dify/api
Luyu Zhang acd6942d21 feat(storage): redirect signed file previews to S3 public base URL
Add an optional S3_PUBLIC_BASE_URL setting that, when configured, lets
file controllers 302-redirect signed previews to the object store / CDN
instead of streaming bytes through the Dify API. Works with any
S3-compatible backend exposing a public domain (Cloudflare R2 custom
domain, MinIO public endpoint, Aliyun OSS public domain, etc.) so that
egress and request handling for images, attachments, tool outputs, and
webapp logos no longer go through the API container.

Signature verification is preserved: the API still validates the HMAC
before issuing the redirect. When S3_PUBLIC_BASE_URL is unset the
behavior is unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 17:12:00 -07:00
..
.idea
.vscode feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
commands feat: marketplace and oauth fixes (#35509) 2026-04-24 07:53:14 +00:00
configs feat(storage): redirect signed file previews to S3 public base URL 2026-04-28 17:12:00 -07:00
constants feat: copy nodes cross apps (#33273) 2026-04-17 10:02:26 +00:00
context chore(api): align Python support with 3.12 (#34419) 2026-04-02 05:07:32 +00:00
contexts chore(api): align Python support with 3.12 (#34419) 2026-04-02 05:07:32 +00:00
controllers feat(storage): redirect signed file previews to S3 public base URL 2026-04-28 17:12:00 -07:00
core feat(storage): redirect signed file previews to S3 public base URL 2026-04-28 17:12:00 -07:00
dev chore: add script to generate openapi v2 json and add in README #35474 (#35477) 2026-04-23 03:42:04 +00:00
docker fix: add miss celery queue (#35282) 2026-04-16 02:40:14 +00:00
enterprise chore: reorg imports (#35308) 2026-04-16 08:50:02 +00:00
enums refactor: quota v3 integration (#35436) 2026-04-27 01:49:40 +00:00
events chore(api): migrate event handlers to use Session(db.engine) (#35234) 2026-04-17 03:59:41 +00:00
extensions feat(storage): redirect signed file previews to S3 public base URL 2026-04-28 17:12:00 -07:00
factories chore(api): adapt Graphon 0.2.2 upgrade (#35377) 2026-04-18 11:16:24 +00:00
fields chore(api): adapt Graphon 0.2.2 upgrade (#35377) 2026-04-18 11:16:24 +00:00
libs refactor: replace deprecated Iterator with Generator in contextmanagers #35433 (#35441) 2026-04-21 07:44:49 +00:00
migrations feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
models refactor: move SegmentAttachmentBinding and UploadFile to TypeBase (#30218) 2026-04-27 14:01:50 +00:00
providers chore: fix use select style api in orm (#35531) 2026-04-24 08:35:20 +00:00
repositories feat: add service api of HITL (#32826) 2026-04-24 06:37:10 +00:00
schedule chore(api): migrate mail task and OAuth data source to use Session(db… (#35235) 2026-04-17 08:52:27 +00:00
services feat(storage): redirect signed file previews to S3 public base URL 2026-04-28 17:12:00 -07:00
tasks fix: download and upload package before invoking upgrade in auto-upgrade task (#35599) 2026-04-27 10:19:56 +00:00
templates feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
tests feat(storage): redirect signed file previews to S3 public base URL 2026-04-28 17:12:00 -07:00
.dockerignore Enhance Code Consistency Across Repository with .editorconfig (#19023) 2025-04-29 18:04:33 +08:00
.env.example feat(storage): redirect signed file previews to S3 public base URL 2026-04-28 17:12:00 -07:00
.importlinter refactor(api): use standalone graphon package (#34209) 2026-03-27 21:05:32 +00:00
.ruff.toml chore: reorg imports (#35308) 2026-04-16 08:50:02 +00:00
AGENTS.md refactor(api): tighten phase 1 shared type contracts (#33453) 2026-03-17 17:50:51 +08:00
app_factory.py feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
app.py feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
celery_entrypoint.py chore(api): adjust monkey patching in gunicorn.conf.py (#26056) 2025-09-22 18:23:01 +08:00
celery_healthcheck.py fix: lighten the health checks for the Worker and Worker Beat services, and disable them by default (#34572) 2026-04-06 02:26:26 +00:00
cnt_base.sh add cnt script and one more example (#28272) 2025-11-18 16:44:14 +09:00
dify_app.py refactor(api): tighten login and wrapper typing (#34447) 2026-04-02 09:36:58 +00:00
Dockerfile refactor: move vdb implementations to workspaces (#34900) 2026-04-13 08:56:43 +00:00
gunicorn.conf.py docs(api): update docs about gevent setup in app.py (#27611) 2025-10-30 15:43:08 +08:00
pyproject.toml chore(deps): bump the storage group across 1 directory with 3 updates (#35578) 2026-04-27 03:21:37 +00:00
pyrefly-local-excludes.txt refactor(api): move trace providers (#35144) 2026-04-17 07:53:35 +00:00
pyrightconfig.json refactor(api): move trace providers (#35144) 2026-04-17 07:53:35 +00:00
pytest.ini chore: add pytest XML and branch coverage reports (#33730) 2026-03-19 17:08:34 +08:00
README.md chore: add script to generate openapi v2 json and add in README #35474 (#35477) 2026-04-23 03:42:04 +00:00
uv.lock chore(deps): bump the storage group across 1 directory with 3 updates (#35578) 2026-04-27 03:21:37 +00:00

Dify Backend API

Setup and Run

Important

In the v1.3.0 release, poetry has been replaced with uv as the package manager for Dify API backend service.

uv and pnpm are required to run the setup and development commands below.

The scripts resolve paths relative to their location, so you can run them from anywhere.

  1. Run setup (copies env files and installs dependencies).

    ./dev/setup
    
  2. Review api/.env, web/.env.local, and docker/middleware.env values (see the SECRET_KEY note below).

  3. Start middleware (PostgreSQL/Redis/Weaviate).

    ./dev/start-docker-compose
    
  4. Start backend (runs migrations first).

    ./dev/start-api
    
  5. Start Dify web service.

    ./dev/start-web
    

    ./dev/setup and ./dev/start-web install JavaScript dependencies through the repository root workspace, so you do not need a separate cd web && pnpm install step.

  6. Set up your application by visiting http://localhost:3000.

  7. Start the worker service (async and scheduler tasks, runs from api).

    ./dev/start-worker
    
  8. Optional: start Celery Beat (scheduled tasks).

    ./dev/start-beat
    

Environment notes

Important

When the frontend and backend run on different subdomains, set COOKIE_DOMAIN to the sites top-level domain (e.g., example.com). The frontend and backend must be under the same top-level domain in order to share authentication cookies.

  • Generate a SECRET_KEY in the .env file.

    bash for Linux

    sed -i "/^SECRET_KEY=/c\\SECRET_KEY=$(openssl rand -base64 42)" .env
    

    bash for Mac

    secret_key=$(openssl rand -base64 42)
    sed -i '' "/^SECRET_KEY=/c\\
    SECRET_KEY=${secret_key}" .env
    

Testing

  1. Install dependencies for both the backend and the test environment

    cd api
    uv sync --group dev
    
  2. Run the tests locally with mocked system environment variables in tool.pytest_env section in pyproject.toml, more can check Claude.md

    cd api
    uv run pytest                           # Run all tests
    uv run pytest tests/unit_tests/         # Unit tests only
    uv run pytest tests/integration_tests/  # Integration tests
    
    # Code quality
    ./dev/reformat               # Run all formatters and linters
    uv run ruff check --fix ./   # Fix linting issues
    uv run ruff format ./        # Format code
    uv run basedpyright .        # Type checking
    

Generate TS stub

uv run dev/generate_swagger_specs.py --output-dir openapi

use https://jsontotable.org/openapi-to-typescript to convert to typescript