[PR #28946] Add file upload enabled check and new i18n message #32249

Closed
opened 2026-02-21 20:51:02 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/28946

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes # 28945.

Summary

I fixed #28945 .
The current implementation allows files to be uploaded via drag-and-drop even when the file upload feature is explicitly disabled in the configuration.

Root Cause

The issue arises because the system only checks for allowed file types (e.g., image extensions) before uploading, but does not check if the entire feature is enabled.
https://github.com/langgenius/dify/blob/247069c7e96fa1763fc9dd9da001bc5683c73a64/web/app/components/base/file-uploader/hooks.ts#L249
Since image types are allowed by default, fileConfig.allowed_file_types includes images. Consequently, even when the file upload feature is disabled (fileConfig.enabled: false), the isAllowedFileExtension function returns True, allowing the upload process to proceed.

Fix

  1. Enforced Feature Check: Added a condition to the handleLocalFileUpload function to check the status of fileConfig.enabled. If it is false, the function now immediately returns an error.

  2. Improved Error Messaging: Introduced a clearer error message for when file uploads are disabled.

  3. Code Cleanup: Removed redundant checks in the clipboard handling logic to standardize the error message and streamline the process, ensuring consistent behavior across different upload methods.

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/28946 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes # 28945`. ## Summary I fixed #28945 . The current implementation allows files to be uploaded via drag-and-drop even when the file upload feature is explicitly disabled in the configuration. ### Root Cause The issue arises because the system only checks for allowed file types (e.g., image extensions) before uploading, but does not check if the entire feature is enabled. https://github.com/langgenius/dify/blob/247069c7e96fa1763fc9dd9da001bc5683c73a64/web/app/components/base/file-uploader/hooks.ts#L249 Since image types are allowed by default, fileConfig.allowed_file_types includes images. Consequently, even when the file upload feature is disabled (fileConfig.enabled: false), the isAllowedFileExtension function returns True, allowing the upload process to proceed. ### Fix 1. Enforced Feature Check: Added a condition to the handleLocalFileUpload function to check the status of fileConfig.enabled. If it is false, the function now immediately returns an error. 2. Improved Error Messaging: Introduced a clearer error message for when file uploads are disabled. 3. Code Cleanup: Removed redundant checks in the clipboard handling logic to standardize the error message and streamline the process, ensuring consistent behavior across different upload methods. ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:51:02 -05:00
yindo closed this issue 2026-02-21 20:51:02 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#32249