Introduce new env to allow rendering of the data URI scheme #14779

Closed
opened 2026-02-21 19:18:43 -05:00 by yindo · 0 comments
Owner

Originally created by @kurokobo on GitHub (Jun 21, 2025).

Self Checks

  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:)
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

Up to version 0.15.x of Dify, specifying image URLs as strings starting with data: rendered images correctly. This was because the sanitizer in react-markdown 8.x, which is bundled with 0.15.x, allowed this format (the data URI scheme).

## Example: Embed dify icon in markdown as base64-encoded string

![Dify Icon](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAADAAAAAwCAIAAADYYG7QAAADZElEQVR4nOyYQWgiVxzGv+0k5CATuyasmWqT0oMNMYfVtQeRrC0kutTdWkFITAmm4E3oIYfeCmlKe8+hNEi7uTW4JGCkuKYNxNDuoUSFpUlbskS0a6IrC9tmA0ndMq8Mzzqro46mpc1hfgzD8z/f431+838+sIsQgovEC/+3gXoUQ3IohuRQDMmhGJJDMSSHYkgOxZAcXdLS4eHh1tZW9WN3dzfHcaOjoxqNRir+7Sm+/QGvG/EKV1N/8BCpn/AnL4xdNlzubdsRkRCLxaQyhmGcTmcqlaoTez8guEZeulFT/PBzcski1Ol1f1+6SFMaJFTF7XazLFsul7PZbDKZ3NjYSCQS0WjU4XBUNX88E+7lZ+Kse/fx8RfQX8EblkrlRbbteFontL8vfrXd3V2DwQBgYGDg5OSkWi88Jp/dIT8+EKd/eltI5e25DlJpN6HnMRqN4XDYZDIVi8VIJPKm491ESgzg8e/C4O49PHmK1M/COP8IX8UrghtW/pu7d3iet9lsQ0NDtLi5uVkqlQwGg8ViOU9ClJGREQDBYDD2vdgiuEbeel94etVXU3y+h6xWK4C5uUpuZ2dnvb1Cn6+srNQt0dm2Hx4eBpDNZnVX4L8pXKbXxKe3rguVq8KLxcvaisB/E5dZTE1NAYhGo1S5vb19fHzMsqzb7a5fo6OEJicnATidzmrlky/FhCgfhRr00NHREcMwAPb29gghwWAQwOzsrHT1zhLK5XIAOI7raBadYrfbAUQiEZ7n19fXAczMzEiVHRgqFArpdBqA2Wzu1BAAn89H31oymczn8zqdjlo8p6HT09NAIFAul3t6erxe7zkMeTwehmF2dnZCoRD1R19iHa22/erqqlarJYQcHByEw+FMJgNgfn6e47ivv0PpiaChm/zhI9yu9CvSvwj3X4ti5R07NGr09fVNTEzE4/Hl5eVqYA1o0dR1qNXqxcVFqrG+13iHN9v2FGqF/qpJ16U0SEiv1wcCATHDrq7+/n6z2exwOFQqFS3eug7jqy3CrUHz98k6NjZGB9PT003VzZz+u2QymaWlJZfLRc/pXC7XTPkfGVpbW6tGsLCw0ELZ7ln2DxkcHPT7/SqVyuPxjI+Pt1BeUv6wkkExJIdiSA7FkByKITkUQ3IohuS4cIb+CgAA///1U72NT4oCcgAAAABJRU5ErkJggg==)

## Example: Embed SVG

![Red Circle](data:image/svg+xml,%3Csvg%20height%3D%22100%22%20width%3D%22100%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Ccircle%20r%3D%2245%22%20cx%3D%2250%22%20cy%3D%2250%22%20fill%3D%22red%22%20%2F%3E%3C%2Fsvg%3E%20)

## Example: Embed Text File

[Right-click and choose "Save link as..." to download a text file](data:text/plain;base64,SGVsbG8gRGlmeSE=)

However, in Dify 1.x, react-markdown was upgraded to 9.x, and these strings are no longer rendered. This change was made due to security concerns, as maliciously crafted image files could potentially be loaded.

I understand the decision to disallow data URI scheme rendering by default in Dify Cloud.
On the other hand, in self-hosted environments, administrators generally have more control over the files being handled. So, I think it makes sense to have new environment variable to allow rendering of the data URI scheme—as was possible in Dify 0.15.x—if the admin takes responsibility not only for the security implications, but also for the possibility of log files becoming larger.

Therefore, I’d like to propose introducing a new environment variable called ALLOW_UNSAFE_DATA_SCHEME. Setting this to true would allow data URI scheme rendering.
By default, it would be false, of course.

2. Additional context or comments

Related to: https://github.com/langgenius/dify/discussions/21259

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @kurokobo on GitHub (Jun 21, 2025). ### Self Checks - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report (我已阅读并同意 [Language Policy](https://github.com/langgenius/dify/issues/1542)). - [x] [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:) - [x] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. Up to version 0.15.x of Dify, specifying image URLs as strings starting with `data:` rendered images correctly. This was because the sanitizer in `react-markdown` 8.x, which is bundled with 0.15.x, allowed this format (the data URI scheme). ```markdown ## Example: Embed dify icon in markdown as base64-encoded string ![Dify Icon](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAADAAAAAwCAIAAADYYG7QAAADZElEQVR4nOyYQWgiVxzGv+0k5CATuyasmWqT0oMNMYfVtQeRrC0kutTdWkFITAmm4E3oIYfeCmlKe8+hNEi7uTW4JGCkuKYNxNDuoUSFpUlbskS0a6IrC9tmA0ndMq8Mzzqro46mpc1hfgzD8z/f431+838+sIsQgovEC/+3gXoUQ3IohuRQDMmhGJJDMSSHYkgOxZAcXdLS4eHh1tZW9WN3dzfHcaOjoxqNRir+7Sm+/QGvG/EKV1N/8BCpn/AnL4xdNlzubdsRkRCLxaQyhmGcTmcqlaoTez8guEZeulFT/PBzcski1Ol1f1+6SFMaJFTF7XazLFsul7PZbDKZ3NjYSCQS0WjU4XBUNX88E+7lZ+Kse/fx8RfQX8EblkrlRbbteFontL8vfrXd3V2DwQBgYGDg5OSkWi88Jp/dIT8+EKd/eltI5e25DlJpN6HnMRqN4XDYZDIVi8VIJPKm491ESgzg8e/C4O49PHmK1M/COP8IX8UrghtW/pu7d3iet9lsQ0NDtLi5uVkqlQwGg8ViOU9ClJGREQDBYDD2vdgiuEbeel94etVXU3y+h6xWK4C5uUpuZ2dnvb1Cn6+srNQt0dm2Hx4eBpDNZnVX4L8pXKbXxKe3rguVq8KLxcvaisB/E5dZTE1NAYhGo1S5vb19fHzMsqzb7a5fo6OEJicnATidzmrlky/FhCgfhRr00NHREcMwAPb29gghwWAQwOzsrHT1zhLK5XIAOI7raBadYrfbAUQiEZ7n19fXAczMzEiVHRgqFArpdBqA2Wzu1BAAn89H31oymczn8zqdjlo8p6HT09NAIFAul3t6erxe7zkMeTwehmF2dnZCoRD1R19iHa22/erqqlarJYQcHByEw+FMJgNgfn6e47ivv0PpiaChm/zhI9yu9CvSvwj3X4ti5R07NGr09fVNTEzE4/Hl5eVqYA1o0dR1qNXqxcVFqrG+13iHN9v2FGqF/qpJ16U0SEiv1wcCATHDrq7+/n6z2exwOFQqFS3eug7jqy3CrUHz98k6NjZGB9PT003VzZz+u2QymaWlJZfLRc/pXC7XTPkfGVpbW6tGsLCw0ELZ7ln2DxkcHPT7/SqVyuPxjI+Pt1BeUv6wkkExJIdiSA7FkByKITkUQ3IohuS4cIb+CgAA///1U72NT4oCcgAAAABJRU5ErkJggg==) ## Example: Embed SVG ![Red Circle](data:image/svg+xml,%3Csvg%20height%3D%22100%22%20width%3D%22100%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Ccircle%20r%3D%2245%22%20cx%3D%2250%22%20cy%3D%2250%22%20fill%3D%22red%22%20%2F%3E%3C%2Fsvg%3E%20) ## Example: Embed Text File [Right-click and choose "Save link as..." to download a text file](data:text/plain;base64,SGVsbG8gRGlmeSE=) ``` However, in Dify 1.x, `react-markdown` was upgraded to 9.x, and these strings are no longer rendered. This change was made due to security concerns, as maliciously crafted image files could potentially be loaded. - Context: https://github.com/remarkjs/react-markdown/issues/774 I understand the decision to disallow data URI scheme rendering by default in Dify Cloud. On the other hand, in self-hosted environments, administrators generally have more control over the files being handled. So, I think it makes sense to have new environment variable to allow rendering of the data URI scheme—as was possible in Dify 0.15.x—if the admin takes responsibility not only for the security implications, but also for the possibility of log files becoming larger. Therefore, I’d like to propose introducing a new environment variable called `ALLOW_UNSAFE_DATA_SCHEME`. Setting this to `true` would allow data URI scheme rendering. By default, it would be `false`, of course. ### 2. Additional context or comments Related to: https://github.com/langgenius/dify/discussions/21259 ### 3. Can you help us with this feature? - [x] I am interested in contributing to this feature.
yindo added the 💪 enhancement label 2026-02-21 19:18:43 -05:00
yindo closed this issue 2026-02-21 19:18:43 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#14779