dify/api
GareArc f533e992d4
fix(hitl): scope OpenAPI/Service-API resume to author-configured webapp forms
Pause-time token emission now draws only from the recipient set each API
surface is allowed to act on (emit ⊆ validate), so the CLI/OpenAPI caller is
never handed a token the resume endpoint would reject as 404 (WTA-867).

A form's recipients are partitioned once, per surface, into a single
FormDisposition: the surface-actionable recipient yields `form_token`, while
the rest are reported as `approval_channels` (e.g. ["email", "console"]) so the
caller is told where approval actually happens. Token and channels are two
projections of one decision (disposition_for_surface) loaded by one recipient
query (load_form_dispositions_by_form_id); the live pause path and the
reconnect snapshot path consume the same FormDisposition so they cannot drift.

RecipientType carries its user-facing approval-channel label as an enum tuple
value, set in __new__, so a new recipient type cannot be declared without one.

Tests: consolidate recipient/disposition/enrich tests into parametrized
matrices, add CONSOLE-surface and empty-token coverage, extract a shared fake
session for the pause-event tests.
2026-06-16 16:11:29 -07:00
..
.idea
.vscode feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
clients feat(api): Agent ask_human HITL (phase-1) — workflow node + Agent v2 chat — ENG-635 (#37437) 2026-06-16 03:43:40 +00:00
commands feat(web): refine onboarding UI (#37433) 2026-06-15 08:47:15 +00:00
configs fix(api): add bounded timeouts to Nacos remote settings HTTP requests (#37444) 2026-06-16 07:42:51 +00:00
constants feat(api): Agent App type S1 — AppMode.AGENT + create flow + binding (#36829) 2026-06-02 03:50:10 +00:00
context chore(api): convert AppContext from ABC to Protocol (#37203) 2026-06-09 03:16:39 +00:00
contexts chore(api): align Python support with 3.12 (#34419) 2026-04-02 05:07:32 +00:00
controllers fix(hitl): scope OpenAPI/Service-API resume to author-configured webapp forms 2026-06-16 16:11:29 -07:00
core fix(hitl): scope OpenAPI/Service-API resume to author-configured webapp forms 2026-06-16 16:11:29 -07:00
dev fix: GET query parameter OpenAPI contracts (#37378) 2026-06-12 09:01:22 +00:00
docker fix: add miss celery queue (#35282) 2026-04-16 02:40:14 +00:00
enterprise ci: add flag for linter (#37018) 2026-06-08 04:53:12 +00:00
enums refactor: quota v3 integration (#35436) 2026-04-27 01:49:40 +00:00
events feat: add cross-environment app migration workflow (#36765) 2026-05-28 07:30:33 +00:00
extensions feat(api): Agent ask_human HITL (phase-1) — workflow node + Agent v2 chat — ENG-635 (#37437) 2026-06-16 03:43:40 +00:00
factories fix: validate conversation variable description length to prevent varchar(255) truncation error (#33038) 2026-06-10 07:28:12 +00:00
fields fix(agent): include app display fields in published references (#37485) 2026-06-16 07:00:37 +00:00
libs refactor: fix OpenAPI contract generation schemas (#37387) 2026-06-12 14:25:53 +00:00
migrations feat(api): Agent ask_human HITL (phase-1) — workflow node + Agent v2 chat — ENG-635 (#37437) 2026-06-16 03:43:40 +00:00
models fix(hitl): scope OpenAPI/Service-API resume to author-configured webapp forms 2026-06-16 16:11:29 -07:00
openapi/markdown fix: issue (#37508) 2026-06-16 08:53:53 +00:00
providers refactor: type remaining bare dict annotations (#37422) 2026-06-14 13:29:02 +00:00
repositories chore(api): convert RecommendAppRetrievalBase and WorkflowPauseEntity from ABC to Protocol (#37182) 2026-06-08 14:17:07 +00:00
schedule feat(web): refine onboarding UI (#37433) 2026-06-15 08:47:15 +00:00
services fix(hitl): scope OpenAPI/Service-API resume to author-configured webapp forms 2026-06-16 16:11:29 -07:00
tasks fix(api): Agent v2 chat ask_human — resume on timeout + skip input guards on resume (#37492) 2026-06-16 08:11:28 +00:00
templates feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
tests fix(hitl): scope OpenAPI/Service-API resume to author-configured webapp forms 2026-06-16 16:11:29 -07:00
.dockerignore
.env.example fix(api): add bounded timeouts to Nacos remote settings HTTP requests (#37444) 2026-06-16 07:42:51 +00:00
.importlinter refactor(api): use standalone graphon package (#34209) 2026-03-27 21:05:32 +00:00
.ruff.toml chore: reorg imports (#35308) 2026-04-16 08:50:02 +00:00
AGENTS.md feat(api): Flask-RESTX response() vs actual return value checker (#36488) 2026-05-21 15:05:06 +00:00
app_factory.py chore(api): clean redundant type ignores (Fixes #24494) (#37358) 2026-06-12 03:56:56 +00:00
app.py chore(api): clean redundant type ignores (Fixes #24494) (#37358) 2026-06-12 03:56:56 +00:00
celery_entrypoint.py chore(api): clean redundant type ignores (Fixes #24494) (#37358) 2026-06-12 03:56:56 +00:00
celery_healthcheck.py fix: lighten the health checks for the Worker and Worker Beat services, and disable them by default (#34572) 2026-04-06 02:26:26 +00:00
cnt_base.sh add cnt script and one more example (#28272) 2025-11-18 16:44:14 +09:00
conftest.py test(api): manage backend pytest services natively (#36235) 2026-05-19 07:52:15 +00:00
dify_app.py refactor(api): tighten login and wrapper typing (#34447) 2026-04-02 09:36:58 +00:00
Dockerfile feat(api): introduce select, file and file list form input types to Human Input node (#36322) 2026-06-04 01:54:28 +00:00
Dockerfile.dockerignore fix(api): fix incorrect docker build context (#37438) 2026-06-15 06:29:58 +00:00
gunicorn.conf.py chore(api): clean redundant type ignores (Fixes #24494) (#37358) 2026-06-12 03:56:56 +00:00
pyproject.toml chore: update to openapi v3 by change dep (#37316) 2026-06-12 07:52:19 +00:00
pyrefly-local-excludes.txt chore(api): Fix several typing errors (#37248) 2026-06-12 14:02:09 +00:00
pytest.ini chore: add pytest XML and branch coverage reports (#33730) 2026-03-19 17:08:34 +08:00
README.md chore: Remove pyright in favor of pyrefly (#36154) 2026-05-14 05:49:08 +00:00
uv.lock chore: update to openapi v3 by change dep (#37316) 2026-06-12 07:52:19 +00:00

Dify Backend API

Setup and Run

Important

In the v1.3.0 release, poetry has been replaced with uv as the package manager for Dify API backend service.

uv and pnpm are required to run the setup and development commands below.

The scripts resolve paths relative to their location, so you can run them from anywhere.

  1. Run setup (copies env files and installs dependencies).

    ./dev/setup
    
  2. Review api/.env, web/.env.local, and docker/middleware.env values (see the SECRET_KEY note below).

  3. Start middleware (PostgreSQL/Redis/Weaviate).

    ./dev/start-docker-compose
    
  4. Start backend (runs migrations first).

    ./dev/start-api
    
  5. Start Dify web service.

    ./dev/start-web
    

    ./dev/setup and ./dev/start-web install JavaScript dependencies through the repository root workspace, so you do not need a separate cd web && pnpm install step.

  6. Set up your application by visiting http://localhost:3000.

  7. Start the worker service (async and scheduler tasks, runs from api).

    ./dev/start-worker
    
  8. Optional: start Celery Beat (scheduled tasks).

    ./dev/start-beat
    

Environment notes

Important

When the frontend and backend run on different subdomains, set COOKIE_DOMAIN to the sites top-level domain (e.g., example.com). The frontend and backend must be under the same top-level domain in order to share authentication cookies.

  • Generate a SECRET_KEY in the .env file.

    bash for Linux

    sed -i "/^SECRET_KEY=/c\\SECRET_KEY=$(openssl rand -base64 42)" .env
    

    bash for Mac

    secret_key=$(openssl rand -base64 42)
    sed -i '' "/^SECRET_KEY=/c\\
    SECRET_KEY=${secret_key}" .env
    

Testing

  1. Install dependencies for both the backend and the test environment

    cd api
    uv sync --group dev
    
  2. Run the tests locally with mocked system environment variables in tool.pytest_env section in pyproject.toml, more can check Claude.md

    cd api
    uv run pytest                           # Run all tests
    uv run pytest tests/unit_tests/         # Unit tests only
    uv run pytest tests/integration_tests/  # Integration tests
    
    # Code quality
    ./dev/reformat               # Run all formatters and linters
    uv run ruff check --fix ./   # Fix linting issues
    uv run ruff format ./        # Format code
    uv run pyrefly check         # Type checking
    

Generate TS stub

uv run dev/generate_swagger_specs.py --output-dir openapi

use https://jsontotable.org/openapi-to-typescript to convert to typescript