The token abuse problem existing in the URL application generated by "Run App" #14793

Closed
opened 2026-02-21 19:18:47 -05:00 by yindo · 1 comment
Owner

Originally created by @Cc-a23187 on GitHub (Jun 22, 2025).

Self Checks

  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:)
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

Regarding the issue of clicking "Run App" to complete the Workflow and then generating a link

After writing the Workflow and clicking "Run App", a link with a key will be redirected. If this is on the public network, it can be accessed by anyone. How can we prevent the token from being misused?
It has been tested that there is no similar timing mechanism. cloud dify executes the link generated by the run app, and it can be accessed and executed two days later.

Image

2. Additional context or comments

Related discussion: https://github.com/langgenius/dify/discussions/6356
Discussion in the discord channel thread: https://discord.com/channels/1082486657678311454/1385521615315664988
Question in the discord understanding-dify channel: https://discord.com/channels/1082486657678311454/1385522648498442251

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @Cc-a23187 on GitHub (Jun 22, 2025). ### Self Checks - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report (我已阅读并同意 [Language Policy](https://github.com/langgenius/dify/issues/1542)). - [x] [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:) - [x] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. ### Regarding the issue of clicking "Run App" to complete the Workflow and then generating a link After writing the Workflow and clicking "Run App", a link with a key will be redirected. If this is on the public network, it can be accessed by anyone. How can we prevent the token from being misused? It has been tested that there is no similar timing mechanism. cloud dify executes the link generated by the run app, and it can be accessed and executed two days later. ![Image](https://github.com/user-attachments/assets/b23d629f-109e-4bce-874b-395ede927c67) ### 2. Additional context or comments Related discussion: https://github.com/langgenius/dify/discussions/6356 Discussion in the discord channel thread: https://discord.com/channels/1082486657678311454/1385521615315664988 Question in the discord _understanding-dify_ channel: https://discord.com/channels/1082486657678311454/1385522648498442251 ### 3. Can you help us with this feature? - [ ] I am interested in contributing to this feature.
yindo closed this issue 2026-02-21 19:18:47 -05:00
Author
Owner

@dosubot[bot] commented on GitHub (Aug 18, 2025):

Hi, @Cc-a23187. I'm Dosu, and I'm helping the Dify team manage their backlog and am marking this issue as stale.

Issue Summary:

  • You raised a security concern about the "Run App" feature generating URLs with tokens that remain valid and publicly accessible for at least two days.
  • This creates a risk of token misuse due to prolonged token validity.
  • You requested a mechanism to prevent unauthorized access or abuse of these tokens.
  • There has been no further activity or responses on this issue so far.

Next Steps:

  • Please let me know if this issue is still relevant to the latest version of Dify by commenting here to keep the discussion open.
  • Otherwise, this issue will be automatically closed in 15 days.

Thank you for your understanding and contribution!

@dosubot[bot] commented on GitHub (Aug 18, 2025): Hi, @Cc-a23187. I'm [Dosu](https://dosu.dev), and I'm helping the Dify team manage their backlog and am marking this issue as stale. **Issue Summary:** - You raised a security concern about the "Run App" feature generating URLs with tokens that remain valid and publicly accessible for at least two days. - This creates a risk of token misuse due to prolonged token validity. - You requested a mechanism to prevent unauthorized access or abuse of these tokens. - There has been no further activity or responses on this issue so far. **Next Steps:** - Please let me know if this issue is still relevant to the latest version of Dify by commenting here to keep the discussion open. - Otherwise, this issue will be automatically closed in 15 days. Thank you for your understanding and contribution!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#14793