[PR #24971] feat: make secretInput type field prevent browser auto-fill #30867

Closed
opened 2026-02-21 20:48:23 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/24971

State: closed
Merged: Yes


Fixes #24968

Summary

This pull request introduces improvements to form handling in the model provider authentication flow and enhances input security in the base field component. The main changes focus on initializing form values for model schemas and updating input field properties for better user experience and security.

Form value initialization and hook improvements:

  • Updated the logic in the useModelFormSchemas hook to initialize form values using the default values from each schema in formSchemas, ensuring that fields are properly pre-filled.
  • Extended the dependency array for the memoization of form values to include formSchemas, so that changes to schemas correctly trigger updates to the computed form values.

Input field security and user experience:

  • Added autoComplete={'new-password'} to the input field in BaseField, improving security by preventing browsers from autofilling sensitive fields with existing credentials.

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/24971 **State:** closed **Merged:** Yes --- Fixes #24968 ## Summary This pull request introduces improvements to form handling in the model provider authentication flow and enhances input security in the base field component. The main changes focus on initializing form values for model schemas and updating input field properties for better user experience and security. **Form value initialization and hook improvements:** * Updated the logic in the `useModelFormSchemas` hook to initialize form values using the default values from each schema in `formSchemas`, ensuring that fields are properly pre-filled. * Extended the dependency array for the memoization of form values to include `formSchemas`, so that changes to schemas correctly trigger updates to the computed form values. **Input field security and user experience:** * Added `autoComplete={'new-password'}` to the input field in `BaseField`, improving security by preventing browsers from autofilling sensitive fields with existing credentials. ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:48:23 -05:00
yindo closed this issue 2026-02-21 20:48:23 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#30867