mirror of https://github.com/langgenius/dify.git
- Block all private/internal networks by default to prevent SSRF attacks - Restrict ports to only HTTP (80) and HTTPS (443) - Deny all requests by default unless explicitly whitelisted - Add customization support via conf.d directory for local overrides - Provide example configurations for common use cases - Add CI/testing setup script to ensure tests pass with strict config - Update docker-compose files to support custom config mounting - Add comprehensive documentation with security warnings |
||
|---|---|---|
| .. | ||
| 00-testing-environment.conf.example | ||
| 10-allow-marketplace.conf.example | ||
| 20-allow-internal-services.conf.example | ||
| 30-allow-external-domains.conf.example | ||
| 40-allow-additional-ports.conf.example | ||