Files
open-webui/backend/open_webui/utils
sasidhar 61f49ff580 fix: ensure trusted email header matches logged-in user
When using trusted email header authentication, verify that the logged-in user's
email matches the value in the header. This prevents session conflicts when the
OAuth server changes the authenticated user.

- Move trusted email verification after user existence check
- Raise 401 if email mismatch is detected
- Only perform verification when WEBUI_AUTH_TRUSTED_EMAIL_HEADER is enabled
2025-06-08 14:16:10 +05:30
..
2025-02-08 01:10:18 +07:00
2025-03-11 18:55:30 +00:00
2025-01-15 23:01:43 -08:00
2025-04-23 00:06:44 +09:00
2025-05-10 19:00:01 +04:00
2025-05-28 01:41:49 +04:00
2025-05-28 01:34:53 +04:00
2025-05-29 02:36:33 +04:00
2025-05-29 23:32:14 +04:00
2025-05-28 01:42:42 +04:00
2025-04-12 16:35:11 -07:00
2024-11-30 23:36:30 -08:00
2025-05-23 02:48:31 +04:00
2025-05-27 00:20:47 +04:00
2025-02-16 00:11:18 -08:00