$ cat open-webui/week/2026-09-07.log
the week in review · Sep 7 – Sep 13, 2026
Denied-by-policy users still sign in via OAuth token exchange
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
The bypass spans both daily briefings this week, leaving any deployment with role-restricted OAuth sign-in affected.
Users denied by the OAuth role policy can still sign in via token exchange open-webui/open-webui
Token exchange hands out a session without enforcing the role policy, so a denial at the OAuth role check is not the end of the login path. If you gate access through that policy, treat it as unenforced until a fix lands; audit which accounts and IdP groups depend on it. The story carries no fixed version, so there is nothing to pin to yet.
$ ls open-webui/week/ # the briefings behind this review
Keep up with Open WebUI in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.