dify/api
QuantumGhost 32a1a61d65 security(api): enforce privilege validation for dataset-to-pipeline transformation
The transformation from classic dataset to knowledge pipeline represents an irreversible
write operation that permanently alters the dataset structure. To prevent unauthorized
modifications, this change implements strict privilege validation in `RagPipelineTransformApi`.

Only users with editor privileges or dataset operator roles are authorized to execute
this transformation, ensuring proper access control for this critical operation.
2025-09-12 17:07:26 +08:00
..
.idea fix nltk averaged_perceptron_tagger download and fix score limit is none (#7582) 2024-08-26 15:14:05 +08:00
.vscode feat/enhance the multi-modal support (#8818) 2024-10-21 10:43:49 +08:00
configs Merge branch 'main' into fix/value-content-rerender-error 2025-09-09 16:40:08 +08:00
constants fix: add Indonesian (id-ID) language support and improve language selector (#24951) 2025-09-02 14:44:59 +08:00
contexts Merge branch 'main' into feat/r2 2025-05-29 09:54:28 +08:00
controllers security(api): enforce privilege validation for dataset-to-pipeline transformation 2025-09-12 17:07:26 +08:00
core fix user_id missed 2025-09-10 13:50:12 +08:00
docker change migration 2025-09-04 18:06:45 +08:00
events Merge remote-tracking branch 'origin/main' into feat/queue-based-graph-engine 2025-09-06 16:05:13 +08:00
extensions Merge branch 'main' into fix/value-content-rerender-error 2025-09-09 16:40:08 +08:00
factories Merge branch 'feat/queue-based-graph-engine' into feat/rag-2 2025-09-08 14:30:43 +08:00
fields Merge branch 'feat/queue-based-graph-engine' into feat/rag-2 2025-09-03 15:01:06 +08:00
libs Revert "feat: email register refactor" (#25367) 2025-09-08 19:20:09 +08:00
migrations fix: migration 2025-09-09 21:41:03 +08:00
models Merge branch 'main' into fix/value-content-rerender-error 2025-09-09 16:40:08 +08:00
repositories Merge branch 'feat/queue-based-graph-engine' into feat/rag-2 2025-09-08 14:30:43 +08:00
schedule [Chore/Refactor] Switch from MyPy to Basedpyright for type checking (#25047) 2025-09-03 11:52:26 +08:00
services fix ruff 2025-09-09 17:07:22 +08:00
tasks Revert "feat: email register refactor" (#25367) 2025-09-08 19:20:09 +08:00
templates Revert "feat: email register refactor" (#25367) 2025-09-08 19:20:09 +08:00
tests Merge branch 'main' into fix/value-content-rerender-error 2025-09-09 16:40:08 +08:00
.dockerignore Enhance Code Consistency Across Repository with `.editorconfig` (#19023) 2025-04-29 18:04:33 +08:00
.env.example Merge branch 'main' into fix/value-content-rerender-error 2025-09-09 16:40:08 +08:00
.importlinter refactor(graph_engine): Merge branch_handler into edge_processor 2025-09-01 12:53:06 +08:00
.ruff.toml add rule for logging check (#24553) 2025-08-27 10:25:06 +08:00
Dockerfile chore: update uv to 0.8.9 (#23833) 2025-08-12 23:41:39 +08:00
README.md [Chore/Refactor] Switch from MyPy to Basedpyright for type checking (#25047) 2025-09-03 11:52:26 +08:00
app.py r2 2025-06-03 19:02:57 +08:00
app_factory.py [Chore/Refactor] Improve type checking configuration (#25185) 2025-09-05 08:34:18 +08:00
celery_entrypoint.py fix(api): adjust gevent patching 2025-09-03 12:29:39 +08:00
commands.py Merge branch 'feat/queue-based-graph-engine' into feat/rag-2 2025-09-08 14:30:43 +08:00
dify_app.py refactor: assembling the app features in modular way (#9129) 2024-11-30 23:05:22 +08:00
gunicorn.conf.py fix(api): adjust gevent patching 2025-09-03 12:29:39 +08:00
pyproject.toml chore: bump version to 2.0.0-beta.2 2025-09-08 15:19:02 +08:00
pyrightconfig.json refactor: update pyrightconfig.json to use ignore field for better type checking configuration (#25373) 2025-09-08 19:55:25 +08:00
pytest.ini Refactor/remove db from cycle manager (#20455) 2025-05-30 04:34:13 +08:00
ty.toml chore: apply ty checks on api code with script and ci action (#24653) 2025-09-02 16:05:13 +08:00
uv.lock chore: bump version to 2.0.0-beta.2 2025-09-08 15:19:02 +08:00

README.md

Dify Backend API

Usage

[!IMPORTANT]

In the v1.3.0 release, poetry has been replaced with uv as the package manager for Dify API backend service.

  1. Start the docker-compose stack

    The backend require some middleware, including PostgreSQL, Redis, and Weaviate, which can be started together using docker-compose.

    cd ../docker
    cp middleware.env.example middleware.env
    # change the profile to other vector database if you are not using weaviate
    docker compose -f docker-compose.middleware.yaml --profile weaviate -p dify up -d
    cd ../api
    
  2. Copy .env.example to .env

    cp .env.example .env
    
  3. Generate a SECRET_KEY in the .env file.

    bash for Linux

    sed -i "/^SECRET_KEY=/c\SECRET_KEY=$(openssl rand -base64 42)" .env
    

    bash for Mac

    secret_key=$(openssl rand -base64 42)
    sed -i '' "/^SECRET_KEY=/c\\
    SECRET_KEY=${secret_key}" .env
    
  4. Create environment.

    Dify API service uses UV to manage dependencies. First, you need to add the uv package manager, if you don't have it already.

    pip install uv
    # Or on macOS
    brew install uv
    
  5. Install dependencies

    uv sync --dev
    
  6. Run migrate

    Before the first launch, migrate the database to the latest version.

    uv run flask db upgrade
    
  7. Start backend

    uv run flask run --host 0.0.0.0 --port=5001 --debug
    
  8. Start Dify web service.

  9. Setup your application by visiting http://localhost:3000.

  10. If you need to handle and debug the async tasks (e.g. dataset importing and documents indexing), please start the worker service.

uv run celery -A app.celery worker -P gevent -c 1 --loglevel INFO -Q dataset,generation,mail,ops_trace,app_deletion,plugin,workflow_storage,conversation

Addition, if you want to debug the celery scheduled tasks, you can use the following command in another terminal:

uv run celery -A app.celery beat

Testing

  1. Install dependencies for both the backend and the test environment

    uv sync --dev
    
  2. Run the tests locally with mocked system environment variables in tool.pytest_env section in pyproject.toml, more can check Claude.md

    uv run pytest                           # Run all tests
    uv run pytest tests/unit_tests/         # Unit tests only
    uv run pytest tests/integration_tests/  # Integration tests
    
    # Code quality
    ../dev/reformat               # Run all formatters and linters
    uv run ruff check --fix ./    # Fix linting issues
    uv run ruff format ./         # Format code
    uv run basedpyright .         # Type checking