[PR #29611] fix: validate page_size limit in plugin list and tasks endpoints #32484

Closed
opened 2026-02-21 20:51:29 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/29611

State: closed
Merged: Yes


Fixes #29610

Add validation constraints to page and page_size fields in ParserList and ParserTasks models to prevent Internal Server Errors when page_size exceeds the plugin daemon limit of 256.

Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

This PR fixes a bug where requesting plugin list or task endpoints with a page_size exceeding 256 results in a 500 Internal Server Error.

The previous implementation lacked proper validation for page_size before forwarding the request to the dify-plugin-daemon, which has a hard limit of 256. This change introduces ge=1 and le=256 constraints for page_size in the ParserList and ParserTasks models, ensuring that invalid page_size values are caught early and return a 400 Bad Request instead of a server error.

dify-plugin-daemon's code for ListPlugin and FetchPluginInstallationTasks.

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/29611 **State:** closed **Merged:** Yes --- Fixes #29610 Add validation constraints to page and page_size fields in ParserList and ParserTasks models to prevent Internal Server Errors when page_size exceeds the plugin daemon limit of 256. > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> This PR fixes a bug where requesting plugin list or task endpoints with a `page_size` exceeding 256 results in a 500 Internal Server Error. The previous implementation lacked proper validation for `page_size` before forwarding the request to the `dify-plugin-daemon`, which has a hard limit of 256. This change introduces `ge=1` and `le=256` constraints for `page_size` in the `ParserList` and `ParserTasks` models, ensuring that invalid `page_size` values are caught early and return a `400 Bad Request` instead of a server error. `dify-plugin-daemon`'s code for [ListPlugin](https://github.com/langgenius/dify-plugin-daemon/blob/0eb2cbe2847577a75d8d411071724355202afdaf/internal/server/controllers/plugins.go#L265) and [FetchPluginInstallationTasks](https://github.com/langgenius/dify-plugin-daemon/blob/0eb2cbe2847577a75d8d411071724355202afdaf/internal/server/controllers/plugins.go#L177). ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:51:29 -05:00
yindo closed this issue 2026-02-21 20:51:29 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#32484