Summary
A chat completion request whose session id is blank (metadata.chat_session_id: "", or an empty X-Chat-Session-Id or x-openwebui-chat-id header) has that blank value taken as its session id. A request with no session id gets a fresh cs_… id; a request with a blank one does not.
Two things follow:
- Clients share a session. Every request with a blank id lands in the same session. Skill invocation logs are keyed by session and agent, so for an agent with local skills, one client's recorded skill loads are replayed into another client's history (
aura.skills_rehydrated). The file store derives the log's name from the session string and the Redis store keys on it, so this holds across instances too.
- Orchestration fails. Orchestration persistence refuses an empty session id as a path component, so with a memory directory configured, an orchestrated request with a blank id fails with
Failed to initialize persistence: Invalid session_id for persistence path: "".
Expected: a blank value is treated like a missing one. The next source is tried, and a request with no non-blank id gets a fresh id.
Reproduction
Pre-requisites
aura webserver on nightly at 513f1ec1
- For the shared session: an agent config with local skills (
[agent.skills])
- For the orchestration failure: an orchestration config with a memory directory
Steps
- Client A sends
POST /v1/chat/completions with an empty X-Chat-Session-Id header and a prompt that makes the agent load a skill.
- Client B sends a different conversation with the same empty header.
- [BUG] Client B's request rehydrates client A's skill invocation (
aura.skills_rehydrated lists it). Expected a fresh session with nothing to rehydrate.
- Against the orchestration config, send any request with an empty
X-Chat-Session-Id header.
- [BUG] The request fails to initialize persistence. Expected it to run under a fresh session id.
Relevant log output
No response
Additional Context
Found while reviewing #794, from reading the code on nightly rather than from a failing server run.
Fixed by #795: a blank value falls through to the next source, and a request with no non-blank id gets a fresh one.
Upload screenshots
No response
Searched Issues
Code of Conduct
Summary
A chat completion request whose session id is blank (
metadata.chat_session_id: "", or an emptyX-Chat-Session-Idorx-openwebui-chat-idheader) has that blank value taken as its session id. A request with no session id gets a freshcs_…id; a request with a blank one does not.Two things follow:
aura.skills_rehydrated). The file store derives the log's name from the session string and the Redis store keys on it, so this holds across instances too.Failed to initialize persistence: Invalid session_id for persistence path: "".Expected: a blank value is treated like a missing one. The next source is tried, and a request with no non-blank id gets a fresh id.
Reproduction
Pre-requisites
aura webserveronnightlyat513f1ec1[agent.skills])Steps
POST /v1/chat/completionswith an emptyX-Chat-Session-Idheader and a prompt that makes the agent load a skill.aura.skills_rehydratedlists it). Expected a fresh session with nothing to rehydrate.X-Chat-Session-Idheader.Relevant log output
No response
Additional Context
Found while reviewing #794, from reading the code on
nightlyrather than from a failing server run.handlers.rsL448–L462: the session id is the metadata value or header as given;unwrap_or_else(generate_chat_session_id)covers only a missing value.handlers.rsL301–L304: the skill log is keyed by that session id and the agent.file/skill_store.rsL101–L102: the file store names the log from the session string, so every blank-session client shares one file per agent.persistence.rsL98–L100 and L315–L320: an empty session id is not a safe path component, andorchestrator.rsL627 fails the run on it.Fixed by #795: a blank value falls through to the next source, and a request with no non-blank id gets a fresh one.
Upload screenshots
No response
Searched Issues
Code of Conduct