Skip to content

[BUG]: A blank chat session id is taken as given, so clients share a session #799

Description

@justintime4tea

Summary

A chat completion request whose session id is blank (metadata.chat_session_id: "", or an empty X-Chat-Session-Id or x-openwebui-chat-id header) has that blank value taken as its session id. A request with no session id gets a fresh cs_… id; a request with a blank one does not.

Two things follow:

  • Clients share a session. Every request with a blank id lands in the same session. Skill invocation logs are keyed by session and agent, so for an agent with local skills, one client's recorded skill loads are replayed into another client's history (aura.skills_rehydrated). The file store derives the log's name from the session string and the Redis store keys on it, so this holds across instances too.
  • Orchestration fails. Orchestration persistence refuses an empty session id as a path component, so with a memory directory configured, an orchestrated request with a blank id fails with Failed to initialize persistence: Invalid session_id for persistence path: "".

Expected: a blank value is treated like a missing one. The next source is tried, and a request with no non-blank id gets a fresh id.

Reproduction

Pre-requisites

  • aura webserver on nightly at 513f1ec1
  • For the shared session: an agent config with local skills ([agent.skills])
  • For the orchestration failure: an orchestration config with a memory directory

Steps

  1. Client A sends POST /v1/chat/completions with an empty X-Chat-Session-Id header and a prompt that makes the agent load a skill.
  2. Client B sends a different conversation with the same empty header.
  3. [BUG] Client B's request rehydrates client A's skill invocation (aura.skills_rehydrated lists it). Expected a fresh session with nothing to rehydrate.
  4. Against the orchestration config, send any request with an empty X-Chat-Session-Id header.
  5. [BUG] The request fails to initialize persistence. Expected it to run under a fresh session id.

Relevant log output

No response

Additional Context

Found while reviewing #794, from reading the code on nightly rather than from a failing server run.

Fixed by #795: a blank value falls through to the next source, and a request with no non-blank id gets a fresh one.

Upload screenshots

No response

Searched Issues

  • No similar issues found

Code of Conduct

  • I agree to follow this project's Code of Conduct

Activity

  1. added 3 commits that reference this issue on Oct 9, 2026
    03337ac
    bde1a6a
    fa3861d
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions