Metadata API allows null values but crashes in business logic layer (TypeError) #15757

Closed
opened 2026-02-21 19:23:11 -05:00 by yindo · 2 comments
Owner

Originally created by @lyzno1 on GitHub (Jul 29, 2025).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

main

Cloud or Self Hosted

Cloud

Steps to reproduce

  1. Send POST request to create metadata with null values:

    curl -X POST "/console/api/datasets/{dataset_id}/metadata" \
      -H "Content-Type: application/json" \
      -d '{"type": null, "name": null}'
    
  2. The request passes API validation but crashes in service layer

Code locations where the bug occurs:

API Layer (incorrectly allows null):

Business Logic Layer (crashes on null):

✔️ Expected Behavior

API should reject null values and return 400 Bad Request:

{
  "message": "Input payload validation failed",
  "errors": {
    "name": "Missing required parameter in the JSON body"
  }
}

Actual Behavior

No response

Originally created by @lyzno1 on GitHub (Jul 29, 2025). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version main ### Cloud or Self Hosted Cloud ### Steps to reproduce 1. **Send POST request to create metadata with null values:** ```bash curl -X POST "/console/api/datasets/{dataset_id}/metadata" \ -H "Content-Type: application/json" \ -d '{"type": null, "name": null}' ``` 2. **The request passes API validation but crashes in service layer** ### Code locations where the bug occurs: **API Layer (incorrectly allows null):** - [`api/controllers/console/datasets/metadata.py:25-26`](https://github.com/langgenius/dify/blob/main/api/controllers/console/datasets/metadata.py#L25-L26) - [`api/controllers/console/datasets/metadata.py:59`](https://github.com/langgenius/dify/blob/main/api/controllers/console/datasets/metadata.py#L59) - [`api/controllers/service_api/dataset/metadata.py:20-21`](https://github.com/langgenius/dify/blob/main/api/controllers/service_api/dataset/metadata.py#L20-L21) - [`api/controllers/service_api/dataset/metadata.py:46`](https://github.com/langgenius/dify/blob/main/api/controllers/service_api/dataset/metadata.py#L46) **Business Logic Layer (crashes on null):** - [`api/services/metadata_service.py:23`](https://github.com/langgenius/dify/blob/main/api/services/metadata_service.py#L23) - [`api/services/metadata_service.py:50`](https://github.com/langgenius/dify/blob/main/api/services/metadata_service.py#L50) ### ✔️ Expected Behavior API should reject null values and return 400 Bad Request: ```json { "message": "Input payload validation failed", "errors": { "name": "Missing required parameter in the JSON body" } } ``` ### ❌ Actual Behavior _No response_
yindo added the 🐞 bug label 2026-02-21 19:23:11 -05:00
yindo closed this issue 2026-02-21 19:23:11 -05:00
Author
Owner

@lyzno1 commented on GitHub (Jul 29, 2025):

@dosubot please review this bug.

@lyzno1 commented on GitHub (Jul 29, 2025): @dosubot please review this bug.
Author
Owner

@dosubot[bot] commented on GitHub (Jul 29, 2025):

This bug is valid and reproducible. The root cause is that the API controllers for dataset metadata creation and update use reqparse with required=True but nullable=True for the type and name fields, which allows null values to pass validation and reach the service layer without checks. The service layer then tries to use these values directly, leading to crashes like TypeError when nulls are encountered (source, source).

The immediate fix is to update the API layer to use nullable=False for all required fields in reqparse, or add explicit null checks and raise a ValueError or LLMBadRequestError to return a 400 Bad Request with a clear error message (source). This pattern is already used in other endpoints and is considered best practice in the codebase.

This validation gap (required=True but nullable=True) appears in multiple endpoints, so a broader audit is recommended to ensure all required fields are properly validated at the API layer to prevent similar issues elsewhere. Adding or updating tests to confirm nulls are rejected at the API boundary will help prevent regressions.

To reply, just mention @dosu.


How did I do? Good | Irrelevant | Incorrect | Verbose | Hallucination | Report 🐛 | Other  Chat with Dosu Join Discord Share on X

@dosubot[bot] commented on GitHub (Jul 29, 2025): <!-- Answer --> This bug is valid and reproducible. The root cause is that the API controllers for dataset metadata creation and update use `reqparse` with `required=True` but `nullable=True` for the `type` and `name` fields, which allows null values to pass validation and reach the service layer without checks. The service layer then tries to use these values directly, leading to crashes like `TypeError` when nulls are encountered ([source](https://github.com/langgenius/dify/blob/main/api/controllers/console/datasets/metadata.py#L25-L26), [source](https://github.com/langgenius/dify/blob/main/api/services/metadata_service.py#L23)). The immediate fix is to update the API layer to use `nullable=False` for all required fields in `reqparse`, or add explicit null checks and raise a `ValueError` or `LLMBadRequestError` to return a 400 Bad Request with a clear error message ([source](https://github.com/langgenius/dify/blob/main/api/controllers/console/workspace/tool_providers.py)). This pattern is already used in other endpoints and is considered best practice in the codebase. This validation gap (required=True but nullable=True) appears in multiple endpoints, so a broader audit is recommended to ensure all required fields are properly validated at the API layer to prevent similar issues elsewhere. Adding or updating tests to confirm nulls are rejected at the API boundary will help prevent regressions. <!-- Dosu Comment Footer --> *To reply, just mention [@dosu](https://go.dosu.dev/dosubot).* --- <sup>How did I do? [Good](https://app.dosu.dev/response-feedback/8cf2b693-05f6-441c-991a-1f4efb07c88a?feedback_type=great_response) | [Irrelevant](https://app.dosu.dev/response-feedback/8cf2b693-05f6-441c-991a-1f4efb07c88a?feedback_type=irrelevant_answer) | [Incorrect](https://app.dosu.dev/response-feedback/8cf2b693-05f6-441c-991a-1f4efb07c88a?feedback_type=incorrect_sources) | [Verbose](https://app.dosu.dev/response-feedback/8cf2b693-05f6-441c-991a-1f4efb07c88a?feedback_type=too_verbose) | [Hallucination](https://app.dosu.dev/response-feedback/8cf2b693-05f6-441c-991a-1f4efb07c88a?feedback_type=hallucination) | [Report 🐛](https://app.dosu.dev/response-feedback/8cf2b693-05f6-441c-991a-1f4efb07c88a?feedback_type=bug_report) | [Other](https://app.dosu.dev/response-feedback/8cf2b693-05f6-441c-991a-1f4efb07c88a?feedback_type=other)</sup>&nbsp;&nbsp;[![Chat with Dosu](https://dosu.dev/dosu-chat-badge.svg)](https://app.dosu.dev/6088a4f4-073a-43f3-b3d4-4f06fb0c05a0/ask?utm_source=github)&nbsp;[![Join Discord](https://img.shields.io/badge/join-5865F2?logo=discord&logoColor=white&label=)](https://go.dosu.dev/discord-bot)&nbsp;[![Share on X](https://img.shields.io/badge/X-share-black)](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/langgenius/dify/issues/23132)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#15757