RepoJournal

$ cat open-webui/week/2026-09-07.log

Open WebUI

Open WebUI

the week in review · Sep 7 – Sep 13, 2026

Denied-by-policy users still sign in via OAuth token exchange

By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology

The bypass spans both daily briefings this week, leaving any deployment with role-restricted OAuth sign-in affected.

2 security advisories 2 briefings covered

all open-webui reviews →

Users denied by the OAuth role policy can still sign in via token exchange open-webui/open-webui

Token exchange hands out a session without enforcing the role policy, so a denial at the OAuth role check is not the end of the login path. If you gate access through that policy, treat it as unenforced until a fix lands; audit which accounts and IdP groups depend on it. The story carries no fixed version, so there is nothing to pin to yet.

$ ls open-webui/week/ # the briefings behind this review

Keep up with Open WebUI in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

all open-webui reviews →