Skip to content

Flexion - Custom Implementations Tracker - #14

Draft
lgarceau768 wants to merge 55 commits into
devfrom
flex
Draft

lgarceau768 wants to merge 55 commits into
devfrom
flex

Conversation

@lgarceau768

@lgarceau768 lgarceau768 commented Jan 24, 2026 •

Copy link
Copy Markdown

This PR is to track the custom implementations developers have made to OWUI.

This PR can remain open

Google Oauth Groups Access Control: #13

Flexion Custom Functions (Gemini Support Pipe): #15 (soon to be added)

FlexChat Rebrand: #19 (soon to be added)

Flexion Specific Readme: #17 (soon to be added)

tjbck and others added 12 commits November 23, 2025 22:10
* refac

* fix: python pip install dep issue

* Merge pull request open-webui#20085 from joaoback/patch-19

Update translation.json (pt-BR)

* fix/refac: stt default content type

* fix/refac: temp chat image handling

* fix/refac: image action button

* chore: bump

---------

Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com>
@lgarceau768 lgarceau768 self-assigned this Jan 24, 2026
@lgarceau768 lgarceau768 added the DO NOT MERGE do not merge label Jan 24, 2026
@lgarceau768 lgarceau768 changed the title Flex - Custom Implementations Tracker Flexion - Custom Implementations Tracker Jan 24, 2026
tjbck and others added 11 commits April 21, 2026 03:56
* refac

* fix: remove reactive label from onDestroy in Markdown

* Update fi-FI translation.json (open-webui#24010)

Added missing translations.

* refac

* i18n: update ko-KR translations (conflict solved) (open-webui#23949)

* i18n: update ko-KR translations

* i18n: fix missing ko-KR translations and reviewed pr-bot recommendation

* i18n: add pt-BR translations for newly added UI items and consistency pass (open-webui#23954)

New **pt-BR** translations for items introduced in the latest releases, plus a consistency/quality pass across existing strings (grammar, tone, capitalization, pluralization). Placeholders and hotkeys preserved. No logic changes.

* fix(utils): Switch throttle decorator to async (open-webui#23979)

After migration to async db operations, the throttle decorator also
needs to support async. Since the decorator is only used for async funcs
now, we can just switch it to async instead of supporting sync and async
at the same time.

Signed-off-by: Adam Tao <tcx4c70@gmail.com>

* refac

* refac

* refac

* refac

* feat: add PaddleOCR-vl loader support and implement retrieval router infrastructure (open-webui#23945)

Co-authored-by: Tim Baek <tim@openwebui.com>
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com>

* refac

* refac

* Enhance image loading performance by adding preload links and setting loading attributes for logos in app.html (open-webui#24011)

* feat(ui): add citation source overflow badge (open-webui#23918)

* refac

* i18n: enhance and expand Dutch language translations (open-webui#23944)

* refac

* refac

* refac

* perf: redirect default model profile image to canonical static URL (open-webui#24015)

- Return 302 to /static/favicon.png instead of streaming the same PNG per
  model id so browsers can cache one asset for default avatars.
- Validate stored /static/ paths with decode, normpath, and /static
  prefix checks; invalid paths fall back to favicon.

Made-with: Cursor

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* feat: enhance RichTextInput configuration to prevent duplicate extensions when rich text is enabled (open-webui#24009)

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* changelog (open-webui#24072)

* refactor(firecrawl): use v2 API directly (open-webui#23934)

Co-authored-by: Tim Baek <tim@openwebui.com>

* chore: bump

* perf(chats): drop redundant db.refresh after commit in update_chat_by_id (open-webui#24024)

The chat table has no computed columns (no DEFAULT, SERIAL/IDENTITY,
or TRIGGER that populate server-side values on UPDATE), and every
column modified by update_chat_by_id is set explicitly from Python
values earlier in the function. db.refresh therefore issues a SELECT
that replaces those just-written Python values with the round-tripped
database representation of the same values, which is a no-op for
functional purposes but pulls the entire chat.chat JSON blob back over
the network and through the driver's JSON decoder.

On large, active chats where chat.chat can reach tens of megabytes,
skipping the refresh measurably reduces latency and eliminates one
~JSON-sized transient allocation per write.

* refac

* chore: format

* chore: i18n

* refac

---------

Signed-off-by: Adam Tao <tcx4c70@gmail.com>
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com>
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com>
Co-authored-by: Teay <pythontogoplease@gmail.com>
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com>
Co-authored-by: tcx4c70 <tcx4c70@gmail.com>
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com>
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com>
Co-authored-by: RomualdYT <romuald@gameurnews.fr>
Co-authored-by: Lucas <lucas@vanosenbruggen.com>
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com>
Co-authored-by: Constantine <Runixer@gmail.com>
* refac

* refac

* refac

* Merge pull request open-webui#24356 from Classic298/patch-1

doc/chore: Update SECURITY.md

* refac

* refac

* refac

* refac

* refac

* chore: Update SECURITY.md (open-webui#24363)

* Update SECURITY.md

* Update SECURITY.md

* Implement asynchronous database ping for health checks (open-webui#24380)

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* fix: prevent STT from blocking the uvicorn event loop (open-webui#24338)

The transcription endpoint was async but called the synchronous transcribe() function directly, blocking the single-threaded uvicorn event loop for the entire duration of inference. This caused all HTTP and WebSocket connections to stall for every user on the instance during STT processing.

- Add asyncio import

- Use async UploadFile.read() instead of synchronous file.file.read()

- Offload the blocking transcribe() call via asyncio.to_thread()

Closes open-webui#24169

* refac

* fix: open file content in new window when clicking file name in FileItemModal (open-webui#24125)

Previously, clicking the file name link did not open the file content
because the condition checked `!isPDF && item.url`, which failed for
`type === 'file'` items that use an ID-based URL path.

Update the condition to trigger on `item.type === 'file' || item.url`,
and resolve the correct URL by extracting `fileId` from `item.id` or
`item.tempId` instead of using `item.url` directly as the file
identifier.

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* Refactor file processing to use asyncio for transcribing, improving concurrency. (open-webui#24379)

* Apply validate_profile_image_url to ChannelWebhookForm.profile_image_url (open-webui#24370)

* refac

* refac

* refac

* refac

* refac

* fix: stream GET /chats/all to prevent OOM on large chat histories (open-webui#24461)

Convert the /chats/all endpoint from loading all user chats into memory
at once to a streaming NDJSON response that fetches chats in batches of
100. This prevents Out-of-Memory crashes for users with large chat
histories.

Backend: Added async generator that paginates through chats with
short-lived DB sessions per batch (critical for SQLite lock release).

Frontend: Updated getAllChats to consume the NDJSON stream via
ReadableStream reader, accumulating results for the export file.

Ref: open-webui#22206

* refac

* refac

* refac

* refac

* refac

* refac

* Enhance CommitSessionMiddleware to allow health probes to bypass session management, ensuring faster and more reliable responses. (open-webui#24384)

* refac

* refac

* refac

* refac

* refac

* refac

* refac: apply DOMPurify to excel and office HTML render assignments (open-webui#24468)

* I18n/improve chinese translation (open-webui#24194)

* i18n: improve zh-CN translation

* i18n: improve zh-TW translation

* perf(prompts): filter prompt list in SQL instead of N+1 has_access loop (open-webui#24288)

get_prompts_by_user_id used to fetch every active prompt (with users +
all access grants), then call AccessGrants.has_access() once per prompt
that the user did not own. With 600+ prompts this issued ~600 extra
round-trips per request and explained the multi-second delay reported in
the GET /api/v1/prompts and /api/v1/prompts/tags endpoints for non-admin
users.

Push the access check into a single SQL query via the existing
AccessGrants.has_permission_filter (EXISTS subquery), so only accessible
rows come back from the DB. Users and access grants for the surviving
rows are still batch-fetched, no N+1 anywhere on this path.

Co-authored-by: Claude <noreply@anthropic.com>

* refac

* refac

* Update catalan translation.json (open-webui#24174)

* perf(prompts): make /tags fetch only the tags column with SQL access filter (open-webui#24287)

Non-admin GET /api/v1/prompts/tags went through get_prompts_by_user_id,
which loaded every active prompt with its full content/data/meta plus
owner records and all access grants, then ran one has_access query per
prompt that wasn't owned by the caller - all so the endpoint could
collapse the result to a sorted tag list. With 600 prompts this took
several seconds while the admin path (a single SELECT) returned in <1s.

Add Prompts.get_tags_by_user_id which selects only the tags column and
applies the same EXISTS-based access filter used by /list. Also tighten
the admin get_tags to project just the tags column instead of full rows.
The endpoint is now one DB query (plus one for groups), no row hydration,
no N+1.

Co-authored-by: Claude <noreply@anthropic.com>

* refac

* refac

* i18n: Add Tagalog (Filipino) translation (open-webui#24254)

Signed-off-by: Adam Tao <tcx4c70@gmail.com>
Co-authored-by: Tim Baek <tim@openwebui.com>
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com>
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com>
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com>
Co-authored-by: Teay <pythontogoplease@gmail.com>
Co-authored-by: tcx4c70 <tcx4c70@gmail.com>
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com>
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com>
Co-authored-by: RomualdYT <romuald@gameurnews.fr>
Co-authored-by: Lucas <lucas@vanosenbruggen.com>
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com>
Co-authored-by: Constantine <Runixer@gmail.com>

* refac

* refac

* refac

* style(env): satisfy ruff (datetime alias, line length, identity check) (open-webui#24118)

* Korean Translation Update (open-webui#24087)

Signed-off-by: Adam Tao <tcx4c70@gmail.com>
Co-authored-by: Tim Baek <tim@openwebui.com>
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com>
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com>
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com>
Co-authored-by: Teay <pythontogoplease@gmail.com>
Co-authored-by: tcx4c70 <tcx4c70@gmail.com>
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com>
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com>
Co-authored-by: RomualdYT <romuald@gameurnews.fr>
Co-authored-by: Lucas <lucas@vanosenbruggen.com>
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com>
Co-authored-by: Constantine <Runixer@gmail.com>

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* feat: brave search llm context

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* fix(mcp): remove asyncio.wait_for/shield from MCP cleanup in chat handler (open-webui#24105)

asyncio.wait_for() and asyncio.shield() create new asyncio Tasks which
violate anyio cancel-scope task-ownership rules. The MCPClient's
exit_stack contains anyio resources (streamable_http transport) that
use anyio cancel scopes. When exited from a different task, anyio raises
'Attempted to exit a cancel scope that isn't the current task's current
cancel scope' as a BaseException.

This BaseException propagates through the finally block, discards the
completed response return value, and surfaces as a 500 Internal Server
Error / 'No response returned.' - silently swallowing successful MCP
tool calls and blocking the chat endpoint.

Fix: call client.disconnect() directly in a simple loop. MCPClient.disconnect()
already catches BaseException internally (see prior commit), so no
wrapper is needed.

Signed-off-by: Adam Tao <tcx4c70@gmail.com>
Co-authored-by: Tim Baek <tim@openwebui.com>
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com>
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com>
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com>
Co-authored-by: Teay <pythontogoplease@gmail.com>
Co-authored-by: tcx4c70 <tcx4c70@gmail.com>
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com>
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com>
Co-authored-by: RomualdYT <romuald@gameurnews.fr>
Co-authored-by: Lucas <lucas@vanosenbruggen.com>
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com>
Co-authored-by: Constantine <Runixer@gmail.com>
Co-authored-by: Circe (Claude Code Sonnet 4.6) <circe@athena-council.org>
Co-authored-by: Claude <noreply@anthropic.com>

* fix:image url validation and signout post (open-webui#24420)

* refac(routers): reject external URLs in profile/model image handlers

* refac(ui): centralize image URL validation in safeImageUrl helper

* refac(auths): make signout POST-only

* refac: gate external profile image redirect behind ENABLE_PROFILE_IMAGE_URL_FORWARDING

Restore the 302 redirect for external http(s) profile image URLs in
the user and model profile-image endpoints, but gate it behind a new
ENABLE_PROFILE_IMAGE_URL_FORWARDING env flag (default: True).

Existing deployments that rely on external profile image forwarding
continue to work unchanged.  Operators who want to suppress the
redirect (to prevent client-side IP/UA/Referer leaks) can set the
flag to False.

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* refac

* chore: format

* chore: changelog (open-webui#24358)

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* changelog

* doc: changelog

* refac

* refac

* refac

* chore: format

* refac

---------

Signed-off-by: Adam Tao <tcx4c70@gmail.com>
Co-authored-by: Classic298 <27028174+Classic298@users.noreply.github.com>
Co-authored-by: Jacob Leksan <63938553+jmleksan@users.noreply.github.com>
Co-authored-by: Athanasios Oikonomou <athoik@gmail.com>
Co-authored-by: Shirasawa <764798966@qq.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Aleix Dorca <aleixdorca@mac.com>
Co-authored-by: Vincent Agra <agravj007@gmail.com>
Co-authored-by: joaoback <156559121+joaoback@users.noreply.github.com>
Co-authored-by: Algorithm5838 <108630393+Algorithm5838@users.noreply.github.com>
Co-authored-by: Kylapaallikko <Kylapaallikko@users.noreply.github.com>
Co-authored-by: Teay <pythontogoplease@gmail.com>
Co-authored-by: tcx4c70 <tcx4c70@gmail.com>
Co-authored-by: goodbey857 <76645482+goodbey857@users.noreply.github.com>
Co-authored-by: RomualdYT <romuald@gameurnews.fr>
Co-authored-by: Lucas <lucas@vanosenbruggen.com>
Co-authored-by: Constantine <Runixer@gmail.com>
Co-authored-by: Shamil <ashm.tech@proton.me>
Co-authored-by: Cyp <cypher9715@naver.com>
Co-authored-by: looselyhuman <fieldian@gmail.com>
Co-authored-by: Circe (Claude Code Sonnet 4.6) <circe@athena-council.org>
Applies all Flexion-specific changes from flex (v0.8.0 base) onto
upstream v0.8.10. Includes Google Cloud Identity OAuth group-based
roles, provider model icons, FlexChat branding, custom functions,
and documentation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds a model helper tooltip/modal with two paths for model discovery:
- Query with an assisted prompt to get model suggestions based on use case
- Browse by common use cases for model inspiration

Also fixes security issue with dedented else statements in oauth.py
and enhances the model suggestion prompt.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
- Import STATIC_DIR explicitly in models.py (no longer a global in v0.9.5)
- Make model_recommendation_template async to match prompt_template() which
  became async in v0.9.5; add await at call site in tasks.py

Both issues found and verified via local Docker test against deployed BAG.
…EXION.md

Replace stub 'Keeping Up with Upstream' section with full runbook covering:
- Manual rebase process (safety prep, conflict resolution, verification, merge)
- Automated CI sync pipeline (upstream-sync.yml workflow usage, secrets setup)
- Conflict type reference table (binary/lock/flexion-unique/shared strategies)
- Flexion customization inventory with conflict risk ratings
lgarceau768 and others added 17 commits May 18, 2026 16:18
…ker build

- models.py: FileResponse was used at line 599 but never imported, causing
  NameError -> 500 on every model profile image request in production
- Dockerfile: OrbStack injects IPv6 CIDR ranges (e.g. fd07:b51a:cc66::/64)
  into no_proxy which httpx cannot parse as URL patterns, breaking the
  sentence-transformers model download step during docker build
These five workflows were inherited from upstream open-webui/open-webui
and were not producing artifacts on flex (none of them triggered on the
flex branch). Renaming to .disabled mirrors the existing convention
(codespell.disabled, lint-*.disabled) and keeps the diff vs upstream
minimal while remaining reversible.

- build-release.yml — upstream release pipeline, not relevant
- docker-build.yaml — publishes to ghcr.io, replaced by publish-flex-image
- format-backend.yaml — autoformat, not part of flex CI
- format-build-frontend.yaml — autoformat, not part of flex CI
- release-pypi.yml — upstream PyPI release, not relevant
Manual workflow (workflow_dispatch only) that builds the Flexion-customized
Docker image for linux/arm64 and pushes it to AWS ECR under the chosen
environment's repository (open-webui-dev or open-webui-prod) with the
caller-supplied version tag.

Design notes:
- ARM-native runner (ubuntu-24.04-arm) matches the Fargate ARM deploy
  target — no QEMU overhead.
- Only linux/arm64 is built. Multi-arch would double build time for no
  current benefit; can be extended later if x86 deploys are needed.
- AWS auth via OIDC: assumes GitHubActionsOpenWebUIDev for environment=dev
  and GitHubActionsOpenWebUIProd for environment=prod. The prod role's
  trust policy was extended in flexion/flexion-open-webui-infra#461 to
  accept tokens from this repo's flex branch.
- Tag overwrite guard: refuses to push if the tag already exists in ECR.
  Prevents accidental republishes that would mask source-of-truth
  provenance. Operator must delete the existing tag manually to retag.
- ECR tag = upstream release tag verbatim (e.g. v0.9.5, not v9.5) — the
  0. prefix is preserved end-to-end through to the CDK pin in the infra
  repo.
chore(ci): disable inherited upstream workflows, add publish-flex-image
PR B of the flex-CI-setup plan. Adds .github/workflows/upstream-sync.yml
and rewrites README_FLEXION.md Option A to match the actually-shipped
behavior (no Bedrock).

The workflow:
- workflow_dispatch only, inputs: dry_run (default true) and target_ref
  (default refs/heads/main → upstream/main)
- Detects drift via `git rev-list flex..upstream/main`
- On dry_run, reports drift count and exits
- On real run, creates upstream-sync/YYYYMMDD-HHMMSS, rebases, applies
  per-file rules:
    * *.png|*.ico|*.wasm → --ours
    * package-lock.json|uv.lock → --theirs
    * functions/**|static/static/providers/**|README_FLEXION.md → --ours
    * everything else → conflict markers stay in the committed content
- Accumulates a conflict-resolution log as markdown
- Opens a PR (draft if manual review is needed, ready otherwise) with
  the log + HITL checklist + list of files containing markers

Uses SYNC_PAT for both checkout and push because GITHUB_TOKEN can't push
branches that touch .github/workflows/.

No Bedrock or other LLM dependencies. Future upgrade path: insert an
LLM-assisted resolver as a step BEFORE the "leave markers" fallback,
without changing surrounding plumbing.
Replaces the "rebase against upstream/main HEAD" model with a daily
schedule that watches for new upstream v*.*.* release tags. On no-new-
release days, the workflow exits cleanly without opening a PR.

Why: upstream's main branch evolves with every commit, but flex tracks
releases (v0.9.5, etc.). Syncing against main HEAD would create churn
from every upstream commit; syncing against release tags matches how the
ECR tagging and CDK pinning already work.

Changes:
- Triggers: on.schedule (daily 09:00 UTC) + on.workflow_dispatch
- workflow_dispatch inputs replaced:
    - dry_run (boolean)              → removed
    - target_ref (string, default refs/heads/main) → removed
    - target_tag (string, optional)  → new; blank = auto-detect latest v*.*.*
    - force (boolean, default false) → new; bypass "already on target" check
- Detection:
    - target tag: explicit input, or `git tag -l 'v[0-9]*.[0-9]*.[0-9]*'
      --sort=-version:refname | head -n 1` (pre-releases excluded)
    - current base: `git describe --tags --abbrev=0 flex`
- Safety: refuses to sync backward (target older than base) without force
- Concurrency group "upstream-sync", no cancel-in-progress
- Throwaway branch name now includes the target tag for traceability
- PR body now references "Publish flex image to ECR" as the followup step

Also rewrites README_FLEXION.md Option A to describe the new model.
feat(ci): add upstream-sync workflow with deterministic conflict rules
GitHub Actions will force the Node.js 24 runtime as the default on
2026-06-02 and remove Node.js 20 on 2026-09-16. The smoke runs of
publish-flex-image both surfaced deprecation warnings for the previous
versions. Node.js 24 has been the active LTS since October 2025, so
this bumps to majors that declare `using: node24` in action.yml.

Bumps:
  actions/checkout                  v5 → v6
  aws-actions/configure-aws-credentials  v4 → v6
  docker/setup-buildx-action        v3 → v4
  docker/build-push-action          v5 → v7
  aws-actions/amazon-ecr-login      stays at v2 (v2.1.5 already on node24)

Breaking-change review:
  - configure-aws-credentials v5 cleaned up boolean-input handling; we
    pass only strings (role-to-assume, aws-region), unaffected.
  - configure-aws-credentials v6 is a Node 24 migration only.
  - build-push-action v6 enables build summaries by default (we accept
    this side effect; opt-out via DOCKER_BUILD_SUMMARY=false if needed).
  - build-push-action v7 is a Node 24 migration plus removal of deprecated
    envs we don't use (DOCKER_BUILD_NO_SUMMARY, DOCKER_BUILD_EXPORT_RETENTION_DAYS).
  - actions/checkout v6, docker/setup-buildx-action v4: Node 24 only.
chore(ci): bump actions to latest majors (Node 24 LTS)
The Upstream Sync workflow has failed every scheduled run since it
was added — actions/checkout fails at fetch with "could not read
Username for 'https://github.com': terminal prompts disabled",
indicating SYNC_PAT is set but invalid (likely expired, revoked, or
lacking required scopes).

The job only needs to (a) push a throwaway branch to this repo and
(b) open a PR. Both are already granted by the workflow's existing
permissions block (contents: write, pull-requests: write), which the
built-in GITHUB_TOKEN honors. The push doesn't need to trigger
downstream workflows, so GITHUB_TOKEN's recursive-trigger restriction
doesn't apply here.

Removes the need to manage a rotating PAT.
fix(ci): use GITHUB_TOKEN instead of SYNC_PAT for upstream-sync
After fixing the auth issue (#29), the workflow failed at the next
step with:

  ! [rejected] v0.6.40 -> v0.6.40 (would clobber existing tag)

This fork carries legacy tags inherited from when it was created.
At least one of them (v0.6.40) points to a different commit than
upstream's tag of the same name, so `git fetch --tags` refuses the
overwrite by default.

We always want upstream's tag values when resolving the sync target,
so `--force` is the right behavior. `--prune` is kept but does NOT
prune tags (no --prune-tags), so any flex-only tags are safe.
fix(ci): force-fetch upstream tags in Upstream Sync
Upstream Open WebUI only allows OPENAI_API_CONFIGS to be set via the
admin UI (writes to the persistent-config DB). For IaC-driven
deployments running with ENABLE_PERSISTENT_CONFIG=false, that means
per-connection settings like prefix_id can't be expressed in env vars,
which forces drift between the deployment manifest and the runtime
config.

Mirror the existing TERMINAL_PROXY_HEADERS pattern: try to parse
$OPENAI_API_CONFIGS as JSON and pass the resulting dict as the
PersistentConfig env_value. Empty, unset, or malformed input falls
back to {} so startup never fails on a bad env var.

Upstream rejected this approach (PR open-webui#16562 closed, issue open-webui#19017 closed
NOT_PLANNED) so this lives in the flex fork permanently.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

DO NOT MERGE do not merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants