mirror of
https://github.com/langgenius/dify-plugin-daemon.git
synced 2026-07-21 17:25:23 -04:00
[RFE] Allow users to sign and verify difypkg files with their own key pairs. #48
Closed
opened 2026-02-16 00:19:23 -05:00 by yindo
·
4 comments
No Branch/Tag Specified
main
build/fix-serverless-runtime-error-propagation
gh-pages
build/test-document2
build/test-document
build/onboarding-ui
build/slim-extract
codex/depot-builds
codex/mac-runner-benchmark
feat/storage-path-prefix
feat/multi-db-user
feat/slim-action
deploy/dev
feat/dify-cli
feat/add-e2e
build/pg-bouncer
codex/add-multimodal-rerank-and-embedding-apis
refactor/local-runtime
build/multimodal-embeddings
codex/refactor-routine.submit-label-handling
codex/refactor-service-layer-based-on-provided-plan
feat/trigger-response
feat/trigger
build/trigger
deploy/trigger-dev
codex/remove-claude-code-reviewer-from-github-ci
codex/add-manifest-check-to-upload-endpoint
feat/no-root-dockerfile
fix/json-schema
fix/blocking-anthorized-langgenius
454-bump-cli-template
build/datasource
feat/datasource
bump-cloud-kit
feat/rag-tag
fix/change-session-not-found-to-400
feat/plugin-readme
add-claude-github-actions-1756274550417
docs/comprehensive-development-documentation
chore/remove-json-schema-validation-error
71cef04
fix/missing-parameter-type
fix/sessions-log
fix/template.env
bump/go-git
build/oauth
feat/oauth-refresh-token
feat/plugin-oauth
feat/tool-oauth-cli
build/plugin-oauth
feat/readme-i18n
fix/memory-leak
feat/icon-dark
feat/default-icon
plugin_launch_concurent
feat/collect-active-requests
feat/dark-icon
feat/support-structured-llm-output
feat/dynamic-selector
fix/reduce-logs
feat/decode-plugin-package
feat/db-extras
fix/backwards-invocation-overflow
feat/length-prefixed-chunking
fix/http-request-reader-header
chore/unify-configurations
fix/hardcoded-serverless-runtime-timeout
fix/cmd
fix/signature
refactor/implement-gen-routes
fix/redis-lock
refactor/codegen
feat/add-authorized-category
chore/style
feat/run-plugin-cli
reduce/run-once
feat/reinstall-serverless-runtime
feat/support-setup-process
fix/apply-stdio-buffer-size
chore/add-warning-messages-to-installed-bucket
feat/repo
enhance/stdio
feat/make-buffer-size-configurable
fix/moderation-init
fix/only-validate-profile-on-quick-mode
feat/support-quick-init-plugins
refactor/oauth-parameters
feat/oauth
refactor/simplify-plugin-invocation
test/integration-test-for-plugins
fix/backwards-compatible-to-llm-result-chunk
feat/auto-scale
enhance/reduce-ci-tests
fix/cli-ci
enhance/removes-llm-result-prompt-messages
fix/disable-benchmark-logs
benchmark/local-runtime
chore/remove-useless-benchmark
feat/benchmark
feat/fetch-app-info
fix/windows-remap-assets
fix/skip-hidden-file
feat/stream-tool-blob-message
fix/path-travel
feat/template-add-ci
enhance/version-compare
feat/sign-apple-os-cli
feat/support-minimal-dify-version-required
refactor/stdip
feat/add-serverless-connector-launching-timeout
fix/remove-prompt_messages-from-llm-result-chunk
feat/standardize-plugin-sdk-versions
chore/update-docs-and-refine-wording
update/readme-cli
fix/infinity-environment-setup
fix/cbor-unmarshaling
fix/use-aws-iam-baseendpoint
fix/lost-query-params-in-endpoint
fix/tiktoken
cohre/update-readme
fix/redis-tests
fix/friendly-identity
fix/marshal-any-map
chore/upgrade-ants
fix/graceful-precompile
enhance/tiktoken
feat/graceful-shutdown
fix/close-serverless-response
fix/correct-cli-guide
fix/plugin-active-log
fix/remove-proxy-args-from-uv
fix/endpoint-hook-url
fix/ci-credentials
feat/disable-gevent
fix/add-gcc
fix/hardcoded-endpoint-timeout
fix/bump-cli-sdk-version
fix/deadloop-when-redis-disconnect
fix/enhence/speed-up-environment-setup
enhance/introduce-uv
fix/change-default-db
fix/deadlock
readme
chore/env.example
feat/add-action-in-url
fix/add-more-pip-args
fix/optimize-local-heartbeat
optimize/db-init
fix/optimize-internal-server-error
fix/increase-default-plugin-max-execution-timeout
fix/force-patch-older-version
enhance/increase-installing-process
LICENSE
fix/set-user-id-to-unrequired
fix/max-launching-concurrent
improve/error-handing-in-serverless
refactor/json-unmarshaler-enhancement
fix/add-pip-mirror-url
enhance/serverless-connector
0.6.5
0.6.4
0.6.3
0.6.2
0.6.1
0.6.0
0.5.9
0.5.8
0.5.7
0.5.6
0.5.5
0.5.4
0.5.3
0.5.2
0.5.1
0.5.0
0.4.1
0.4.0
0.3.3
0.3.2
0.3.1
0.3.0
0.3.0b1
0.2.0
0.1.3
0.1.2
0.1.1
0.1.0
0.0.10
0.0.9
0.0.8
0.0.7
0.0.6
0.0.5
0.0.4
0.0.3
0.0.2
0.0.1
0.0.1-beta.23
0.0.1-beta.22
0.0.1-beta.21
0.0.1-beta.20
0.0.1-beta.19
0.0.1-beta.18
0.0.1-beta.17
0.0.1-beta.16
0.0.1-beta.15
0.0.1-beta.14
0.0.1-beta.13
0.0.1-beta.12
0.0.1-beta.11
0.0.1-beta.10
0.0.1-beta.9
0.0.1-beta.8
0.0.1-beta.7
0.0.1-beta.6
0.0.1-beta.5
0.0.1-beta.4
0.0.1-beta.3
0.0.1-beta.2
0.0.1-beta.1
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: langgenius/dify-plugin-daemon#48
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @kurokobo on GitHub (Mar 18, 2025).
In the current implementation, signature verification for
difypkgcan only be performed with the public key embedded in the executable of the daemon. Onlydifypkgfiles signed with Dify's private key are currently supported.Therefore, if someone wants to introduce a self-developed plugin in their self-hosted environment at a company, they have no choice but to set
FORCE_VERIFYING_SIGNATUREtofalse. However, this poses the risk of allowing the installation of unsafe unauthorized plugins.I believe supporting the following scenarios would be especially useful in enterprise environments and beneficial not only for users of the free community edition but also for enterprise edition users.
cmd/licenseif we mamually build it)difypkgwith any private key (this already can be done withcmd/licenseif we mamually build it)@Yeuoly commented on GitHub (Mar 20, 2025):
I agree, it makes sense to allowing users to specific their own private key, but It's hard to make sure the safety of plugins, for personal use and company self-deployed use, they may want a keychains, use different key to verify different plugins, maybe a folder named .keychains? how do you think of it
@kurokobo commented on GitHub (Mar 22, 2025):
@Yeuoly
Thanks for your feedback!
If the daemon unconditionally trusts all keys within a specific folder like
.keychains/*.pem, it could lead to issues where unintended keys are trusted due to user error or some malicious attack. As the first step, wouldn't it suffice to specify the paths of the trusted key files as a semicolon-separated list in an environment variable?Below are implementation ideas.
Step 1: Add a feature to the existing
dify-pluginCLI to generate key pairs and sign difypkg file using the specified private key as an argument.Step 2: Add a feature to the daemon to verify signatures using the list of public keys specified by an environment variable.
Step 3: Once it has been confirmed that the features up to Step 2 are sufficiently effective, enable management of trusted public keys for each workspace through a web GUI as part of the workspace management functionality. The public keys will be registered in the database.
@benjamin-mogensen commented on GitHub (Mar 23, 2025):
I have previously worked with application signing and Microsoft and Apple has some more rigorous processes in place that ensure trusted software. This involves both signing with a trusted certificate issued by a trusted provider as well as notarization where you upload your software to them for scanning and if they approve your app is fully notarized and can then be made available in their App Store. Now, this process is quite complex and I am not sure if Dify would go down that kind of route and maybe this would also only be applicable to the public cloud version of Dify and not so much for self hosted one.
I do think that if running enterprise edition we could allow install of unsigned plugins and at the same time only allow admins to install plugins that way the security risk of malicious code is minimized IMO.
@kurokobo commented on GitHub (Mar 23, 2025):
@Yeuoly
I have implemented Step 1 and Step 2 from my above comment as a proof of concept and created a draft PR: https://github.com/langgenius/dify-plugin-daemon/pull/137.
I would appreciate it if you (or of course anyone here!) could try it out if possible.
✨ New sub commands for CLI
Ready-to-Use binaries: https://github.com/kurokobo/dify-plugin-daemon/releases/tag/0.0.6%2Bsignature%2Bp02
✨ New environment variables for daemon
Ready-to-Use container images: https://github.com/kurokobo/dify-plugin-daemon/pkgs/container/dify-plugin-daemon
✨ Example Configuration Steps
For Self-Hosted Dify 1.0+ only. Not applicable for Cloud edition.
dify-pluginbinary from the release page of forked demo projectdify-plugin plugin packagecommandmyorg.private.pemandmyorg.public.pemmyorg.private.pemmy-custom-plugin.signed.difypkgverifycommandpublic_keysunder yourdocker/volumes/plugin_daemonmyorg.public.pem(Public Key) underdocker/volumes/plugin_daemon/public_keysdocker-compose.override.yamlfile with following content, on the next to yourdocker-compose.yamlmy-custom-plugin.signed.difypkg.