[PR #24324] fix: standardize authentication error messages to prevent user enumeration #30583

Closed
opened 2026-02-21 20:47:49 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/24324

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

This PR standardizes error messages across authentication endpoints to prevent user enumeration attacks. Currently, different error messages allow attackers to determine whether an email address is registered in the system, which poses a security risk.

Part of #24323

Changes Made:

  1. Added generic authentication error - Created AuthenticationFailedError to provide consistent error messages
  2. Updated login endpoints - Both console and web login now return the same error regardless of whether the account exists or password is wrong
  3. Modified password reset flows - All password reset endpoints now return success to prevent account existence disclosure
  4. Updated email code login - Modified to always return success response
  5. Added security tests - Created test suite to verify the security improvements

Security Impact:

  • Prevents attackers from determining valid email addresses through error responses
  • Protects user privacy by not revealing account existence
  • Reduces risk of targeted phishing and brute force attacks

Screenshots

Before After
Different errors revealed account existence Consistent "Invalid email or password" error
Password reset returned "account not found" Always returns success

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/24324 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary This PR standardizes error messages across authentication endpoints to prevent user enumeration attacks. Currently, different error messages allow attackers to determine whether an email address is registered in the system, which poses a security risk. Part of #24323 ### Changes Made: 1. **Added generic authentication error** - Created `AuthenticationFailedError` to provide consistent error messages 2. **Updated login endpoints** - Both console and web login now return the same error regardless of whether the account exists or password is wrong 3. **Modified password reset flows** - All password reset endpoints now return success to prevent account existence disclosure 4. **Updated email code login** - Modified to always return success response 5. **Added security tests** - Created test suite to verify the security improvements ### Security Impact: - Prevents attackers from determining valid email addresses through error responses - Protects user privacy by not revealing account existence - Reduces risk of targeted phishing and brute force attacks ## Screenshots | Before | After | |--------|-------| | Different errors revealed account existence | Consistent "Invalid email or password" error | | Password reset returned "account not found" | Always returns success | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:47:49 -05:00
yindo closed this issue 2026-02-21 20:47:50 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#30583