dify/web/app/components/develop/secret-key
yungle246 be6612f454 feat: allow knowledge base API keys to be scoped to a single dataset
Reintroduce the nullable api_tokens.dataset_id column (dropped in 2e9819ca5b28)
so dataset API keys can opt into per-knowledge-base scoping:

- NULL dataset_id keeps today's workspace-wide behavior, so every existing key
  and the existing /datasets/api-keys create route are unchanged.
- validate_dataset_token rejects a bound key for any other dataset, and for
  endpoints that carry no dataset id (e.g. list-all), with 403.
- CachedApiToken carries dataset_id with a None default so cache entries
  written before deploy keep deserializing.
- The per-dataset console routes in apikey.py (previously dead code that 500ed
  on a missing ApiToken.dataset_id) now create bound keys; their list returns
  bound keys plus workspace keys so the dataset page shows the full access
  picture.
- Frontend: the knowledge base API access popover gains an API keys entry; the
  secret key modal accepts datasetId, shows a scope column, and offers a
  workspace / this-knowledge-base scope choice on create. New strings are
  localized for all 23 locales.
2026-06-11 11:41:47 +09:00
..
__tests__ feat: allow knowledge base API keys to be scoped to a single dataset 2026-06-11 11:41:47 +09:00
assets Fix tts play logic (#2683) 2024-03-05 09:22:36 +08:00
input-copy.tsx refactor: migrate to tailwind v4 style (#36417) 2026-05-20 03:39:44 +00:00
secret-key-button.tsx refactor: migrate to tailwind v4 style (#36417) 2026-05-20 03:39:44 +00:00
secret-key-generate.tsx refactor: migrate to tailwind v4 style (#36417) 2026-05-20 03:39:44 +00:00
secret-key-modal.tsx feat: allow knowledge base API keys to be scoped to a single dataset 2026-06-11 11:41:47 +09:00
style.module.css chore: clean up useless tailwind reference (#34478) 2026-04-02 11:45:19 +00:00