What open-webui/open-webui shipped
Written by FoxPlug from public releases; not affiliated with Open WebUI. An automatic summary of the public release, pull request and commit data of github.com/open-webui/open-webui. Open WebUI did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Week of September 21, 2026
What shipped
- Admins can no longer bypass chat access restrictions through direct API requests when ENABLE_ADMIN_CHAT_ACCESS is disabled. Pull request #31416
- Model uploads and downloads now respect custom headers and authentication types for Ollama connections. Pull request #31490
- Manage Ollama dialog now applies custom headers and authentication types when listing, pulling, creating, copying and deleting models. Pull request #31489
- Tool approval mode now shows approval cards for all tool calls in a single turn, not just the first one. Pull request #31315
- File uploads and hybrid search now work with Qdrant strict mode by paginating reads in chunks of 1000 points. Pull request #31461
- Tavily web search now respects a configurable search depth setting instead of always using the default. Pull request #31308
- Searching automations and filtering models by non-ASCII words now works correctly on PostgreSQL with the default settings. Pull request #31423
- Chat header, folder, note and action menus now close before their dialogs open, so first clicks inside dialogs work. Pull request #31496
- The max_tokens parameter sent through the API is now correctly passed to Ollama models as output length. Pull request #31437
Why it matters
This week focused on fixing access control and authentication issues that affected API security and multi-connection setups, plus resolving approval workflows and database compatibility problems. Several fixes address tool handling and parameter passing that were silently failing in production setups.
Changelog entry
- Security: Enforce chat access restrictions for admins through API requests Pull request #31416
- Fix: Model upload and download respect connection custom headers and auth Pull request #31490
- Fix: Manage Ollama applies custom headers and authentication types Pull request #31489
- Fix: Show approval cards for all tool calls in multi-call turns Pull request #31315
- Fix: File uploads and hybrid search work with Qdrant strict mode Pull request #31461
- Feature: Add configurable Tavily search depth setting Pull request #31308
- Fix: Non-ASCII search queries work on PostgreSQL with default settings Pull request #31423
- Fix: max_tokens API parameter now reaches Ollama models Pull request #31437
- Fix: Dialog menus close before opening, first clicks work correctly Pull request #31496
- Fix: Spacing preserved in reasoning model answers after thinking block Pull request #31438
- Fix: Backslashes in uploaded HTML files handled correctly Pull request #31450
Weekly digest: access control, authentication, tool approvals, Qdrant compatibility, and API parameter handling all improved. 10 fixes for production stability.