dify/api
GareArc d4834ddd98
fix(tools): scope builtin tool default-credential clear to tenant
When two workspace members each set their own credential as the default
for the same provider, both rows ended up with is_default=True for the
same (tenant_id, provider). The clear UPDATE was filtered by user_id,
so it only reset the caller's own defaults and left other members'
defaults intact. The consumer (`get_builtin_provider`) is tenant-scoped
and picks an arbitrary winner via the created_at tiebreak when multiple
defaults exist, producing user-visible inconsistencies.

Drop user_id from the clear filter so default selection becomes
properly tenant-scoped, matching
`DatasourceProviderService.set_default_datasource_provider`.

Adds a regression test that asserts the clear filter_by call uses
tenant_id/provider but not user_id.

Backport of equivalent fix on main to lts/1.13.x.
2026-05-07 02:30:35 -07:00
..
.idea
.vscode chore(api): update launch.json.example to include new workflow_based_app_execution. (#32184) 2026-02-10 17:08:43 +08:00
commands refactor: select in console datasets document controller (#34029) 2026-03-25 12:47:25 +09:00
configs feat: sync enterprise telemetry to lts (#34190) 2026-03-27 17:54:16 +08:00
constants fix: add missing pipeline_templates (#31528) 2026-03-01 17:33:04 +08:00
context refactor: move workflow package to dify_graph (#32844) 2026-03-02 18:42:30 +08:00
contexts refactor(model): Refactor plugin model schema cache to be process-global to prevent redundant Daemon API calls (#31689) 2026-01-29 14:31:15 +08:00
controllers feat: add inner API endpoints for admin DSL import/export (#34059) 2026-03-25 19:48:53 +08:00
core fix: cache credentials & enterprise calls (#35528) 2026-04-23 23:08:04 +08:00
dify_graph feat: configurable model parameters with variable reference support in LLM, Question Classifier and Variable Extractor nodes (#33082) 2026-03-24 17:41:51 +08:00
docker feat(tasks): isolate summary generation to dedicated dataset_summary queue (#32972) 2026-03-06 14:35:28 +08:00
enterprise feat: sync enterprise telemetry to lts (#34190) 2026-03-27 17:54:16 +08:00
enums feat: add trial model list in system features (#31313) 2026-01-26 11:52:05 +08:00
events fix: fix opensearch import (#35476) 2026-04-22 12:09:23 +08:00
extensions feat: sync enterprise telemetry to lts (#34190) 2026-03-27 17:54:16 +08:00
factories refactor: migrate db.session.query to select in infra layer (#33694) 2026-03-19 15:48:29 +09:00
fields refactor: move workflow package to dify_graph (#32844) 2026-03-02 18:42:30 +08:00
libs fix(api): fix concurrency issues in StreamsBroadcastChannel (#34061) 2026-03-25 15:47:31 +08:00
migrations chore: change draft var to user scoped (#33066) 2026-03-16 14:04:41 +08:00
models fix: resolve SADeprecationWarning for callable default in remaining TypeBase models (#34049) 2026-03-25 12:51:36 +09:00
repositories refactor(api): tighten phase 1 shared type contracts (#33453) 2026-03-17 17:50:51 +08:00
schedule refactor: use EnumText for TidbAuthBinding.status and MessageFile.type (#33975) 2026-03-24 05:38:29 +09:00
services fix(tools): scope builtin tool default-credential clear to tenant 2026-05-07 02:30:35 -07:00
tasks feat: sync enterprise telemetry to lts (#34190) 2026-03-27 17:54:16 +08:00
templates refactor: make url in email template more better (#31166) 2026-01-19 14:28:41 +08:00
tests fix(tools): scope builtin tool default-credential clear to tenant 2026-05-07 02:30:35 -07:00
.dockerignore Enhance Code Consistency Across Repository with .editorconfig (#19023) 2025-04-29 18:04:33 +08:00
.env.example fix: do not block upsert for baidu vdb (#33280) 2026-03-23 20:42:57 +08:00
.importlinter refactor: llm decouple code executor module (#33400) 2026-03-16 10:06:14 +08:00
.ruff.toml refactor(api): move model_runtime into dify_graph (#32858) 2026-03-02 20:15:32 +08:00
AGENTS.md refactor(api): tighten phase 1 shared type contracts (#33453) 2026-03-17 17:50:51 +08:00
app_factory.py feat: sync enterprise telemetry to lts (#34190) 2026-03-27 17:54:16 +08:00
app.py chore(typing): reduce ty excludes for A1 (#31721) 2026-01-30 02:38:57 +08:00
celery_entrypoint.py chore(api): adjust monkey patching in gunicorn.conf.py (#26056) 2025-09-22 18:23:01 +08:00
cnt_base.sh add cnt script and one more example (#28272) 2025-11-18 16:44:14 +09:00
dify_app.py refactor: assembling the app features in modular way (#9129) 2024-11-30 23:05:22 +08:00
Dockerfile ci: Simplify nltk data download in Dockerfile (#33495) 2026-03-16 12:06:20 +09:00
gunicorn.conf.py docs(api): update docs about gevent setup in app.py (#27611) 2025-10-30 15:43:08 +08:00
pyproject.toml chore: lts bump litellm and langsmith versions (#35592) 2026-04-28 13:05:49 +08:00
pyrefly-local-excludes.txt feat: sync enterprise telemetry to lts (#34190) 2026-03-27 17:54:16 +08:00
pyrightconfig.json chore: bump dependencies for lts (#35231) 2026-04-15 14:21:45 +08:00
pytest.ini chore: add pytest XML and branch coverage reports (#33730) 2026-03-19 17:08:34 +08:00
README.md docs(api): simplify setup README and worker guidance (#32704) 2026-02-27 18:12:52 +08:00
uv.lock chore: bump versions (#35866) 2026-05-07 13:53:39 +08:00

Dify Backend API

Setup and Run

Important

In the v1.3.0 release, poetry has been replaced with uv as the package manager for Dify API backend service.

uv and pnpm are required to run the setup and development commands below.

The scripts resolve paths relative to their location, so you can run them from anywhere.

  1. Run setup (copies env files and installs dependencies).

    ./dev/setup
    
  2. Review api/.env, web/.env.local, and docker/middleware.env values (see the SECRET_KEY note below).

  3. Start middleware (PostgreSQL/Redis/Weaviate).

    ./dev/start-docker-compose
    
  4. Start backend (runs migrations first).

    ./dev/start-api
    
  5. Start Dify web service.

    ./dev/start-web
    
  6. Set up your application by visiting http://localhost:3000.

  7. Start the worker service (async and scheduler tasks, runs from api).

    ./dev/start-worker
    
  8. Optional: start Celery Beat (scheduled tasks).

    ./dev/start-beat
    

Environment notes

Important

When the frontend and backend run on different subdomains, set COOKIE_DOMAIN to the sites top-level domain (e.g., example.com). The frontend and backend must be under the same top-level domain in order to share authentication cookies.

  • Generate a SECRET_KEY in the .env file.

    bash for Linux

    sed -i "/^SECRET_KEY=/c\\SECRET_KEY=$(openssl rand -base64 42)" .env
    

    bash for Mac

    secret_key=$(openssl rand -base64 42)
    sed -i '' "/^SECRET_KEY=/c\\
    SECRET_KEY=${secret_key}" .env
    

Testing

  1. Install dependencies for both the backend and the test environment

    cd api
    uv sync --group dev
    
  2. Run the tests locally with mocked system environment variables in tool.pytest_env section in pyproject.toml, more can check Claude.md

    cd api
    uv run pytest                           # Run all tests
    uv run pytest tests/unit_tests/         # Unit tests only
    uv run pytest tests/integration_tests/  # Integration tests
    
    # Code quality
    ./dev/reformat               # Run all formatters and linters
    uv run ruff check --fix ./   # Fix linting issues
    uv run ruff format ./        # Format code
    uv run basedpyright .        # Type checking