[PR #21480] feat(oauth): plugin oauth service #29680

Closed
opened 2026-02-21 20:46:02 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/21480

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

OAuth Proxy Service - OAuth 2.0 Proxy Service

Description:

This service provides proxy context management functionality for OAuth 2.0 authorization flows,
primarily used to prevent CSRF (Cross-Site Request Forgery) attacks.

Main Features:

  1. create_proxy_context(): Create proxy context

    • Generate unique context_id (UUID)
    • Store user session information in Redis cache
    • Set 5-minute expiration time
    • Return context_id for OAuth authorization URL
  2. use_proxy_context(): Validate proxy context

    • Retrieve and delete stored context data from Redis
    • Validate context_id validity and expiration time
    • Return user session information for subsequent processing

Security Features:

  • Use Redis distributed cache for session state storage
  • Implement one-time use mechanism (getdel operation)
  • Timestamp-based expiration validation
  • Protection against replay attacks and CSRF attacks

Use Cases:

  • OAuth 2.0 authorisation code flow
  • OAuth callback processing requiring state validation

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/21480 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 2. Ensure there is an associated issue and you have been assigned to it > 3. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary OAuth Proxy Service - OAuth 2.0 Proxy Service Description: ============ This service provides proxy context management functionality for OAuth 2.0 authorization flows, primarily used to prevent CSRF (Cross-Site Request Forgery) attacks. Main Features: -------------- 1. create_proxy_context(): Create proxy context - Generate unique context_id (UUID) - Store user session information in Redis cache - Set 5-minute expiration time - Return context_id for OAuth authorization URL 2. use_proxy_context(): Validate proxy context - Retrieve and delete stored context data from Redis - Validate context_id validity and expiration time - Return user session information for subsequent processing Security Features: ------------------ - Use Redis distributed cache for session state storage - Implement one-time use mechanism (getdel operation) - Timestamp-based expiration validation - Protection against replay attacks and CSRF attacks Use Cases: ---------- - OAuth 2.0 authorisation code flow - OAuth callback processing requiring state validation ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:46:02 -05:00
yindo closed this issue 2026-02-21 20:46:02 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#29680