[PR #28297] fix(api): add session_id validation for webapp JWT authentication #32004

Closed
opened 2026-02-21 20:50:34 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/28297

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

fix #28224

  • Add optional user_id parameter to decode_jwt_token() for session validation
  • Validate JWT end_user session_id against provided user_id parameter
  • Update backend LoginStatusApi to accept and pass through user_id
  • Update frontend webAppLoginStatus() to support userId parameter
  • Pass embeddedUserId to login status checks in splash component

When user_id is provided, JWT authentication will fail if the session ID doesn't match, enabling detection of expired sessions. Therefore, we can dynamically update user_id.

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/28297 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary fix #28224 - Add optional `user_id` parameter to `decode_jwt_token()` for session validation - Validate JWT end_user session_id against provided user_id parameter - Update backend `LoginStatusApi` to accept and pass through user_id - Update frontend `webAppLoginStatus()` to support userId parameter - Pass embeddedUserId to login status checks in splash component When user_id is provided, JWT authentication will fail if the session ID doesn't match, enabling detection of expired sessions. Therefore, we can dynamically update user_id. ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:50:34 -05:00
yindo closed this issue 2026-02-21 20:50:34 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#32004