[Enhancement/Refactor] Add caller info to restrict access #15826

Closed
opened 2026-02-21 19:23:31 -05:00 by yindo · 0 comments
Owner

Originally created by @DavideDelbianco on GitHub (Aug 1, 2025).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

I've recently had a spike in the usage of a workflow because the embedded chatbot does not restrict traffic by any means, and simply copying the JavaScript code that generates the chat bubble is enough to import it on any other website.

I have resolved the issue by creating a proxy service that restricts inbound traffic.

Not everyone is able to manage traffic by firewall services / proxying, and it would probably help something more user-friendly like:
Add an "allowed sources" in the app configuration settings, or the possibility to expose to the workflow the caller details (Browser Agent, IP, Referrer URL, etc...)

2. Additional context or comments

No response

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @DavideDelbianco on GitHub (Aug 1, 2025). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. I've recently had a spike in the usage of a workflow because the embedded chatbot does not restrict traffic by any means, and simply copying the JavaScript code that generates the chat bubble is enough to import it on any other website. I have resolved the issue by creating a proxy service that restricts inbound traffic. Not everyone is able to manage traffic by firewall services / proxying, and it would probably help something more user-friendly like: Add an "allowed sources" in the app configuration settings, or the possibility to expose to the workflow the caller details (Browser Agent, IP, Referrer URL, etc...) ### 2. Additional context or comments _No response_ ### 3. Can you help us with this feature? - [ ] I am interested in contributing to this feature.
yindo added the 💪 enhancement label 2026-02-21 19:23:31 -05:00
yindo closed this issue 2026-02-21 19:23:31 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#15826