
- 🏞️ 工具返回的图像。 工具产生的图像现在以 OpenAI 兼容提供商接受的形式传递给模型,因此它实际上可以查看它们,而不是接收到无法读取的结果。提交
- 🖼️ 外部消息图像。 托管在其他站点上并在消息中引用的图像现在内联显示,而不是被替换为占位符。提交
- 🔣 包含垂直条的名称。 您通过 @ 符号或斜杠插入的内容现在按您键入的键记录,而不是根据其名称猜测,因此名称包含垂直条的提示或模型不再被误认为是技能。提交
- 〰️ 可折叠块上方的文本。 直接写在可折叠部分上方的行不再变成大标题,并且该部分本身仍然呈现为可折叠小部件,而不是泄漏其标记。提交、#27148、#27001
- ✳️ 消息输入中的星号。 用星号包裹单词不再会静默地将其变为斜体并吞掉星号,因此您的提示会完全按照您键入的方式到达模型。提交
- 📶 手机上的重新连接警告。 在使用另一个应用后切换回 Open WebUI 不再会在选项卡唤醒并自行重新连接时闪烁连接丢失警告。提交
- 🧭 从自动化编辑器访问侧边栏。 在手机上打开自动化现在不会隐藏侧边栏按钮,因此您无需先离开编辑器即可四处移动。
- 🔣 包含不寻常字符的聊天。 存储前会从文本中清理损坏的字符序列,因此拾取了损坏字符序列的对话仍可保存和打开,而不会无法加载。提交、#27201、#27081
- 📛 工具调用后的失败。 在继续进行工具调用或代码解释器运行后失败的回复现在会说明情况,而不是在答案中途停止且无解释原因。提交、#27426、#27411
- 💾 重新加载后保留的错误。 结束流式回复的错误现在会保存到对话中,因此重新加载后它仍然在那里,而不是消失。#27365、#27074
- 💬 可读的错误消息。 对话中的错误现在始终显示可读的、换行的文本,而不是超出边缘,包括包裹在另一个错误中的错误。
- 🪝 被阻止的 webhook 目标看起来像失败。 指向不可公开访问的地址的 webhook 现在会跳过并显示简短警告,而不是显示错误和完整的回溯(看起来像服务器在启动时崩溃)。提交、#26975
- 🕵️ 错误日志中打印的值。 失败现在不会在其回溯旁边打印附近变量的内容,这可能会将密钥和消息内容放入日志中,并且新的 “LOGURU_DIAGNOSE” 设置可为调试重新开启该详细信息。提交、#26814
- 🪵 空的审计排除列表。 清除从审计日志记录中排除的路径列表现在不会完全关闭审计,因此请求会按预期记录。#27370、提交
- 📒️ 可读的审计日志主体。 记录响应主体的审计日志现在将其存储为可读文本,而不是压缩数据,因此当浏览器请求压缩时,条目是可读的。#27369
- 👍 反馈事件中的评级。 某人对响应进行评级时发送的事件现在携带给出的评级,而不是报告为空。提交、#26840
- ⏱️ 准确的请求计时标头。 每个响应上报告的处理时间现在包含秒的小数部分,而不是将一秒以下的所有内容都向下舍入为零。#27368
- 📋️ 提供商拒绝日志记录。 当模型提供商拒绝请求时,其给出的原因现在记录在服务器日志中,因此管理员无需直接查询提供商即可诊断故障。#27238、#27237、#26253
- ⏳️ 更快的许可启动。 带有许可证密钥的实例在启动期间不再等待许可证服务器,因此应用程序无需该延迟即可准备好服务流量。提交、提交
- 📅 日历邀请回复。 您是否接受邀请现在由您自己的回复决定,而不是由创建事件的人决定,并且您拒绝的邀请会从您的日历中消失。#27007
- 🗓️ 手写计划。 重复规则现在以相同的方式读取(无论其是大写还是小写),规则中的开始日期得到尊重,逐秒的规则被理解,并且无法支持的规则会收到清晰的错误消息而不是不可预测地运行。提交、提交、#27470
- 📅 一个日历事件使服务器停滞。 确定重复事件下一次何时发生现在只需遍历其规则一次,而不是为每个事件重新从头开始计算,因此从旧开始日期每分钟重复一次的事件无法再为所有人占用服务器。#27468
- ⏰ 重复自动化的调度。 每隔几分钟或几小时重复一次的自动化现在与时钟对齐,并且在服务器时钟领先于您的时区时,不再被错误地拒绝(认为没有即将到来的运行)。提交、#26954
变更内容
- ⚠️ 数据库迁移: 此版本包含数据库架构更改;我们强烈建议在生产环境中升级之前备份数据库及所有关联数据。如果您运行的是多工作程序、多服务器或负载平衡部署,则必须同时更新所有实例,不支持滚动更新,这会因架构不兼容导致应用程序故障。
- 🛠️ 管理设置移入设置中。 管理设置和分析仪表板不再是单独的页面,现在与您的个人设置一起在设置窗口中打开,位于其自己的管理部分下,旧链接会重定向到那里。提交、提交、提交
- 📁 工作区操作集于一个菜单中。 创建、导入和导出工作区项目不再在每个页面上都有自己的按钮,现在可以从工作区标题中的单个“创建”菜单访问,创建提示或知识库会打开对话框而不是单独的页面。提交、提交、提交、提交
- 🔐 管理员不再能访问他人的自动化。 查看、编辑、运行和删除自动化现在限于创建它的人,因此拥有他人自动化链接的管理员会被拒绝访问,而不是被允许通过。提交
- 🏷️ 更短的无表情符号标题。 聊天和笔记的自动生成标题现在为两到四个单词,不再包含表情符号,任何喜欢旧风格的人可以通过编辑管理设置中的标题生成提示来恢复它。提交、提交
- 🗂️ 已归档的聊天移至设置中。 “已归档聊天”快捷方式不再在用户菜单中,您的已归档对话现在通过设置访问,在那里也可以搜索和排序。提交、提交
- 🔢 使用情况现在单独报告最新调用。 在响应的使用情况块中,“prompt_tokens”和“completion_tokens”现在携带最近模型调用的计数(而不是累计总数),而“input_tokens”、“output_tokens”和“total_tokens”保持累计,因此任何读取第一对用于计费的内容应改为读取第二组。提交、#27031
- 🧳 “python-jose”库不再安装。 Open WebUI 中没有任何内容再导入它,因此它及其引入的两个包已从映像中删除,并且任何直接导入它的工具或函数现在需要自己安装它。#27444
- 📦 不再捆绑存储模拟器。 可选的 Google Cloud 存储模拟器不再作为完整软件包的一部分安装,因此任何依赖它进行本地存储测试的人现在需要自己安装“gcp-storage-emulator”。提交
更新内容 (原始)
Added
- 🎨 Redesigned interface. Open WebUI has been visually rebuilt from the ground up. All aspects of the User Interface, from the chat view to the admin panel. Now with a narrower conversation column, lighter typography, tidier spacing, consistent menus and dropdowns, clearly outlined text boxes, and settings rearranged. Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, #27178, Commit, Commit
- 🤖 Sub-agents. Administrators can now enable sub-agents, which let a model hand parts of a task to background helper agents that run their own tool-driven conversations and report results back into the chat, tuned through new “ENABLE_SUBAGENTS”, concurrency, iteration, and system-prompt settings. Commit, Commit, Commit, Commit
- 📂 Folder pages. Opening a folder now takes you to its own page, where its chats load a page at a time, can be sorted by title or last updated, and you can start a new chat straight from the folder. Commit
- ⏲️ Chat timers. The assistant can now set a timer that brings a prompt back into the conversation later, after a delay or at a set time, and can drop it automatically if you read the chat or reply before it fires. Commit
- 🔔 Notification targets. Notifications now have their own settings tab where you can send them to several webhook destinations, each picking which events it wants, from chats finishing or failing to channel messages and calendar alerts, with a test button and a choice between always notifying or only when you are away, and any webhook you already had is carried over for you. Commit, Commit, Commit, #24750
- 🗯️ Full replies in channels. A reply from the assistant in a channel is now saved and shown in full, with its reasoning, tool calls and other structured parts, where it previously came through blank. Commit, #26720, #27409, #26707, #26656
- 📣 Notifications from the assistant. The assistant can now send you a notification itself when something is worth your attention, so a long task can reach you after you have moved on to something else. Commit, Commit
- 🌎 Share a chat with anyone holding the link. A shared chat can now be set to Open so it opens without signing in, with visitors no longer bounced to the sign-in page on their way to it, which administrators must first allow through a new “Chats Open Sharing” permission that stays off by default, and such pages ask search engines not to index them. Commit, Commit
- 🔖 Chat variables. A model’s system prompt can now declare fields such as text boxes and dropdown lists that you fill in for a conversation, with the values saved alongside the chat and carried over when it is forked or cloned. Commit, Commit, Commit, Commit, Commit, Commit, #26915
- 🗄️ LDAP group synchronization. Administrators can now map LDAP groups to Open WebUI groups from the authentication settings, with optional automatic creation of missing groups, so a user’s group memberships are kept in step with the directory each time they sign in. #27263, #18015
- 👥 Restrict sharing with groups. Admins can now stop resources from being shared with entire groups through a new “USER_PERMISSIONS_ACCESS_GRANTS_ALLOW_GROUPS” permission, which stays enabled by default so existing group sharing keeps working untouched. Commit, Commit, Commit, Commit, #27124
- 🤝 Shared folder collaboration. People with access to a shared folder can now use its files and system prompt as knowledge in chat and, with write access, rename and manage the folder, all according to their read or write permission. Commit, Commit, Commit, Commit
- 👁️ Chat previews in the sidebar. Hovering a chat in the sidebar now shows a compact preview of its recent messages, so you can find the conversation you want without opening it. Commit, Commit, Commit, Commit
- 🕗 Local message timestamps. Message timestamps now appear on hover in your device’s local date and time format, with the full weekday and date shown in a tooltip. Commit, Commit
- 📇 User variables. You can now store your own values in account settings, such as your role or how you like answers written, and a model’s system prompt can insert them wherever they are needed. Commit, Commit, Commit
- 🧺 Automations that file their chats away. An automation can now be pointed at one of your folders, from the dialog, the editor or by asking the assistant, so each run lands there instead of loose in your chat list, and the folder is cleared automatically if it is later deleted. Commit, Commit, Commit
- 🔵 See what you have not read yet. Folders in the sidebar now carry a count of chats with something new in them, a folder’s own page marks unread chats with a dot, shows a spinner on any still generating, clears the dot as you open one, and keeps itself up to date as replies finish elsewhere, unread chats sort to the top of a folder, and you can mark a single chat unread again mark everything in a folder read, or mark every chat read at once from the sidebar. Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit
- 🗜️ Compact a chat on demand. Typing a compact command in a long conversation now summarizes the earlier turns straight away, instead of waiting for it to happen automatically once the conversation grows past the threshold. Commit, Commit
- 🌿 Fork a chat. Every response now has a fork button that copies the conversation up to that point into a new chat which remembers where it branched, so you can carry on down a different path without touching the original. Commit, Commit, Commit, Commit
- 📌 Pin the conversation map. The chat overview now has a pin control that stops it recentring on the newest message, so you can keep looking at the branch you were reading while a reply comes in. #25736
- 📊 Chat status at a glance. The slash menu now shows how full the context window is, and a new status command opens a panel with context usage, queued messages, running tasks, and the chat ID. Commit, Commit
- 🎹 Customizable keyboard shortcuts. Most keyboard shortcuts can now be rebound to key combinations of your choosing in settings, which saves them to your account, warns you when two actions share a combination, and offers a reset to the defaults, with moving to the previous or next chat and opening the controls panel available to bind as well. Commit, Commit, #26624
- ⌨️ Turn keyboard shortcuts off. A new switch in the keyboard settings disables every configurable shortcut and hides its hint, so combinations that clash with your browser or operating system pass straight through. #27300, #1008
- ⌨️ Skills in slash commands. Typing a slash in the message input now lists your skills alongside your prompts, grouped under headings and with descriptions on hover, so you can attach a skill without leaving the keyboard. Commit
- 📎 Attach anything with the at menu. Typing an at sign in the message input now searches your folders, knowledge collections, and individual files as well as your models, and pasting a link offers it as a web page or YouTube attachment. Commit
- 📝 Chat with a note. Chatting with a note now gives you the full chat experience, including model choice, tools and file attachments, alongside suggested prompts, a button to insert a response straight into the note, edits that appear in the note as the assistant makes them, and as many separate conversations per note as you want to keep. Commit, Commit
- ↕️ Sort your lists. The notes, prompts, models, knowledge, skills, tools and functions lists can now be sorted by title or by when they were last updated, in either direction, by clicking the column headings. Commit, Commit, #27457, #27456
- 🗒️ Notes without stored contents. A note whose contents were never filled in now opens and saves normally instead of failing. Commit
- 📄 Note attachments. Notes now have an upload option in their menu and show attached files above the note itself, where you can open or remove them, instead of only accepting files dropped onto the page. Commit, Commit
- 🗂️ The assistant can search your attachments. A new Files capability lets the model list the files attached to the chat and search them by meaning or by exact text, and read the parts it needs, rather than having their whole contents pushed into the conversation up front, and knowledge collections or notes attached to a chat are now announced to the model so it can query those the same way. Commit, Commit, #26711, #27232, #26708
- 🔎 Search in the attachment menu. The attachment menu now lets you search your knowledge bases, notes, files, and chats instead of scrolling to find them, with matching text shown for chats. Commit
- ⚗️ Default file upload mode. You can now choose in settings how attached files are handled by default, rather than picking that on each upload. #20900, #18431
- ⬇️ Response auto-scroll toggle. A new interface setting lets you stop the view following a reply as it is written, so you can read earlier text while generation continues. Commit, #26826
- 📜 Client certificates for SearXNG. Web search can now present a client certificate to a SearXNG instance that requires one, through new “SEARXNG_CLIENT_CERT_FILE” and “SEARXNG_CLIENT_KEY_FILE” settings. Commit, #26992
- 🔭 OpenSERP web search. Web search can now run against a self-hosted OpenSERP instance, which returns results from several major search engines without any API key, configured through a new “OPENSERP_BASE_URL” setting. #27437, #27438
- 🥇 Model order as a setting. Administrators can now set the order models appear in through a new “MODEL_ORDER_LIST” variable, so the arrangement survives a restart on instances that do not persist configuration. #27420, #27206
- ⏱️ Idle cap for streamed replies. Administrators can now set an “AIOHTTP_CLIENT_STREAM_IDLE_TIMEOUT” that ends a streamed reply when the provider stops sending anything for that long, instead of holding the connection open until the overall timeout expires. Commit, Commit
- 🖼️ Media types an extraction engine may handle. Administrators can now list which image and video types the configured content extraction engine is allowed to process, instead of media being passed to it only when the engine is the external one, so an engine with its own text recognition can take images. Commit, #26940, #14768
- 🧵 Where a channel reply lands. Administrators can now choose whether a reply to a mention posts in a thread under that message or straight into the channel. Commit, #27410
- 📚 Limits for knowledge tools. Administrators can now set how much a knowledge search or file view may return, how many files one search may scan, and how many matches are reported, and a knowledge command’s whole output is now capped so a single call cannot flood the conversation. Commit, #27524, #27327, #26139
- 🎛️ File streaming chunk size. Administrators can now tune how large each chunk of a streamed file transfer is through a new “AIOHTTP_FILE_STREAM_CHUNK_SIZE” setting. Commit
- 🪛 Model for summarizing long chats. Administrators can now pick a dedicated model to write context compaction summaries, separate from the task model, with the conversation’s own model used when none is chosen. #26806, #27051
- 📏 Context compaction token cap. Administrators can now set a “Token Cap” that limits how high per-model context compaction thresholds are allowed to reach, giving finer control over long-conversation summarization. Commit, Commit, Commit
- ⚖️ Retained messages after compaction. Administrators can now set what share of recent messages survives when a long conversation is summarized, between a tenth and half of it. Commit, #27050
- 🧠 Memory as a per-model capability. Whether a model receives your stored memories is now a switch on the model itself, so it can be left on for everyday assistants and off for ones that should start from nothing. Commit, #26861, #18610
- ☑️ Searchable model pickers. When editing a model, the Tools, Skills, Knowledge, Voice, Filters and Actions pickers now let you search and toggle items in place, select or clear them all at once, and see what is active at a glance. Commit, Commit, Commit, Commit, Commit, Commit, #26758
- 🎚️ Switch for single sign-on. OAuth and OIDC now have their own on and off switch in the authentication settings, matching the LDAP one above it, so sign-in through a provider can be turned off without clearing the configuration. #26988
- 🖲️ One sign-in attempt at a time. The sign-in, sign-up and LDAP form now disables its buttons while a request is in flight, so a slow response no longer turns repeated clicks or Enter presses into several concurrent attempts. #27416, #27264
- 🛂 Trusted clients for token exchange. Administrators can now list which OAuth clients may have their tokens exchanged for a session, through a new “OAUTH_TOKEN_EXCHANGE_TRUSTED_CLIENT_IDS” setting, so a token a person obtained by signing in to an unrelated application of the same provider can no longer be turned into a session as that person. #27546, Commit, Commit
- 🚪 Throttle for token exchange. Administrators can now cap how often the OAuth token exchange endpoint may be called from one address through new “OAUTH_TOKEN_EXCHANGE_RATE_LIMIT” and “OAUTH_TOKEN_EXCHANGE_RATE_LIMIT_WINDOW” settings, which bound automated attempts with leaked or guessed tokens and stay off until set. Commit
- 🔏 PKCE for every sign-in provider. The code challenge setting now applies to Google, Microsoft and GitHub sign-in as well as OpenID Connect, so the same protection covers every provider. Commit, #27302
- 🔤 Embeddings through the OpenAI-compatible API. Integrations built on OpenAI client libraries can now create embeddings through the Ollama proxy, so embedding requests go through the same sign-in and model access rules as chat instead of needing direct access to Ollama. #27332, Commit, #27328, Docs:#1331
- 🎚️ Passthrough parameters per connection. Administrators can now list request parameters that a connection should receive untranslated, under a new Advanced section in connection settings, so provider-specific options reach the upstream API intact. Commit
- 🅰️ Anthropic requests passed straight through. Requests to the Anthropic-compatible API aimed at an Anthropic or LiteLLM connection now reach the provider untouched rather than being translated on the way, and LiteLLM is selectable as a connection type. Commit
- 💭 Reasoning in Anthropic responses. Responses from the Anthropic-compatible API now carry the model’s reasoning as thinking blocks, in both streamed and complete responses. Commit
- 🧩 Structured output through the Anthropic-compatible API. Requests can now ask for a JSON schema or JSON object response and set a reasoning effort, which are carried through to the upstream model. Commit
- 🪧 Group names in forwarded headers. Custom headers on a connection can now carry the groups a person belongs to, by name or by id, so an upstream service or gateway can apply its own rules per group. #27236, #26834
- 🪪 User identity forwarded to Mistral OCR. Document extraction through Mistral OCR now carries the requesting user’s identity when user info forwarding is enabled, so a gateway in front of it can attribute requests per user like other outbound integrations already do. #27253, #27250
- 🔢 Anthropic token-counting endpoint. The Anthropic-compatible API now offers a token-counting endpoint, so integrations can check how many input tokens a request will use before sending it. Commit, Commit
- 🖲️ Terminal instructions read fresh. The instructions a terminal server provides are now fetched for each request, so changing them on the server takes effect immediately instead of after re-saving the connection or restarting. #27242
- 🖥️ Live terminal server policies. Administrators can now read an orchestrator terminal server’s current policy and lifecycle settings directly in connection settings rather than relying on a locally cached copy. Commit, Commit
- 🌍 Model privacy at a glance. Admins can now make a model public or private straight from its menu in the model list, where each model is marked as public, shared, or private. Commit
- 📈 Personal usage dashboard. A new Usage tab in settings shows your own activity over time, including a token-activity heatmap, current and longest streaks, lifetime and peak token counts, your longest active chat, and your most used models and tools. Commit
- 🧠 Memories in settings. Your memories are now listed directly in personalization settings where you can search, add, edit, and remove them, instead of being tucked behind a separate manage dialog. Commit
- 💾 Import notes and automations. Notes can now be brought in from text and markdown files, and automations can be exported and imported as files, so you can move them between instances. Commit, Commit
- 🧮 Counts in the tabs. The workspace tabs now show how many models, knowledge bases, prompts, skills, and tools you have, and the admin tabs do the same for users, groups, leaderboard entries, and feedback, so you can see the size of each section without opening it. Commit, Commit, Commit
- 🧾 Group permissions at a glance. The groups list now shows whether each group uses custom or default permissions, without opening it. Commit, Commit
- 📤 Streamed file transfers. Uploading a model, pipeline or audio file now sends it in chunks instead of holding the whole thing in memory, and reading and writing files no longer blocks other requests, so large transfers no longer spike memory or stall the server. Commit, #27351, #27349
- 🧰 Built-in tool descriptions built once. The descriptions handed to the model for the built-in tools are now worked out once at startup rather than rebuilt on every message. Commit, Commit, #27374, #27396
- 🪺 Records read without a double pass. Loading a model, tool, prompt, skill, note, knowledge base, channel or calendar no longer converts the record twice on the way out. Commit, #27377
- 🔧 Faster tool and knowledge base listings. Listing tools no longer loads each one’s full source, and working out which tools and knowledge bases you can see takes a single check rather than one per item. #27387
- 🧊 Quicker collection checks on Chroma. Checking whether a collection exists now asks for that one collection instead of listing them all, which grew slower with every knowledge base and file. Commit, #27394
- 🔠 Tokenizer loaded once. The tokenizer used to split documents is now kept after first use rather than being loaded again for every file. Commit, #27394
- 📗 Faster knowledge base file lists. Opening a knowledge base now loads just the file names and details instead of the entire extracted text of every document, so large collections appear almost instantly. #27386, #26144
- 🗝️ Faster file access checks. Working out whether you can open a file no longer scales with how many workspace models and knowledge bases exist, so opening files and listing folder contents stays quick on large instances. #27383
- 🕰️ Faster automation scheduling. Working out when an automation that repeats every few minutes or hours runs next is now near instant, instead of taking twenty seconds or more and slowing further each year. Commit, #26954
- 📁 Faster folder loading. Your folder list no longer runs a separate lookup for every folder to check where it sits, so it loads in a single pass. Commit
- 🎯 One round of requests per folder click. Selecting a folder in the sidebar now fetches the folder, the folder tree, and each expanded folder’s chats once instead of two to four times. #27540, #27539
- 🎧 No wasted work when nobody is listening. Updates for a chat whose tab has been closed, or for requests made through the API, are no longer packaged up only to be discarded, which matters most on long streamed replies. #27366, Commit
- 📑 Cheaper audit logging. With audit logging on, each request is no longer authenticated a second time just to record the log entry, so audited instances carry noticeably less overhead. #27373
- 🪧 Cheaper tagging after each reply. Saving the tags generated for a conversation now updates just that field instead of loading, rewriting and re-reading the whole conversation, which cost more the longer the chat. #27382
- ✍️ Faster saves across the app. Saving a chat, note, prompt, tool or user setting no longer re-reads the record it just wrote, so writes finish sooner, most noticeably on long conversations. #27381, #27379, Commit, Commit
- 🛢️ Less database overhead per request. SQLite installations no longer run a connection check before every database call, and requests that never touch the database skip the bookkeeping that used to run regardless. #27385
- ⚡ Faster memory lookups. Stored memories are now indexed so retrieving them stays quick as the number you have grows. Commit, #26957
- 🪪 Fewer checks before a reply starts. Working out whether you may use a model now looks up the model and your group memberships once instead of repeating both, including for every model a workspace model is built on. #27378
- 👤 Lighter user activity checks. Checking whether someone is currently active now reads only that timestamp rather than their whole profile, including their profile image. Commit, #27224
- 📨 Fewer settings lookups when sending a message. Sending a chat message now reads the settings behind tools, file retrieval, voice, skills and the code interpreter in fewer trips to the database, so replies start sooner. #27223
- 🪄 Lighter conversion for Ollama requests. Preparing a request for an Ollama model no longer copies the entire conversation before sending it, which cost more with every message and repeated on each tool-call round. #27371
- 🦙 Fewer settings lookups on Ollama requests. Ollama chat, generation and embedding requests now read their connection settings once instead of up to four times, so each request reaches the server sooner. #27226
- 🧹 Less repeated work on every response. Security headers are now worked out once at startup rather than rebuilt for each response, and ordinary page requests skip the redirect handling they never needed, so responses carry less overhead. #27229
- 🚀 Lower per-request overhead. Requests no longer each perform a settings lookup before they are handled, trimming a little latency from everything the app does. Commit, #27395, Commit, Commit, #27227
- 💨 Leaner filter handling while streaming. Filters applied to a streaming reply no longer re-read their settings and each plugin’s full source from the database for every chunk, so responses with filters enabled cost the server far less work. #27228, #27372, Commit, Commit, Commit, #27392
- 🚦 No filter bookkeeping without filters. Streamed API responses only build up the full reply for outlet filters when the model actually has one configured, instead of doing it for every request. Commit, #27391
- ✂️ Cheaper tag detection while streaming. Watching a reply for reasoning and code blocks now examines only the newly arrived text rather than rescanning the whole answer on every chunk, so a long answer no longer costs progressively more as it grows. #27360
- 🌊 Steadier long responses. Building up a streamed reply no longer costs more work as it grows, so long answers keep pace instead of slowing down toward the end. #27231, #27359, Commit, #27390
- 📦 Faster JSON handling as an option. Administrators can now switch the whole application to a faster encoder through a new “ENABLE_ORJSON” setting, covering request bodies, responses, upstream provider payloads and live updates, where the encoding of live updates was the largest single cost on the workers handling them in clustered deployments; it stays off by default because the faster encoder is stricter about what it accepts. #27583
- ⚙️ Faster Redis handling. The compiled “hiredis” parser now ships as a dependency and is used automatically, so deployments backed by Redis spend noticeably less processor time reading responses. #27282
- 🔗 Fewer Redis round trips per chat. Deployments backed by Redis now look up the model and connected sessions once per request instead of twice, and fetch the model list in a single call. #27225
- 🛰️ Fewer Sentinel lookups. Redis Sentinel deployments no longer ask which server is the primary and open a fresh connection before every single command, which had caused heavy connection churn and stalls under load. Commit, #27213, #27210
- 📡 Lighter live connection handling. Typing indicators, shared document edits and reconnections no longer re-read your account or copy the full participant list each time, and idle sessions are no longer rewritten every few seconds. Commit, #27393
- 🏎️ Faster chat search on PostgreSQL. Searching chats on PostgreSQL now reads from the message table instead of unpacking each conversation’s stored data row by row, so results stay quick as your history grows. Commit, #27221
- ⚡ Lighter model lists. Model lists no longer carry embedded profile images in their data, so they load faster. Commit, Commit
- 🏗️ Fewer queries when building the model list. Assembling the model list now makes fewer database round trips and no longer fetches every plugin’s source code along the way, so it comes together faster. Commit, #27389
- 🪶 Model lists without knowledge text. Model lists no longer include the extracted text of files attached to a model as knowledge, so they stay small regardless of how large those knowledge bases are. Commit, #27287
- 🔛 Functions can react to being switched on or off. Two new events fire just before a function is enabled or disabled, and the function being enabled receives its own event even though it is not active yet, so it can run whatever setup or teardown it needs. Commit, #26754, #26748
- 🔛 Multiple choice settings in plugins. A tool or function can now offer a setting where you tick several options from a list, fixed or worked out at the time it is shown, instead of asking you to type a comma-separated list of allowed values. #26884, #26848
- 🔌 Disable plugins entirely. Administrators can now completely turn off the built-in Tools and Functions plugin surfaces through a new “ENABLE_PLUGINS” setting, which hides them across the workspace and admin areas and removes their execution paths. Commit, Commit, Commit, Commit
- 🧵 Lighter chat listings and search. Building a page of chat search results or a folder listing no longer copies each full conversation to read its title and dates, so those pages come together faster and use far less memory while they are built. #27388
- 📮 Name lookups off the thread pool. Looking up a hostname no longer occupies one of the limited threads shared by every other piece of blocking work, so model calls, searches, page fetches and tool calls stop queueing behind each other once a few lookups are slow. #27440
- 🥬 Faster web page parsing. Pages pulled in by web search and web retrieval are now read with a faster parser, cutting roughly a tenth off the time spent on a ten result search. #27439
- 🧭 No pointless lookups when filtering search results. Filtering web search results against a domain list no longer resolves every result to an address first, which had turned a three second search into half a minute wherever the resolver was slow or a name did not resolve. Commit, #26920
- 🚄 Leaner passthrough streaming. Responses the server only relays now go straight through in whole network reads instead of being split line by line, roughly halving the work spent shuttling a streamed reply on those routes. #27384
- 🧶 Web page parsing off the critical path. Reading those pages no longer holds up everything else on the server, so other people’s replies, live updates and health checks keep flowing during a search instead of stalling for a second or more. #27446
- 🈶 Faster uploads of non-English text files. Working out the encoding of an uploaded text file now samples the part that needs it rather than scanning the whole file, taking a four megabyte Japanese or Chinese document from several seconds down to well under one. #27445
- ♿ Improved UI accessibility. Keyboard and screen reader users can now tell which chat in the sidebar is the one being viewed, open reasoning and detail blocks in a response, expand sidebar sections and open a folder without a mouse, sort the admin user list from the keyboard and hear which column it is sorted by, open a dropdown and its submenus with the keyboard, close them again with Escape and land back where they started, hear which value a dropdown is set to rather than only its label, hear what each admin settings switch, group permission toggle, checkbox, API key field and advanced model parameter slider controls, have the message box announced by its placeholder instead of as an unnamed field, press Enter on Cancel in a confirmation dialog without triggering the delete, reach the regenerate control, jump straight past the sidebar to the conversation with a skip link, hear what an icon-only button does across chat, calls, file previews, modals and the admin pages rather than an unlabelled button, placeholder text, section headings, field descriptions, inactive tab labels, timestamps, counters and icons are now readable against their background when High Contrast Mode is on, and sidebar buttons across notes, automations, the playground, and admin pages announce whether they open or close the sidebar. #27510, #27513, #27503, #27494, #27491, #27490, #27489, #27488, #27555, #27556, #27554, #27558, #27501, #27492, #27509, #27502, #26769, Commit, Commit, #26768, #26770, Commit, Commit, Commit, #27508
- 🔄 General improvements. Various improvements were implemented across the application to enhance performance, stability, and security.
- 🌐 Translation updates. Slovenian is now available, and translations for English (UK), Finnish, German, Japanese, Portuguese (Brazil) and Portuguese (Portugal) were enhanced and expanded.
Fixed
- 🛡️ Security Advisory: This release includes security and access-control fixes. We recommend updating production deployments at your earliest convenience. Not all security fixes in this version may be enumerated in the fixed section. Some may be withheld for a short time to give administrators time to upgrade. Advisories
- 🔒 Terminal file preview isolation. Previewing an HTML file in the system terminal now runs it in an isolated context by default, closing a cross-site scripting hole that could expose your login session or, for privileged accounts, run code on the server. #26907
- ➗ Malformed maths in a message. Maths that fails to render is now shown as plain text rather than being placed into the page as markup, closing a way for a crafted formula in a chat, channel or shared conversation to run code in the browser of anyone reading it. #26718
- 🔩 Updated file upload parsing library. The library that parses file uploads and form submissions has been updated to a release that addresses a security advisory affecting that parsing path. #26991
- 🛑 Deactivated accounts lose live access. Real-time connections now apply the same role check as the rest of the application, so an account moved out of the user or admin role can no longer keep its channels and shared notes open on an existing token. #27537
- 🛅 Writing into someone else’s chat. Completion and action requests now confirm you own the chat they name before anything is written to it, so a filter or action can no longer be pointed at another person’s conversation. #27486
- 🎟️ Ollama version no longer readable anonymously. Reading the configured Ollama backend’s version now requires signing in, closing a route that let anyone learn the version in use and count how many backends are configured. #27199
- 🔐 Folder sharing permission. The folder sharing setting in default and group permissions now saves instead of being silently discarded, so allowing or restricting folder sharing actually takes effect. #27296, #27120
- 🔕 Webhook permission enforcement. People without permission to use webhooks can no longer save webhook notification destinations to their settings, so the permission is enforced when settings are saved rather than only reflected in the interface. #27297, Commit
- 🛎️ Stopping someone else’s generation. Deleting a chat now checks who you are before anything is cancelled, so knowing another person’s chat id no longer lets you cut off their reply or title generation on a request that is refused anyway. #27006
- 🚥 Automation limits in chat. Automations that the assistant creates or reschedules on your behalf now respect the same maximum count and minimum interval as the ones you set up yourself, instead of being able to exceed both. #27523, #27121
- ⏲️ Cancelling someone else’s timers. Marking a chat as read now only clears your own pending timers on it, instead of clearing everyone’s, which had let another person’s scheduled prompt be silently cancelled without them being told. #27472
- 🗑️ Deleting a shared folder’s subfolders. Deleting a folder is now limited to its owner or an administrator at every level, so someone with write access to a shared folder can no longer delete a subfolder and take the owner’s chats with it. #27003
- 📕 Tool source shown to people who can only use it. Opening a tool you were given read access to no longer returns its source code, which read access was never meant to include. #27005
- 🎯 Model settings in the list endpoint. Listing models no longer includes each one’s parameters and system prompt for people with read access only, matching what opening a single model already returned. #27004
- 🖌️ Image generation and web search without permission. Turning on image generation or web search through the older request format now checks your permission first, so someone denied those features can no longer trigger them, and the billing that comes with them, by asking for that format. #26703
- 🎗️ Terminal single sign-on tokens. The token forwarded to a terminal server for single sign-on is now taken from your own session on the server rather than from a header the browser supplied, so a caller can no longer send someone else’s token in its place. #26719
- 🫗 Web search results scoped to you. The temporary collections holding a web search’s pages are now tied to the person who ran the search, closing the one place where that scoping was not applied. #26706
- 🧺 Knowledge base cleanup reaching other collections. Tidying up a knowledge base now acts only on files and folders that belong to it, so someone with write access to one knowledge base can no longer delete folders or search data belonging to another. #26722
- ⌛ Searches that could stall the server. A search pattern inside knowledge base commands now runs under a time budget, so a pattern that would take minutes to evaluate can no longer hold up everyone else on the instance. #27471
- 🚫 Disabled terminal servers are refused. A terminal connection an administrator has turned off can no longer be reached by browsing its files, opening a session, or calling its tools, rather than only disappearing from the interface. Commit
- 🧫 Files attached to a shared folder. Adding files to a folder is now refused unless the folder’s owner can read them, and a folder’s files are checked against what its owner can still read before they are used as knowledge in chat, so a collaborator can no longer place files into someone else’s folder or keep serving files the owner has since lost access to. #27464, Commit
- 🧷 Knowledge claimed by a direct connection. Files listed as knowledge on a model supplied by the browser for a direct connection are now filtered against your own access before anything is retrieved, so a crafted request can no longer pull in documents you cannot otherwise open. Commit, #26723
- 🪜 Reaching a restricted model through a shared one. A shared workspace model can no longer be used to reach an underlying model the person could not otherwise use, which previously slipped through when that model had no entry of its own. #26905, #26900
- 🖌️ Shared image checkpoint changes. Only administrators can now change the instance-wide Automatic1111 checkpoint, so an ordinary image generation request no longer switches the image model for everyone. #27244
- 💬 Channel message ownership. Only the author of a channel message, or an administrator, can now edit or delete it, instead of anyone able to post in that channel. #27197
- 🗄️ Chats shared with an administrator. An administrator can now open a chat that was deliberately shared with them even when broad admin access to other people’s chats is turned off, instead of being refused a chat any other recipient could read. #27127
- 📓 Notes in folder knowledge are access checked. Notes attached to a folder are now filtered against your own access before the list reaches the assistant, rather than relying on later checks further along. #26739
- 🧱 Code interpreter module blocking. Modules an administrator has blocked for the code interpreter are now actually blocked, and other imports inside interpreter code work again. #27245
- 📉 Charts in the code interpreter. Code that draws a chart now runs in the default code interpreter setup, instead of failing with a syntax error unless file persistence was turned on. #26800, #26660
- 🎬 Chat action availability. Chat actions can no longer be triggered when they are disabled, not assigned to the model in use, or on a model the caller cannot access, matching the actions the interface actually offers. #27243
- 🗨️ Response text where it was missing. Assistant replies are no longer stored without their text, so copying, exporting, searching and reusing a conversation return the reply instead of nothing. Commit, #26799, #26436
- 🧪 Filter edits that survive a reload. A change a filter makes to a finished response is now saved with the conversation, instead of showing on screen and reverting the next time the chat is opened. #27414, #27017
- 📃 Action functions receive the response text. Running an action on a response now passes the assistant’s text to the function, instead of handing it an empty message. #26798, #26672
- 🍎 Blank messages on Safari. Assistant responses no longer render as empty in Safari and on iPhone and iPad, where a browser painting bug left on-screen messages unpainted. #26805, #26712, #26844
- ➡️ Prompts opened from a link. A prompt passed in through a link that sends automatically now waits for tool servers to finish loading, so external tools are available on that first message instead of the model reporting it has none. Commit, #24176
- 🪟 Tool result prompt submission. Interactive tool result embeds that send a prompt back to the chat work again, showing the confirmation dialog before submitting instead of silently doing nothing. #26914, #26912
- 📻 Live updates in a second tab. Opening Open WebUI again while already connected now joins the new tab to your event stream, so notifications and chat updates reach every open tab instead of only the first one. Commit
- 🔁 Connection recovery on new chats. Chats started from the home page now recover automatically after a dropped connection, such as from mobile backgrounding, a VPN or IP change, or waking from sleep, instead of getting stuck loading until a manual refresh. #26913, #26844
- 🪫 Terminal choice cleared on load. Your selected terminal is no longer dropped while the list of terminals is still loading, so it survives a page refresh. Commit, Commit, Commit, #26775, #26677
- 🔌 Dropped sessions during keepalive. Live connections no longer break on a routine keepalive check, which had cut the session so that anything the server needed to run in your browser failed afterwards, most visibly the code execution tool reporting the client as disconnected on every run. #27553, #27550
- ✂️ Context compaction turn boundaries. Long-conversation compaction now summarizes only completed earlier turns instead of sometimes cutting through the middle of a single turn, keeping the current turn’s tool calls and results intact. #27035, Commit, Commit
- 🪆 Summaries on a direct connection. Summarizing a long conversation on a direct connection can now use the configured summary model rather than being limited to the connection’s own model. #26806
- 🪟 System prompt through compaction. The system message now stays at the front of the conversation when a long chat is summarized, instead of being folded into the summary and lost from that point on. Commit, Commit, Commit, #26713, #26710
- 🧷 Context compaction continuity. After a compaction, the retained recent messages now stay in the prompt on every following turn instead of disappearing after the first, preserving conversational continuity and prompt caching. #27037, Commit, Commit
- 🔟 Context size after tool calls. The context meter and long-conversation compaction now read the size of the latest request rather than adding up every call in a tool loop, and understand the counts reported by Ollama and llama.cpp as well as the OpenAI-style ones, so compaction no longer fires far below its threshold, or never at all, and the usage shown is no longer inflated. Commit, Commit, #27031, #26752, #24410
- 💭 Reasoning that arrives late or empty. Reasoning sent by a provider after the answer has started is now shown in its proper place above the answer rather than appended after it, and reasoning notes carrying nothing no longer open an empty thinking block. Commit, #26687, #26645
- 📐 System prompt lost during tool calls. A model’s system prompt now stays in place through every round of tool calls, instead of being dropped after the first one and, with memories enabled, replaced by the memory block alone. #26857, #26836
- 🪶 Memories from structured replies. A reply delivered as structured output is now read when memories are reviewed after a turn, so nothing worth remembering is skipped just because of how the answer arrived. Commit, #26705, #26651
- 🎲 Stable skill ordering. Skills available to a model are now listed in the same order on every request, instead of shuffling between requests and quietly defeating prompt caching. Commit, #26986
- 🛑 Stopping an answer the moment it starts. Each answer in a chat now carries its own task identifier from the first event onward, so stopping one immediately after sending no longer misses. Commit
- ⏸️ Deleting while a reply is being written. The delete control is now hidden on messages while a response is generating or a task is running, so a conversation can no longer be left with the finished reply detached from the messages before it. Commit, #26668
- 🎁 Feedback while a download is prepared. Downloading a file or folder from the terminal now tells you it is being prepared, will not start the same archive twice if you click again, and reports a failure instead of quietly giving up or leaving a preview spinning. #27421, #27055
- 📥 Moving an archived chat into a folder. Moving an archived chat into a folder now takes it out of the archive so it appears there, and the folder’s contents refresh straight away after a move from the menu. #27485, #27484
- 📜 Chats past the first sixty in a folder. Folder listings now page through every chat instead of stopping at a fixed limit, so older chats no longer appear to vanish from a folder once it grows past sixty. #26786, Commit
- 📌 Sidebar highlight follows the open chat. The sidebar no longer keeps a chat highlighted after you move to another page, so deleting or archiving it there no longer throws you back to a new chat, and cloning no longer leaves two chats looking selected. #26977
- 🔀 Sidebar ordering during replies. Background updates such as follow-up suggestions, sources, and status no longer bump a chat to the top of the sidebar or change its last-updated time, and neither does saving a chat’s variables or settings, nor the automatic title generation on a new chat. Commit, Commit
- 🖱️ One hover preview at a time. Moving between chats in the sidebar, or between avatars in the admin user list, channel messages and member lists, no longer leaves an earlier preview open behind the new one. #27549, #27548, #27578, #27577
- ✨ Folder lists no longer flash. Clicking a folder title in the sidebar no longer empties the chat lists of your expanded folders for a moment before they reappear. #27535, #27533
- 🫧 Flickering sidebar rows. Moving the pointer across a chat in the sidebar no longer makes its title and timestamp flicker in and out, or draw the timestamp underneath the action buttons. #27474, #27473
- ⭐ Rating scale in multi-model replies. The rating scale in the feedback panel is no longer cut off when several models answer side by side, so every score can be picked. #26846
- 🧑🤝🧑 Duplicate models side by side. Adding the same model twice in a side-by-side chat now keeps each column’s own answer after a reload, instead of every column collapsing onto the first one. #26980
- ⬅️ Back button after opening admin or workspace. Going back in the browser now returns you to the page you came from, instead of being pushed forward again to where you just were. #27478, #27477
- 🎛️ Typing a top_k value. The top_k box in advanced parameters now accepts whole numbers up to its limit and rejects anything else, instead of letting the slider and the box disagree over what is allowed. Commit, #26669
- 🌙 Date pickers in dark mode. The calendar and clock icons on date and time fields are now visible in dark mode, across the calendar, automation schedules, account settings and analytics. #27275, #27274
- 🪞 Settings content stays inside the window. Long chat titles in Archived Chats now shorten with the full title on hover, and the admin analytics tables and chart no longer stretch past the edge of the settings window. #27306, #27305, #27329
- 🔗 Settings links that open in place. A link to a settings tab now opens it without a page refresh, and the Add Terminal button in the terminal menu goes straight to the Integrations tab instead of flashing the admin panel and doing nothing. #27552, #27551
- 🎰 Model choice on a fresh chat. Starting a new chat now falls back to your default model when the previous selection is no longer available, instead of leaving the picker empty, while a model named in the link still wins. Commit, #26697
- 📱 Model selector on small screens. The model list now stays fully on screen and sizes itself to the space available, instead of running past the edge or hiding behind the on-screen keyboard on phones. Commit, Commit, Commit
- 📲 Sidebar stays open over the calendar. Opening the calendar from the account menu on a phone now closes the sidebar, as every other entry in that menu already did. #26979
- 🗓️ Automation dialog on narrow screens. The buttons along the bottom of the automation dialog now sit on their own row on a phone, instead of the schedule and model pickers wrapping and pushing Cancel into the middle. #27027
- 📐 Input menu with keyboard open. The message input’s attachment menu now stays on screen and resizes to fit when the on-screen keyboard is open on mobile, instead of running off the edge. Commit
- 🎈 Dropdowns that follow their content. A menu now stays in place as its contents grow or shrink, instead of running past the edge of the screen when a submenu swaps in taller content, and no longer bounces as it opens. #27460, #27458
- 🧾 Attachment menus load once. Opening a submenu of the attachment menu now requests its list a single time instead of twice. #27461, #27459
- 🔦 Chat search on PostgreSQL. Searching your chats now finds matches in current conversations on PostgreSQL setups, instead of only matching chats still stored in the older format. Commit
- 🧲 Search quality with prefix-based embedding models. Memories, knowledge base descriptions and searches against an external vector database now carry the query and content markers your embedding model expects, so results are no longer quietly worse than they should be on models that rely on them. Commit, #26958, #26353
- 🥄 Counting matches in knowledge base commands. Piping text into a search inside knowledge base commands now honours the count and filenames-only flags, instead of returning the matching lines regardless. #26721, #26715
- 🔍 Knowledge base file search. Searching inside knowledge base files now returns matching lines with correct line numbers, and patterns that list alternatives separated by a pipe find matches instead of silently returning none. #27249, Commit, Commit, #26795, #26781, #26744
- 🖨️ PDF text recognition. The text recognition package is now included again, so the application starts and PDFs with image text extraction enabled upload correctly instead of failing. #26851, #26646, #26994
- 🧿 Mistral OCR on a stock install. Extracting documents with Mistral OCR now works out of the box, instead of failing on a missing name resolution library that the code assumed was present. #27440
- 📧 Outlook message uploads. Uploading a .msg email now works, where it previously failed because the package it relied on could not be installed alongside the rest of the application at all. #26704, #26690
- 🖇️ Uploads with PaddleOCR-VL selected. With PaddleOCR-VL chosen as the document loader, only PDFs and images now go to it and everything else falls back to the usual handling, so text, markdown, spreadsheet and Word files index instead of being rejected. #27529, #24988, #26759
- 🪙 Documents containing special tokens. Splitting text by tokens no longer fails when the content contains reserved marker sequences, so those pages and files can be fetched and added to a knowledge base. Commit, #27094
- 📚 Knowledge base upload reliability. Adding a file directly to a knowledge base now finishes processing and linking the file before reporting success, so uploaded files are reliably searchable. Commit
- 🛠️ Web loader settings from the admin panel. The web loader picked in admin settings is now actually used, along with its certificate checking, request pacing and proxy settings, so instances that fetch pages through an external loader work again instead of trying to reach the internet directly with whatever was configured at startup. #26749, #26747, Commit, #27083, #27025, #27061
- 🚧 Quoted entries in the web fetch filter list. Stray quote marks around a filter entry, which Docker Compose passes through literally, no longer turn the list into one that blocks every web address. #26910, #26908
- 🌐 Web fetching with certain plugins installed. Fetching a web page and loading web search results work again on instances where a tool or function pulls in a replacement networking library, which previously made every fetch fail and return nothing. #26796, #26791
- 📢 Web search failures explained. When a search finds pages but cannot store them, the chat now says what went wrong and points at the document settings, instead of reporting sites searched and then no sources found. #26883
- 🕸️ Mixed web page extraction. Fetching several web pages at once now reads each one according to its own format, instead of applying the first page’s format to the whole batch and garbling the rest. #27367
- 🧯 Leftover browser sessions on web fetches. Fetching pages through a remote Playwright server now closes each page and the browser even when a page times out or the search is abandoned partway, instead of leaving sessions open and slowing every later search until that server was restarted. #27526, #25880
- 🖇️ Sign-in profile pictures fetched safely. The profile picture pulled in when someone signs in through a provider is now fetched through the same protected path as other outbound requests, so a host that changes its address between the check and the fetch can no longer point it at an internal service, taking the forwarded sign-in token with it. #26699
- 🪃 Backslashes in terminal proxy paths. A request to the terminal proxy containing a backslash is now refused, closing a way to smuggle directory traversal past the path check to an upstream that treats it as a separator. #27198
- 🧱 Internal addresses disguised as public ones. A web address that hides an internal target inside an IPv6 address, through the mapped, 6to4, Teredo or NAT64 forms, is now recognised and refused like any other internal address. Commit
- 🪤 Tighter checks when a page is fetched. Every request a fetched page makes is now checked against the address rules rather than only the page itself, each hop of a redirect is checked in turn, and background workers and socket connections the page tries to open are refused. Commit, #27042, #27008
- 🐢 Dropped pages when fetches are paced. Pages fetched through Firecrawl, Tavily, Microsoft Web IQ or Playwright are no longer discarded whenever the loader has to pause between requests, which quietly lost any page following close behind another and sometimes blamed it on a failed security check. #27528, #26079
- 🎙️ Dictation repeating earlier speech. Dictating into the message box no longer re-inserts everything you said in previous recordings, and cancelling a recording no longer inserts the text anyway. #26793, #26784
- 🧩 Order of long transcriptions. A long recording split into pieces for transcription is now reassembled in the order it was spoken, instead of sections sometimes appearing out of sequence in the transcript and everything read from it. #27417, #27143
- 🔊 Text-to-speech reliability. Text-to-speech playback and other streamed responses no longer intermittently cut out partway through when several requests run at once. #26924, #26922
- 🧮 Anthropic usage reporting. Responses from the Anthropic-compatible API now report accurate input and output token counts, pass through cache and server tool figures where the provider gives them, and leave the input count out entirely rather than reporting zero when it is unknown. Commit, Commit, Commit, Commit, Commit, Commit, #26790, #27293, Docs:#1328
- 📨 Non-streaming requests to strict providers. A request that is not streaming no longer carries the streaming-only usage option, which some providers reject outright.
- 🪝 Tool calls with structured arguments. A provider that sends a tool call’s arguments as an object, or as nothing at all, no longer breaks the reply partway through. #27195
- 🧬 Shared pipe model tool calls. Non-admin users of a shared model built on a pipe or manifold model no longer see the response silently stop right after a tool call. #26906, #26900
- 🧑🔧 Startup as an arbitrary user. Running the image as a non-root account, as OpenShift and similar setups do, no longer fills the boot log with permission errors while it writes its own icons and manifest. #26664, #26662
- 🩹 Startup with an ownerless tool or function. A tool or function left without an owner no longer prevents the application from starting, which had blocked all chat responses until it was removed. #26850, #26843
- 🏷️ Model names containing a connection prefix. A prefix set on a connection is now removed only from the front of the model name, so a model whose own name contains that text is no longer mangled before the request is sent. Commit
- 🦙 Newly pulled Ollama models. Sending a message to a model that was pulled after the list was last built now refreshes the list and proceeds, instead of reporting the model as not found. Commit, #27353
- 🗑️ Deleting a model from the selector. Removing a workspace model from the model selector menu now deletes just that model and leaves the underlying one in place, instead of failing with a not found error. #26819
- 🔑 Connecting a remote MCP server over OAuth. Setting up a remote MCP server now reports plainly when its sign-in details cannot be discovered, rather than saving an unusable connection that failed with a server error the moment you tried to authorise it. #26654, #26647
- 🪢 Tool servers with cross-referencing types. A tool server whose description defines types that refer to each other now loads its tools instead of failing outright, so the integration appears in model and tool selection again. #27413, #27239
- 👥 Previewing what someone can use. The preview of a person’s access now includes the models, knowledge bases and tools they own, not just the ones shared with them. Commit, #27423, #27407
- 🧰 Model editor loading. The model editor no longer fails to open when its tool list can’t be loaded, falling back gracefully instead. Commit
- 🗃️ Milvus Lite collection creation. Setting up collections now succeeds on embedded Milvus Lite, which previously could fail while creating the resource index. #26911
- 🧽 Milvus log noise. Instances backed by Milvus no longer fill their logs with deprecation warnings while indexing and retrieving, and keep working with future PyMilvus releases that drop the old interface entirely. #27521, #26978
- 🚏 Stray terminal containers. Terminal orchestrator connections that use a policy now send every request through that policy, so each person no longer ends up with a second unintended container alongside the intended one. #26945, Commit
- 🔦 Connections on hardened instances. With the admin access bypass turned off, a connection that has no access grants yet is now reachable by administrators again, instead of being hidden from everyone including the admin who created it. #27581, #27580, #27064
- ♻️ Connection changes take effect immediately. Saving connection settings now refreshes the model list straight away, instead of leaving the previous models in place until the server was restarted.
- 🚫 Disabled OpenAI connections are enforced. Turning off the OpenAI API now blocks chat requests to it and clears its models, rather than only hiding it from the interface.
- 🪛 Deleting an Ollama connection. Removing an Ollama connection now saves straight away, instead of reappearing until the Ollama API switch was toggled afterwards. #27483, #27482
- 🧹 Orphaned sessions get cleaned up. The instance that reaps sessions left behind by a crashed worker now keeps trying if another instance holds the job, rather than one instance giving up for good and leaving stale sessions to accumulate, and the lock it uses can no longer be released or renewed by an instance that does not hold it. Commit, Commit
- 🧊 Redis cluster connections. A deployment using Redis in cluster mode is no longer handed a connection built for a single server, or the reverse, when both point at the same address. Commit
- 🚏 Stopping a reply when Redis is configured. The stop button now actually halts generation on Redis-backed deployments, where the listener that carries stop requests between instances quietly died after a few idle seconds and left tokens streaming on, and a new “REDIS_SOCKET_TIMEOUT” setting controls that timeout. #27104, #26779
- 🛟 Redis failover on timeouts. A Redis connection that times out now retries against a freshly resolved primary instead of failing, so Sentinel setups recover from a failover rather than erroring out. Commit, #27210
- 👣 First sign-in through a trusted header. Two requests arriving together for someone signing in for the first time through a trusted header no longer create two accounts for the same person, and the database now refuses a second account for an address that already exists, whatever its capitalisation. Commit, Commit, #27571, #27117
- 🔧 Sign-on settings from environment variables. Single sign-on settings supplied through environment variables are no longer overridden by stale values saved at first startup, so changing them takes effect. #26928, #26917
- 🎫 Expired identity tokens sent to tools. A sign-in session is now refreshed before the earliest of its tokens expires, so tools and pipes that forward your identity no longer hand a downstream service a token it rejects. #27520, #27066
- 🎫 Sign-in tokens that never expire. A provider that returns no expiry and no way to refresh is now taken at its word, instead of being given an invented one-hour lifetime that left the session unusable afterwards. Commit, #26802, #26141
- 🔓 Single sign-on after a key rotation. Signing in with OIDC now recovers when the provider rotates its signing key, refreshing the cached keys and retrying instead of failing with an invalid credentials error. #27310, #26407
- 🔑 Signing in after a session expires. An expired session now cleanly returns you to the sign-in page and back to where you were afterwards, instead of bouncing you away from the sign-in page or leaving a stale session behind. Commit, Commit, #26751, #26731
- 🫥 Temporary chats and channels write nothing. Generating or editing an image and status updates in a temporary chat or a channel message no longer try to save themselves against a conversation that was never stored, and the task list tools are no longer offered there at all rather than being offered and then failing. Commit, Commit, Commit, Commit, #27432
- 🎞️ Artifacts panel reopening itself. The artifacts panel now opens once when a finished block is detected, so closing it partway through a reply no longer sees it forced back open on every word that follows. Commit, #27399
- 🏞️ Images returned by a tool. Images a tool produces are now passed to the model in a form the OpenAI-compatible providers accept, so it can actually look at them instead of receiving a result it cannot read. Commit
- 🖼️ External message images. Images hosted on other sites and referenced in a message now display inline instead of being replaced with a placeholder. Commit
- 🔣 Names containing a vertical bar. What you insert with the at sign or a slash is now recorded by the key you typed rather than guessed from its name, so a prompt or model whose name contains a vertical bar is no longer mistaken for a skill. Commit
- 〰️ Text above a collapsible block. A line written directly above a collapsible section is no longer turned into a large heading, and the section itself still renders as a collapsible widget rather than leaking its markup. Commit, #27148, #27001
- ✳️ Asterisks in the message input. Wrapping a word in asterisks no longer silently turns it italic and swallows the asterisks, so your prompt reaches the model exactly as you typed it. Commit
- 📶 Reconnect warnings on mobile. Switching back to Open WebUI after using another app no longer flashes a connection lost warning while the tab wakes up and reconnects on its own. Commit
- 🧭 Sidebar access from the automation editor. Opening an automation on a phone no longer hides the sidebar button, so you can move around without leaving the editor first.
- 🔣 Chats containing unusual characters. Broken character sequences are now cleaned out of text before it is stored, so a conversation that picked one up still saves and still opens instead of failing to load. Commit, #27201, #27081
- 📛 Failures after a tool call. A reply that fails while continuing after a tool call or a code interpreter run now says so, instead of stopping mid-answer with nothing to explain why. Commit, #27426, #27411
- 💾 Errors kept after reloading. An error that ends a streamed reply is now saved to the conversation, so it is still there when you reload instead of disappearing. #27365, #27074
- 💬 Readable error messages. Errors in a conversation now always show readable text that wraps instead of running off the edge, including errors that arrive wrapped inside another error.
- 🪝 Blocked webhook targets look like failures. A webhook pointing at an address that is not publicly reachable is now skipped with a short warning, instead of an error and a full traceback that read like the server crashing on startup. Commit, #26975
- 🕵️ Values printed in error logs. A failure no longer prints the contents of nearby variables alongside its traceback, which could put keys and message content into the logs, and a new “LOGURU_DIAGNOSE” setting turns that detail back on for debugging. Commit, #26814
- 🪵 Empty audit exclusion list. Clearing the list of paths excluded from audit logging no longer switches off auditing altogether, so requests are recorded as intended. #27370, Commit
- 🗒️ Readable audit log bodies. Audit logs that record response bodies now store them as readable text instead of compressed data, so entries are legible whenever a browser requested compression. #27369
- 👍 Rating in feedback events. Events sent when someone rates a response now carry the rating that was given, instead of reporting it as empty. Commit, #26840
- ⏱️ Accurate request timing header. The processing time reported on each response now includes fractions of a second instead of rounding everything under a second down to zero. #27368
- 📋 Provider rejection logging. When a model provider rejects a request, the reason it gave is now recorded in the server logs, so administrators can diagnose failures without querying the provider directly. #27238, #27237, #26253
- ⏳ Faster licensed startup. Instances with a license key no longer wait on the license server during startup, so the app becomes ready to serve traffic without that delay. Commit, Commit
- 📅 Calendar invitation responses. Whether you have accepted an invitation is now decided by your own response rather than by whoever created the event, and invitations you decline disappear from your calendar. #27007
- 🗓️ Schedules written by hand. A recurrence rule is now read the same way whether it is written in upper or lower case, a start date in the rule is respected, second-by-second rules are understood, and a rule that cannot be supported is refused with a clear message instead of behaving unpredictably. Commit, Commit, #27470
- 📅 One calendar event stalling the server. Working out when a repeating event happens next now walks its rule once rather than re-counting from the beginning for every occurrence, so an event repeating every minute from an old start date can no longer occupy the server for everyone. #27468
- ⏰ Recurring automation scheduling. Automations that repeat every few minutes or hours now align to the clock and are no longer wrongly rejected as having no upcoming runs when the server clock is ahead of your timezone. Commit, #26954
Changed
- ⚠️ Database Migrations: This release includes database schema changes; we strongly recommend backing up your database and all associated data before upgrading in production environments. If you are running a multi-worker, multi-server, or load-balanced deployment, all instances must be updated simultaneously, rolling updates are not supported and will cause application failures due to schema incompatibility.
- 🛠️ Admin settings moved into settings. Admin settings and the analytics dashboard are no longer separate pages and now open alongside your personal settings in the settings window, under their own Admin section, with the old links redirecting there. Commit, Commit, Commit
- 📁 Workspace actions in one menu. Creating, importing, and exporting workspace items no longer have their own buttons on each page and are now reached from a single Create menu in the workspace header, with creating a prompt or knowledge base opening a dialog rather than a separate page. Commit, Commit, Commit, Commit
- 🔐 Administrators no longer reach other people’s automations. Viewing, editing, running and deleting an automation is now limited to the person who created it, so an administrator with a link to someone else’s automation is refused rather than allowed through. Commit
- 🏷️ Shorter titles without emojis. Automatically generated titles for chats and notes are now two to four words and no longer include an emoji, and anyone who prefers the old style can restore it by editing the title generation prompt in admin settings. Commit, Commit
- 🗂️ Archived chats moved to settings. The Archived Chats shortcut is no longer in the user menu, and your archived conversations are now reached through Settings, where they can also be searched and sorted. Commit, Commit
- 🔢 Usage now reports the latest call separately. In a response’s usage block, “prompt_tokens” and “completion_tokens” now carry the counts from the most recent model call rather than the running total, while “input_tokens”, “output_tokens” and “total_tokens” stay cumulative, so anything reading the first pair for billing should read the second set instead. Commit, #27031
- 🧳 The “python-jose” library is no longer installed. Nothing in Open WebUI imports it anymore, so it and the two packages it pulled in have been dropped from the image, and any tool or function that imports it directly now needs to install it itself. #27444
- 📦 Storage emulator no longer bundled. The optional Google Cloud Storage emulator is no longer installed as part of the full package, so anyone who relied on it for local storage testing now needs to install “gcp-storage-emulator” themselves. Commit