KnowledgeFS spaces used their own `knowledge_space_*` RBAC vocabulary, so workspace roles configured for knowledge bases did not apply to them. Reuse the legacy `dataset_*` permission points instead, following the mapping the dataset console already applies: - read -> dataset_readonly - create -> dataset_create_and_management - edit / document write -> dataset_edit - delete -> dataset_delete - access config -> dataset_access_config - query / research / trace detail -> dataset_retrieval_recall The enterprise `/knowledge-fs/permission-keys/batch` lookup now answers in that vocabulary and is translated back into the product capabilities the console exposes as `permission_keys`, so the web stays unchanged; the historical `knowledge_space_*` keys remain accepted during the transition. Workspace-level checks send the mapped dataset scene with `resource_type=dataset`, and the RBAC-disabled fallback grants every dataset point KnowledgeFS consults. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015zw5G5SX3HmVfnZof6YWAc |
||
|---|---|---|
| .. | ||
| .idea | ||
| .vscode | ||
| clients | ||
| commands | ||
| configs | ||
| constants | ||
| context | ||
| contexts | ||
| controllers | ||
| core | ||
| dev | ||
| docker | ||
| enterprise | ||
| enums | ||
| events | ||
| extensions | ||
| factories | ||
| fields | ||
| libs | ||
| machinery | ||
| migrations | ||
| models | ||
| openapi/markdown | ||
| providers | ||
| repositories | ||
| schedule | ||
| services | ||
| tasks | ||
| templates | ||
| tests | ||
| .dockerignore | ||
| .env.example | ||
| .importlinter | ||
| .ruff.toml | ||
| AGENTS.md | ||
| app_factory.py | ||
| app.py | ||
| celery_entrypoint.py | ||
| celery_healthcheck.py | ||
| cnt_base.sh | ||
| conftest.py | ||
| dify_app.py | ||
| Dockerfile | ||
| Dockerfile.dockerignore | ||
| gunicorn.conf.py | ||
| knowledge-fs-contract.lock.json | ||
| knowledge-fs-product-operation-gaps.json | ||
| knowledge-fs-product-operations.json | ||
| pyproject.toml | ||
| pyrefly-local-excludes.txt | ||
| pytest.ini | ||
| README.md | ||
| uv.lock | ||
Dify Backend API
Setup and Run
Important
In the v1.3.0 release,
poetryhas been replaced withuvas the package manager for Dify API backend service.
uv and pnpm are required to run the setup and development commands below.
Using scripts (recommended)
The scripts resolve paths relative to their location, so you can run them from anywhere.
-
Run setup (copies env files and installs dependencies).
./dev/setup -
Review
api/.env,web/.env.local, anddocker/middleware.envvalues (see theSECRET_KEYnote below). -
Start middleware (PostgreSQL/Redis/Weaviate).
./dev/start-docker-compose -
Start backend (runs migrations first).
./dev/start-api -
Start Dify web service.
./dev/start-web./dev/setupand./dev/start-webinstall JavaScript dependencies through the repository root workspace, so you do not need a separatecd web && pnpm installstep. -
Set up your application by visiting
http://localhost:3000. -
Start the worker service (async and scheduler tasks, runs from
api)../dev/start-worker -
Start Celery Beat when scheduled tasks are needed. This is required when
KNOWLEDGE_FS_LIFECYCLE_WORKER_ENABLED=trueso provisioning and deletion outbox commands are dispatched to the lifecycle worker../dev/start-beat
Environment notes
Important
When the frontend and backend run on different subdomains, set COOKIE_DOMAIN to the site’s top-level domain (e.g.,
example.com). The frontend and backend must be under the same top-level domain in order to share authentication cookies.
-
Generate a
SECRET_KEYin the.envfile.bash for Linux
sed -i "/^SECRET_KEY=/c\\SECRET_KEY=$(openssl rand -base64 42)" .envbash for Mac
secret_key=$(openssl rand -base64 42) sed -i '' "/^SECRET_KEY=/c\\ SECRET_KEY=${secret_key}" .env
Testing
-
Install dependencies for both the backend and the test environment
cd api uv sync --group dev -
Run the tests locally with mocked system environment variables in
tool.pytest_envsection inpyproject.toml, more can check Claude.mdcd api uv run pytest # Run all tests uv run pytest tests/unit_tests/ # Unit tests only uv run pytest tests/integration_tests/ # Integration tests # Code quality ./dev/reformat # Run all formatters and linters uv run ruff check --fix ./ # Fix linting issues uv run ruff format ./ # Format code uv run pyrefly check # Type checking
Generate TS stub
uv run dev/generate_swagger_specs.py --output-dir openapi
use https://jsontotable.org/openapi-to-typescript to convert to typescript