[PR #27858] fix: change TenantApi endpoint from GET to POST #31876

Closed
opened 2026-02-21 20:50:18 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/27858

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

change TenantApi endpoint from GET to POST to prevent implicit tenant switching

Changed /workspaces/current and deprecated /info endpoints from GET to POST to prevent unintended state changes through GET requests. GET requests should be idempotent and not cause state changes like tenant switching.

Backend changes:

  • Changed TenantApi.get() to TenantApi.post() in workspace.py
  • Endpoint still performs automatic tenant switching when current tenant is archived, but now only through explicit POST requests

Frontend changes:

  • Updated fetchCurrentWorkspace in service/common.ts to use POST instead of GET
  • Changed from get() to post() while maintaining the same interface

This ensures tenant switching (even implicit fallback for archived tenants) only happens through intentional POST requests, improving security and following REST best practices.

Fixes #27839

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/27858 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> change TenantApi endpoint from GET to POST to prevent implicit tenant switching Changed /workspaces/current and deprecated /info endpoints from GET to POST to prevent unintended state changes through GET requests. GET requests should be idempotent and not cause state changes like tenant switching. Backend changes: - Changed TenantApi.get() to TenantApi.post() in workspace.py - Endpoint still performs automatic tenant switching when current tenant is archived, but now only through explicit POST requests Frontend changes: - Updated fetchCurrentWorkspace in service/common.ts to use POST instead of GET - Changed from get() to post() while maintaining the same interface This ensures tenant switching (even implicit fallback for archived tenants) only happens through intentional POST requests, improving security and following REST best practices. Fixes #27839 ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:50:18 -05:00
yindo closed this issue 2026-02-21 20:50:18 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#31876