Potential Data Exposure: KB IDs Included in Exported App DSL #12079

Closed
opened 2026-02-21 19:05:39 -05:00 by yindo · 1 comment
Owner

Originally created by @1Ckpwee on GitHub (Mar 25, 2025).

Originally assigned to: @Gevtolev, @JohnJyong on GitHub.

Self Checks

  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

1.1.3

Cloud or Self Hosted

Cloud

Steps to reproduce

  1. Use export app with default settings (include_secret=false).
  2. Check the exported DSL and observe that it includes KB ids.

✔️ Expected Behavior

  • Clarification on whether KB ids should be included in the export by default.
  • If included, documentation or API guidelines should highlight potential risks.
  • Consider adding an additional parameter to allow users to control whether KB ids are included.

Actual Behavior

Users should be prompted whether to expose the KB ids

Originally created by @1Ckpwee on GitHub (Mar 25, 2025). Originally assigned to: @Gevtolev, @JohnJyong on GitHub. ### Self Checks - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report (我已阅读并同意 [Language Policy](https://github.com/langgenius/dify/issues/1542)). - [x] [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version 1.1.3 ### Cloud or Self Hosted Cloud ### Steps to reproduce 1. Use export app with default settings (include_secret=false). 2. Check the exported DSL and observe that it includes KB ids. ### ✔️ Expected Behavior - Clarification on whether KB ids should be included in the export by default. - If included, documentation or API guidelines should highlight potential risks. - Consider adding an additional parameter to allow users to control whether KB ids are included. ### ❌ Actual Behavior Users should be prompted whether to expose the KB ids
yindo added the 🐞 bug📚 documentation labels 2026-02-21 19:05:39 -05:00
yindo closed this issue 2026-02-21 19:05:39 -05:00
Author
Owner

@dosubot[bot] commented on GitHub (Mar 25, 2025):

The issue raised highlights a concern about KB IDs being included in the exported DSL by default in Dify version 1.1.3. The expected behavior is to have clarification on whether KB IDs should be included by default and, if so, to have documentation or API guidelines that address potential risks. Additionally, it suggests adding a parameter to control the inclusion of KB IDs and prompting users about their exposure.

Currently, the Dify documentation mentions a prompt related to the export of sensitive information, specifically for environment variables marked as Secret [1]. However, there is no specific mention of KB IDs in the documentation or codebase regarding their inclusion or exclusion in exported DSL, nor are there security guidelines or best practices related to handling KB IDs during export. It might be beneficial to address these concerns in the documentation or through additional features in the platform.

To continue talking to Dosu, mention @dosu.


Help Dosu learn! Give it feedback: Great Response | Irrelevant Answer | Incorrect Sources | Too Verbose | Hallucination | Bug Report | Other

@dosubot[bot] commented on GitHub (Mar 25, 2025): <!-- Answer --> The issue raised highlights a concern about KB IDs being included in the exported DSL by default in Dify version 1.1.3. The expected behavior is to have clarification on whether KB IDs should be included by default and, if so, to have documentation or API guidelines that address potential risks. Additionally, it suggests adding a parameter to control the inclusion of KB IDs and prompting users about their exposure. Currently, the Dify documentation mentions a prompt related to the export of sensitive information, specifically for environment variables marked as `Secret` <sup>[[1]](https://github.com/langgenius/dify-docs/blob/main/en/guides/management/app-management.md)</sup>. However, there is no specific mention of KB IDs in the documentation or codebase regarding their inclusion or exclusion in exported DSL, nor are there security guidelines or best practices related to handling KB IDs during export. It might be beneficial to address these concerns in the documentation or through additional features in the platform. <!-- Dosu Comment Footer --> *To continue talking to [Dosu](https://dosu.dev), mention @dosu.* --- <sup>Help Dosu learn! Give it feedback: [Great Response](https://app.dosu.dev/response-feedback/e4268dc9-7882-49f2-95ac-215751e01dd0?feedback_type=great_response) | [Irrelevant Answer](https://app.dosu.dev/response-feedback/e4268dc9-7882-49f2-95ac-215751e01dd0?feedback_type=irrelevant_answer) | [Incorrect Sources](https://app.dosu.dev/response-feedback/e4268dc9-7882-49f2-95ac-215751e01dd0?feedback_type=incorrect_sources) | [Too Verbose](https://app.dosu.dev/response-feedback/e4268dc9-7882-49f2-95ac-215751e01dd0?feedback_type=too_verbose) | [Hallucination](https://app.dosu.dev/response-feedback/e4268dc9-7882-49f2-95ac-215751e01dd0?feedback_type=hallucination) | [Bug Report](https://app.dosu.dev/response-feedback/e4268dc9-7882-49f2-95ac-215751e01dd0?feedback_type=bug_report) | [Other](https://app.dosu.dev/response-feedback/e4268dc9-7882-49f2-95ac-215751e01dd0?feedback_type=other)</sup>
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#12079