[PR #11450] fix(datasets): add created_by to ApiToken for get datasets from api correct current user #27225

Closed
opened 2026-02-21 20:41:06 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/11450

State: closed
Merged: No


Summary

This PR Fixes #11331. The problem was that admin-created API keys always showed the owner’s dataset list, even when the owner set “Only Me” permissions.

I added a new field, created_by, to the ApiToken model to track who created each API key. This makes sure the correct user and permissions are used when accessing datasets.

In the web console, users will now only see the Datasets API keys they created. Old keys without the created_by field will still work fine.

Screenshots

Before After
image image
image image

Checklist

Important

Please review the checklist below before submitting your pull request.

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/11450 **State:** closed **Merged:** No --- # Summary This PR Fixes #11331. The problem was that admin-created API keys always showed the owner’s dataset list, even when the owner set “Only Me” permissions. I added a new field, `created_by`, to the `ApiToken` model to track who created each API key. This makes sure the correct user and permissions are used when accessing datasets. In the web console, users will now only see the Datasets API keys they created. Old keys without the `created_by` field will still work fine. # Screenshots | Before | After | |--------|-------| | <img width="677" alt="image" src="https://github.com/user-attachments/assets/1d9ab47f-33d8-4145-b007-6eefa9a75854"> | <img width="631" alt="image" src="https://github.com/user-attachments/assets/1ef08a32-3892-4608-831a-d0a50f2efa10"> | | ![image](https://github.com/user-attachments/assets/daf187b0-db91-4fa2-864b-47e8ca97c957) | ![image](https://github.com/user-attachments/assets/84c9b890-3c59-4e80-8dd7-4803c9b69a3f) | # Checklist > [!IMPORTANT] > Please review the checklist below before submitting your pull request. - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:41:06 -05:00
yindo closed this issue 2026-02-21 20:41:06 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#27225