dify/api
-LAN- 04954918a5
Merge commit from fork
* fix(oraclevector): SQL Injection

Signed-off-by: -LAN- <laipz8200@outlook.com>

* fix(oraclevector): Remove bind variables from FETCH FIRST clause

Oracle doesn't support bind variables in the FETCH FIRST clause.
Fixed by using validated integers directly in the SQL string while
maintaining proper input validation to prevent SQL injection.

- Updated search_by_vector method to use validated top_k directly
- Updated search_by_full_text method to use validated top_k directly
- Adjusted parameter numbering for document_ids_filter placeholders

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Signed-off-by: -LAN- <laipz8200@outlook.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-08-26 13:51:23 +08:00
..
.idea fix nltk averaged_perceptron_tagger download and fix score limit is none (#7582) 2024-08-26 15:14:05 +08:00
.vscode feat/enhance the multi-modal support (#8818) 2024-10-21 10:43:49 +08:00
configs feat: Implements periodic deletion of workflow run logs that exceed t… (#23881) 2025-08-19 09:47:34 +08:00
constants fix video and audio extension, keep consistent with the web page. (#23287) 2025-08-01 22:59:38 +08:00
contexts fix: Copy request context and current user in app generators. (#20240) 2025-05-27 10:56:23 +08:00
controllers fix: standardize authentication error messages to prevent user enumeration (#24324) 2025-08-26 09:46:23 +08:00
core Merge commit from fork 2025-08-26 13:51:23 +08:00
docker fix delete conversations via Api and delete conversations from db as well (#23591) 2025-08-25 09:43:45 +08:00
events opt(api): optimize update contention on the providers table (#24520) 2025-08-26 11:41:38 +08:00
extensions refactor: better error handler (#24422) 2025-08-25 09:28:42 +08:00
factories fix: mime_type could be None (#23880) 2025-08-14 13:40:06 +08:00
fields feat: API docs for service api (#24425) 2025-08-25 09:26:54 +08:00
libs feat: add authorizations for swagger doc (#24518) 2025-08-26 11:41:00 +08:00
migrations feat: add multi model credentials (#24451) 2025-08-25 16:12:29 +08:00
models feat: add multi model credentials (#24451) 2025-08-25 16:12:29 +08:00
repositories refactor: simplify repository factory with Django-style import_string (#24354) 2025-08-22 21:56:25 +08:00
schedule try ast-grep (#24149) 2025-08-19 13:41:52 +08:00
services feat: add multi model credentials (#24451) 2025-08-25 16:12:29 +08:00
tasks fix delete conversations via Api and delete conversations from db as well (#23591) 2025-08-25 09:43:45 +08:00
templates Feat: add notification for change email completed (#22812) 2025-07-24 14:16:39 +08:00
tests fix: standardize authentication error messages to prevent user enumeration (#24324) 2025-08-26 09:46:23 +08:00
.dockerignore Enhance Code Consistency Across Repository with `.editorconfig` (#19023) 2025-04-29 18:04:33 +08:00
.env.example feat: Implements periodic deletion of workflow run logs that exceed t… (#23881) 2025-08-19 09:47:34 +08:00
.ruff.toml make logging not use f-str, change others to f-str (#22882) 2025-07-25 10:32:48 +08:00
Dockerfile chore: update uv to 0.8.9 (#23833) 2025-08-12 23:41:39 +08:00
README.md readme and claude.md sync. (#24495) 2025-08-26 12:57:26 +08:00
app.py chore: avoid repeated type ignore noqa by adding flask_restful and flask_login in mypy import exclusions (#19224) 2025-05-06 11:58:49 +08:00
app_factory.py example for logging (#24441) 2025-08-25 11:41:17 +08:00
commands.py feat(api): auto-delete WorkflowDraftVariable when app is deleted (#23737) 2025-08-13 11:13:08 +08:00
dify_app.py refactor: assembling the app features in modular way (#9129) 2024-11-30 23:05:22 +08:00
mypy.ini refactor: better error handler (#24422) 2025-08-25 09:28:42 +08:00
pyproject.toml chore: apply static type checks on celery async task dispatches and imports (#24418) 2025-08-24 23:07:22 +08:00
pytest.ini Refactor/remove db from cycle manager (#20455) 2025-05-30 04:34:13 +08:00
uv.lock chore: apply static type checks on celery async task dispatches and imports (#24418) 2025-08-24 23:07:22 +08:00

README.md

Dify Backend API

Usage

[!IMPORTANT]

In the v1.3.0 release, poetry has been replaced with uv as the package manager for Dify API backend service.

  1. Start the docker-compose stack

    The backend require some middleware, including PostgreSQL, Redis, and Weaviate, which can be started together using docker-compose.

    cd ../docker
    cp middleware.env.example middleware.env
    # change the profile to other vector database if you are not using weaviate
    docker compose -f docker-compose.middleware.yaml --profile weaviate -p dify up -d
    cd ../api
    
  2. Copy .env.example to .env

    cp .env.example .env
    
  3. Generate a SECRET_KEY in the .env file.

    bash for Linux

    sed -i "/^SECRET_KEY=/c\SECRET_KEY=$(openssl rand -base64 42)" .env
    

    bash for Mac

    secret_key=$(openssl rand -base64 42)
    sed -i '' "/^SECRET_KEY=/c\\
    SECRET_KEY=${secret_key}" .env
    
  4. Create environment.

    Dify API service uses UV to manage dependencies. First, you need to add the uv package manager, if you don't have it already.

    pip install uv
    # Or on macOS
    brew install uv
    
  5. Install dependencies

    uv sync --dev
    
  6. Run migrate

    Before the first launch, migrate the database to the latest version.

    uv run flask db upgrade
    
  7. Start backend

    uv run flask run --host 0.0.0.0 --port=5001 --debug
    
  8. Start Dify web service.

  9. Setup your application by visiting http://localhost:3000.

  10. If you need to handle and debug the async tasks (e.g. dataset importing and documents indexing), please start the worker service.

uv run celery -A app.celery worker -P gevent -c 1 --loglevel INFO -Q dataset,generation,mail,ops_trace,app_deletion,plugin,workflow_storage,conversation

Addition, if you want to debug the celery scheduled tasks, you can use the following command in another terminal:

uv run celery -A app.celery beat

Testing

  1. Install dependencies for both the backend and the test environment

    uv sync --dev
    
  2. Run the tests locally with mocked system environment variables in tool.pytest_env section in pyproject.toml, more can check Claude.md

    uv run pytest                           # Run all tests
    uv run pytest tests/unit_tests/         # Unit tests only
    uv run pytest tests/integration_tests/  # Integration tests
    
    # Code quality
    ../dev/reformat               # Run all formatters and linters
    uv run ruff check --fix ./    # Fix linting issues
    uv run ruff format ./         # Format code
    uv run mypy .                 # Type checking