The workflow API lacks validation for file upload methods #11229

Closed
opened 2026-02-21 18:57:12 -05:00 by yindo · 0 comments
Owner

Originally created by @lrhan321 on GitHub (Mar 16, 2025).

Self Checks

  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

1.0.1

Cloud or Self Hosted

Self Hosted (Docker), Self Hosted (Source)

Steps to reproduce

  1. Create a workflow, add a file variable at the start node, specify the upload method as local, and then publish the workflow.
  2. Create an API key, and request the workflow through the API, specifying the transfer_method of the file as remote_url, and provide a valid url.

Image

✔️ Expected Behavior

The workflow API should not run properly because the upload method was specified as "local" during orchestration.

Actual Behavior

The workflow can run successfully, which is inconsistent with the behavior defined by the orchestration. Additionally, this may lead to unforeseen issues later on.

Image

Originally created by @lrhan321 on GitHub (Mar 16, 2025). ### Self Checks - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report (我已阅读并同意 [Language Policy](https://github.com/langgenius/dify/issues/1542)). - [x] [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version 1.0.1 ### Cloud or Self Hosted Self Hosted (Docker), Self Hosted (Source) ### Steps to reproduce 1. Create a workflow, add a file variable at the start node, specify the upload method as local, and then publish the workflow. 2. Create an API key, and request the workflow through the API, specifying the `transfer_method` of the file as `remote_url`, and provide a valid `url`. ![Image](https://github.com/user-attachments/assets/a6074d76-921c-42dc-8661-ed2453b60586) ### ✔️ Expected Behavior The workflow API should not run properly because the upload method was specified as "local" during orchestration. ### ❌ Actual Behavior The workflow can run successfully, which is inconsistent with the behavior defined by the orchestration. Additionally, this may lead to unforeseen issues later on. ![Image](https://github.com/user-attachments/assets/0abc7858-266f-46ad-91e2-e142b3f43b7a)
yindo added the 🐞 bug label 2026-02-21 18:57:12 -05:00
yindo closed this issue 2026-02-21 18:57:12 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#11229